Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-08-17 07:25:17 INFO
TEST-RUNNER
Test instance bGm6dI6LfgPQo8I created
baseUrl
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh
variant
{
  "client_auth_type": "private_key_jwt",
  "response_type": "code token",
  "server_metadata": "discovery",
  "client_registration": "dynamic_client",
  "response_mode": "default"
}
alias
isva_op_oidc_core_test_gh
description
isva_op_oidc_core_test_gh
planId
xyeb29Tiv5fzt
config
{
  "alias": "isva_op_oidc_core_test_gh",
  "description": "isva_op_oidc_core_test_gh",
  "server": {
    "discoveryUrl": "https://isamfed.com:8843/oauth2/.well-known/openid-configuration",
    "login_hint": "testuser"
  },
  "client": {
    "client_id": "client01",
    "client_secret": "secret"
  },
  "client2": {
    "client_id": "client01dup",
    "client_secret": "secret"
  },
  "consent": {},
  "client_secret_post": {
    "client_id": "client01",
    "client_secret": "secret"
  }
}
testName
oidcc-refresh-token
2022-08-17 07:25:17 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
2022-08-17 07:25:17
GetDynamicServerConfiguration
HTTP request
request_uri
https://isamfed.com:8843/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:25:18 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-type": "application/json",
  "date": "Wed, 17 Aug 2022 07:25:18 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "transfer-encoding": "chunked",
  "x-correlation-id": "CORR_ID-3fa99455-ac2c-419a-a71a-26b4a1687534",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"authorization_endpoint":"https://isamfed.com:8843/oauth2/authorize","backchannel_authentication_endpoint":"https://isamfed.com:8843/oauth2/ciba","backchannel_authentication_request_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"backchannel_token_delivery_modes_supported":["poll","ping"],"backchannel_user_code_parameter_supported":false,"claim_types_supported":["normal"],"claims_parameter_supported":true,"claims_supported":["iss","name","displayName","email","email_verified","acr","openbanking_intent_id","sharing_duration"],"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"grant_types_supported":["authorization_code","implicit","password","client_credentials","refresh_token","urn:openid:params:grant-type:ciba"],"id_token_encryption_alg_values_supported":["none"],"id_token_encryption_enc_values_supported":["none"],"id_token_signing_alg_values_supported":["RS256"],"introspection_endpoint":"https://isamfed.com:8843/oauth2/introspect","issuer":"https://isamfed.com:8843/oauth2/","jwks_uri":"https://isamfed.com:8843/oauth2/jwks","mtls_endpoint_aliases":{"backchannel_authentication_endpoint":"https://isamfed.com:8843/oauth2/ciba","introspection_endpoint":"https://isamfed.com:8843/oauth2/introspect","pushed_authorization_request_endpoint":"https://isamfed.com:8843/oauth2/par","registration_endpoint":"https://isamfed.com:8843/oauth2/register","revocation_endpoint":"https://isamfed.com:8843/oauth2/revoke","token_endpoint":"https://isamfed.com:8843/oauth2/token"},"pushed_authorization_request_endpoint":"https://isamfed.com:8843/oauth2/par","registration_endpoint":"https://isamfed.com:8843/oauth2/register","request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_parameter_supported":true,"request_uri_parameter_supported":true,"require_pushed_authorization_requests":false,"require_request_uri_registration":false,"response_modes_supported":["query","fragment","form_post"],"response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"revocation_endpoint":"https://isamfed.com:8843/oauth2/revoke","scopes_supported":["openid","profile","email","phone","address"],"subject_types_supported":["public"],"tls_client_certificate_bound_access_tokens":true,"token_endpoint":"https://isamfed.com:8843/oauth2/token","token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none"],"userinfo_encryption_enc_values_supported":["none"],"userinfo_endpoint":"https://isamfed.com:8843/oauth2/userinfo","userinfo_signing_alg_values_supported":["RS256"]}
2022-08-17 07:25:18 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
authorization_endpoint
https://isamfed.com:8843/oauth2/authorize
backchannel_authentication_endpoint
https://isamfed.com:8843/oauth2/ciba
backchannel_authentication_request_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
backchannel_token_delivery_modes_supported
[
  "poll",
  "ping"
]
backchannel_user_code_parameter_supported
false
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
claims_supported
[
  "iss",
  "name",
  "displayName",
  "email",
  "email_verified",
  "acr",
  "openbanking_intent_id",
  "sharing_duration"
]
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "client_credentials",
  "refresh_token",
  "urn:openid:params:grant-type:ciba"
]
id_token_encryption_alg_values_supported
[
  "none"
]
id_token_encryption_enc_values_supported
[
  "none"
]
id_token_signing_alg_values_supported
[
  "RS256"
]
introspection_endpoint
https://isamfed.com:8843/oauth2/introspect
issuer
https://isamfed.com:8843/oauth2/
jwks_uri
https://isamfed.com:8843/oauth2/jwks
mtls_endpoint_aliases
{
  "backchannel_authentication_endpoint": "https://isamfed.com:8843/oauth2/ciba",
  "introspection_endpoint": "https://isamfed.com:8843/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://isamfed.com:8843/oauth2/par",
  "registration_endpoint": "https://isamfed.com:8843/oauth2/register",
  "revocation_endpoint": "https://isamfed.com:8843/oauth2/revoke",
  "token_endpoint": "https://isamfed.com:8843/oauth2/token"
}
pushed_authorization_request_endpoint
https://isamfed.com:8843/oauth2/par
registration_endpoint
https://isamfed.com:8843/oauth2/register
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_parameter_supported
true
request_uri_parameter_supported
true
require_pushed_authorization_requests
false
require_request_uri_registration
false
response_modes_supported
[
  "query",
  "fragment",
  "form_post"
]
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
revocation_endpoint
https://isamfed.com:8843/oauth2/revoke
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
subject_types_supported
[
  "public"
]
tls_client_certificate_bound_access_tokens
true
token_endpoint
https://isamfed.com:8843/oauth2/token
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none"
]
userinfo_encryption_enc_values_supported
[
  "none"
]
userinfo_endpoint
https://isamfed.com:8843/oauth2/userinfo
userinfo_signing_alg_values_supported
[
  "RS256"
]
2022-08-17 07:25:18 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-08-17 07:25:18 SUCCESS
ExtractTLSTestValuesFromServerConfiguration
Extracted TLS information from authorization server configuration
registration_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 8843
}
authorization_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 8843
}
token_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 8843
}
userinfo_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 8843
}
2022-08-17 07:25:18
FetchServerKeys
Fetching server key
jwks_uri
https://isamfed.com:8843/oauth2/jwks
2022-08-17 07:25:18
FetchServerKeys
HTTP request
request_uri
https://isamfed.com:8843/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:25:19 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-type": "application/json",
  "date": "Wed, 17 Aug 2022 07:25:19 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "transfer-encoding": "chunked",
  "x-correlation-id": "CORR_ID-370c3023-e559-4394-8765-9d19f4f4b5aa",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"keys":[{"use":"sig","kty":"EC","kid":"es256","crv":"P-256","x":"2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58","y":"GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"},{"use":"sig","kty":"RSA","kid":"httpserver","n":"p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw","e":"AQAB"},{"use":"sig","kty":"RSA","kid":"mtls01","n":"ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw","e":"AQAB"},{"use":"sig","kty":"RSA","kid":"rsa256","n":"toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ","e":"AQAB"},{"use":"enc","kty":"EC","kid":"es256_dup","crv":"P-256","x":"2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58","y":"GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"},{"use":"enc","kty":"RSA","kid":"httpserver_dup","n":"p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw","e":"AQAB"},{"use":"enc","kty":"RSA","kid":"mtls01_dup","n":"ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw","e":"AQAB"},{"use":"enc","kty":"RSA","kid":"rsa256_dup","n":"toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ","e":"AQAB"}]}
2022-08-17 07:25:19
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"use":"sig","kty":"EC","kid":"es256","crv":"P-256","x":"2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58","y":"GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"},{"use":"sig","kty":"RSA","kid":"httpserver","n":"p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw","e":"AQAB"},{"use":"sig","kty":"RSA","kid":"mtls01","n":"ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw","e":"AQAB"},{"use":"sig","kty":"RSA","kid":"rsa256","n":"toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ","e":"AQAB"},{"use":"enc","kty":"EC","kid":"es256_dup","crv":"P-256","x":"2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58","y":"GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"},{"use":"enc","kty":"RSA","kid":"httpserver_dup","n":"p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw","e":"AQAB"},{"use":"enc","kty":"RSA","kid":"mtls01_dup","n":"ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw","e":"AQAB"},{"use":"enc","kty":"RSA","kid":"rsa256_dup","n":"toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ","e":"AQAB"}]}
2022-08-17 07:25:19 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "use": "sig",
      "kty": "EC",
      "kid": "es256",
      "crv": "P-256",
      "x": "2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58",
      "y": "GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "httpserver",
      "n": "p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw",
      "e": "AQAB"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "mtls01",
      "n": "ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw",
      "e": "AQAB"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "rsa256",
      "n": "toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "EC",
      "kid": "es256_dup",
      "crv": "P-256",
      "x": "2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58",
      "y": "GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "httpserver_dup",
      "n": "p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "mtls01_dup",
      "n": "ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "rsa256_dup",
      "n": "toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ",
      "e": "AQAB"
    }
  ]
}
2022-08-17 07:25:19 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "use": "sig",
      "kty": "EC",
      "kid": "es256",
      "crv": "P-256",
      "x": "2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58",
      "y": "GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "httpserver",
      "n": "p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw",
      "e": "AQAB"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "mtls01",
      "n": "ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw",
      "e": "AQAB"
    },
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "rsa256",
      "n": "toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "EC",
      "kid": "es256_dup",
      "crv": "P-256",
      "x": "2eFMhRrJ32E2iMUd8yqTH1S1R0iUNeJVkpxEtEcAK58",
      "y": "GpCy6KiKO4cFyeuAz8wUpBUHQmx0SX0YnswvZaSKkEc"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "httpserver_dup",
      "n": "p30DhlZ8sr5ZDi6prRvKL4M9ErQJ4ZYZST153m_xBP68ft-vuLOLLzl8pAXBW5IqR0YEchGQPJtUQjqE4j7ht-rqN2WQxLVzUdc9FGi2VDADdRvBncpBgSjueU-tSblcZ6LSF0UPeM2z5xTdMSgWRJ9xff_cvHJTpACdG2EWwe8u9a9yzVz_dqLbVugy415Cotp3DiZyIjHVEADvJY9Xlxk4E39lCKOMQlAFMPH76HnXCrVCi4MZeokCYHBzH_8ue29ImhLAZRE83F9r0mhfx37lAraut3rr6sRponY4wBRaEXpNrVlcTTNMyvL272TCkEZqtm4mwepVhNYj7Pxblw",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "mtls01_dup",
      "n": "ppY9BFOF6YXRPSRv-p21I6l-9OiTF_JbjzQ3zbvkhwkQ8p30chePHLQVeBBev1oV5j_oGYzD2_hUkUcqueHETuOFTaZ8Z0VpN9c2HDXTZ4IeTUpPJPPWcqJ4ykWxtZdhgWbxjn5lROzupAUrsT9nJci4_8KgEu6vaTnIo-NLVwzFkNr9cMYRBcg7O20RL7V7LSgGyqw2vUK3jvBCgsCZSWRjjBQiYGQjEYkvGmAm22Omw2HmdJ0mFV4m7DpyY2WRhLqSAedzkwsYioTDPXqa-ts8DgBqUySPYp1ACSoeHxVO5gnKd6ukaCNyh5U7bui0zMRw_NKRGChA1nJN3cg1Mw",
      "e": "AQAB"
    },
    {
      "use": "enc",
      "kty": "RSA",
      "kid": "rsa256_dup",
      "n": "toihHnUntP41DGJEpUQjHuzyWtb4NQEg5r38YoaCRVfnX7pmYOgn6zOU3jgUXuNqJefTHNLRq7_wxZT2zsCFrJvfg8ccl4Ds1Vp3Hur3mQVsqhXrKRqBvvsF_1pbJSbyLCk0_HkrcP9XRNP4Lq2MiofAtt89Lmya9ZlwbA4NLkEJFNtC-6wuq48kpA-TWXOcQXPUW-0RZS7t8DGgRlQpeUwj8-g6N_uUSk21hawGNlWmOYkrQ7w4kCIKO2U4Y6_2dygwNnESxiPA_61UuH9wVjWxo1XiyKJnpDGiYXGeihoGn6EcLMKeA8wACuR_1ah7BD3iKMQRW3DWEBfjp0LMyQ",
      "e": "AQAB"
    }
  ]
}
2022-08-17 07:25:19 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-08-17 07:25:19 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-08-17 07:25:19 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-08-17 07:25:19 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-08-17 07:25:19
StoreOriginalClientConfiguration
Created original_client_config object from the client configuration.
client_id
client01
client_secret
secret
2022-08-17 07:25:19
ExtractClientNameFromStoredConfig
Extracted client_name from stored client configuration.
client_name
2022-08-17 07:25:19 SUCCESS
GenerateRS256ClientJWKs
Generated client JWKs
client_jwks
{
  "keys": [
    {
      "p": "6G3_zd-Qckf8PdX4jDLVqIUwypKLrh0NMKzYZcLVoAuozqPPuEg0PdJnVZEW274VFC0hAW-hFoo89qQAIvRbrWD5uU9u6ch60ZoaRQBnVPrKLDtkGfqB8_SsWyZ3c-GraAfkfXs9caj2OuS2UXFDBLFBZrZBOtXdohkQN__65fU",
      "kty": "RSA",
      "q": "nB77jQOsl3QZKQoJLkPZzmhppZhgX3I-UB7u7DROxy-QyOVyHSRBU7oAuWW5hP-eRUp9VRRee37_ZI0H-po1pD13-0--ofo_PB93GKDN4qdtbHulegsdsB7RYybdgQBsumxJt8jPAZUgZcqaujVErPolIH0Y1lmMtrAY63Tu5cc",
      "d": "e4kX-Y54gywEFl0Zy0MxmrtBKInfiWVbfR3CirVbBmlcxk0PsOnYTD-edQiLxF0RaCtQfqN31XxeyzmXjTHgSAoeN09CXtpoLliKrhcIUZ2yIER8rmpWVkZYeP2h0HkGODz2ANF6U-HepjGoaEs4FLo8D7yc0iZbIbnbCPe9GcOr8K03TLy_qyjUktdQDUdbimODXNsFoijqeekdW_wYY2nXn8RriO_pUfuJptFEqOceFAfCfCEdOLVarnxgwdYUnI-QQNE6CvpwH6YqumdsFCoXlSQFM9zRGA37W4kpYpeWentzgYcRdOLa-eUPxGq517u_4oxRlgTcC5JE5EHC2Q",
      "e": "AQAB",
      "use": "sig",
      "qi": "W9FwkUcvi7-j5Zj315qGgetC4GqSp1RqnZa06uqt_OVV-SrQZ-L3Hwutj_I4Mu-tHQ9kr6tQqW0nCsKEpHdfOoL3pEynI4K1zaZOOmFg0VmgW-iqbG8n0vhwtfh0yXEfmonG4hHd_B5h6krfsECM1h1ltuFPJuD0QOHkxgHGkUU",
      "dp": "huHO4RosKSW9K-VQJ4wYkYM5nVUN2izhyq2Dpwo6Dna1r7VAhiDgsD-5194q9bqJYPwPe1XclcgDON5TdfV4flUYloGSS_kbzScwt3pUfOxNBv4wSSMm5vvGSd840vbTEbwCzQ8HyT3UJrkzVG_2BHMZERITKKGTzM3eq6DRaUE",
      "alg": "RS256",
      "dq": "ZXWhJyiPHrJds5UJGF8SCplCp1KatwzIwEsKHMl1tO8NmfG7MoMgTWhhFhus8GkrE37war1dFccX9OHOoKddWwpzkghmLGA0fj84p_HBO55xd4H3rZPRzGaKz3QvmamL_69mTSEcnruqnVyJJ6B8rCm4vR9vZ8Y0s3lICKUqqHs",
      "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "alg": "RS256",
      "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
    }
  ]
}
2022-08-17 07:25:19 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-08-17 07:25:19
CreateEmptyDynamicRegistrationRequest
Created empty dynamic registration request
2022-08-17 07:25:19
AddClientNameToDynamicRegistrationRequest
Added client_name to registration request
client_name
OIDF Conformance Test bGm6dI6LfgPQo8I
2022-08-17 07:25:19
AddAuthorizationCodeGrantTypeToDynamicRegistrationRequest
Added 'authorization_code' to 'grant_types'
grant_types
[
  "authorization_code"
]
2022-08-17 07:25:19
AddImplicitGrantTypeToDynamicRegistrationRequest
Added 'implicit' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit"
]
2022-08-17 07:25:19
AddPublicJwksToDynamicRegistrationRequest
Added client public JWKS to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
      }
    ]
  }
}
2022-08-17 07:25:19
AddTokenEndpointAuthMethodToDynamicRegistrationRequestFromEnvironment
Added token endpoint auth method to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt"
}
2022-08-17 07:25:19
AddResponseTypesArrayToDynamicRegistrationRequestFromEnvironment
Added response_types array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ]
}
2022-08-17 07:25:19
AddRedirectUriToDynamicRegistrationRequest
Added redirect_uris array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ]
}
2022-08-17 07:25:19
AddContactsToDynamicRegistrationRequest
Added contacts array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ],
  "contacts": [
    "certification@oidf.org"
  ]
}
2022-08-17 07:25:19
AddRefreshTokenGrantTypeToDynamicRegistrationRequest
Added 'refresh_token' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit",
  "refresh_token"
]
2022-08-17 07:25:19
CallDynamicRegistrationEndpoint
HTTP request
request_uri
https://isamfed.com:8843/oauth2/register
request_method
POST
request_headers
{
  "accept": "application/json",
  "accept-charset": "utf-8",
  "content-type": "application/json",
  "content-length": "753"
}
request_body
{"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"kty":"RSA","e":"AQAB","use":"sig","alg":"RS256","n":"jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw"}]},"token_endpoint_auth_method":"private_key_jwt","response_types":["code token"],"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"contacts":["certification@oidf.org"]}
2022-08-17 07:25:20 RESPONSE
CallDynamicRegistrationEndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "content-length": "1168",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:25:20 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-96d00252-dc90-49f0-baac-0d47a409f947",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"client_id":"7a2c2baa-aa8c-4654-b935-937981ceed81","client_id_issued_at":1660721120,"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","client_secret":"hCNr2QnMXUGlmmB2","client_secret_expires_at":0,"contacts":["certification@oidf.org"],"grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"alg":"RS256","e":"AQAB","kty":"RSA","n":"jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw","use":"sig"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"registration_access_token":"v8EMQOOr6i8BY_ZmHVHBknrLMIumJYI5pqYvNsK9bhw.rInJfdvVtSVch1HLM2hQAiSKSh7INck1RGr8pd2tMpb2lATyexUvSVqC-bF9G_cdugFHxjqN13RYSOGmtnEQfw","registration_client_uri":"https://isamfed.com:8843/oauth2/register/7a2c2baa-aa8c-4654-b935-937981ceed81","response_types":["code token"],"token_endpoint_auth_method":"private_key_jwt"}
2022-08-17 07:25:20
CallDynamicRegistrationEndpoint
Parsed registration endpoint response
status
201
endpoint_name
dynamic registration
headers
{
  "content-length": "1168",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:25:20 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-96d00252-dc90-49f0-baac-0d47a409f947",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
body
{"client_id":"7a2c2baa-aa8c-4654-b935-937981ceed81","client_id_issued_at":1660721120,"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","client_secret":"hCNr2QnMXUGlmmB2","client_secret_expires_at":0,"contacts":["certification@oidf.org"],"grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"alg":"RS256","e":"AQAB","kty":"RSA","n":"jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw","use":"sig"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"registration_access_token":"v8EMQOOr6i8BY_ZmHVHBknrLMIumJYI5pqYvNsK9bhw.rInJfdvVtSVch1HLM2hQAiSKSh7INck1RGr8pd2tMpb2lATyexUvSVqC-bF9G_cdugFHxjqN13RYSOGmtnEQfw","registration_client_uri":"https://isamfed.com:8843/oauth2/register/7a2c2baa-aa8c-4654-b935-937981ceed81","response_types":["code token"],"token_endpoint_auth_method":"private_key_jwt"}
body_json
{
  "client_id": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "client_id_issued_at": 1660721120,
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "client_secret": "hCNr2QnMXUGlmmB2",
  "client_secret_expires_at": 0,
  "contacts": [
    "certification@oidf.org"
  ],
  "grant_types": [
    "authorization_code",
    "implicit",
    "refresh_token"
  ],
  "jwks": {
    "keys": [
      {
        "alg": "RS256",
        "e": "AQAB",
        "kty": "RSA",
        "n": "jb8pKVAW9JGXRALZ7UK1vKgqSp8V353rVL0DugavnSDReHZ1wHFY0h36nZMeAJYeubGTkhCMvW3p_c43lKch6kXd87LvQExVZR0B_1FD9sIUYlRY2MhHP8KJbMrw3VprR00IoH15m6X1XCW7fxhe1ufb3aKEL_jRCsrsOXjXG7Z6dEqDE-nZUutmSnfFZLkoi5hST18lCZSgMkIiKRiwW6BnxPnUzWFw376i2s4wNdu4EfFmtWyg9Lle5b9RxylXnmZuswo48neN4UDFh7lHKFVrOA4n6RK68V_T4qcoF_657cOgGW59bzjGj7NVuiVHYDVKlR6E_k2oW27fOYLqcw",
        "use": "sig"
      }
    ]
  },
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ],
  "registration_access_token": "v8EMQOOr6i8BY_ZmHVHBknrLMIumJYI5pqYvNsK9bhw.rInJfdvVtSVch1HLM2hQAiSKSh7INck1RGr8pd2tMpb2lATyexUvSVqC-bF9G_cdugFHxjqN13RYSOGmtnEQfw",
  "registration_client_uri": "https://isamfed.com:8843/oauth2/register/7a2c2baa-aa8c-4654-b935-937981ceed81",
  "response_types": [
    "code token"
  ],
  "token_endpoint_auth_method": "private_key_jwt"
}
2022-08-17 07:25:20 SUCCESS
EnsureContentTypeJson
endpoint_response Content-Type: header is application/json
2022-08-17 07:25:20 SUCCESS
EnsureHttpStatusCodeIs201
dynamic registration endpoint returned the expected http status
expected_status
201
http_status
201
2022-08-17 07:25:20 SUCCESS
CheckNoErrorFromDynamicRegistrationEndpoint
Dynamic registration endpoint did not return an error.
2022-08-17 07:25:20 SUCCESS
ExtractDynamicRegistrationResponse
Extracted client from dynamic registration response
client_id
7a2c2baa-aa8c-4654-b935-937981ceed81
2022-08-17 07:25:20 SUCCESS
VerifyClientManagementCredentials
Verified dynamic registration management credentials
registration_client_uri
https://isamfed.com:8843/oauth2/register/7a2c2baa-aa8c-4654-b935-937981ceed81
registration_access_token
v8EMQOOr6i8BY_ZmHVHBknrLMIumJYI5pqYvNsK9bhw.rInJfdvVtSVch1HLM2hQAiSKSh7INck1RGr8pd2tMpb2lATyexUvSVqC-bF9G_cdugFHxjqN13RYSOGmtnEQfw
2022-08-17 07:25:20
SetScopeInClientConfigurationToOpenId
Set scope in client configuration to "openid"
scope
openid
2022-08-17 07:25:20
SetScopeInClientConfigurationToOpenIdOfflineAccessIfServerSupportsOfflineAccess
scopes supported does not contain 'offline_access' so not adding it to the list of scopes to be requested
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
2022-08-17 07:25:20 SUCCESS
EnsureServerConfigurationSupportsPrivateKeyJwt
Found supported private_key_jwt method
method
private_key_jwt
2022-08-17 07:25:20
StoreOriginalClient2Configuration
Created original_client_config object from the client configuration.
client_id
client01dup
client_secret
secret
2022-08-17 07:25:20
ExtractClientNameFromStoredConfig
Extracted client_name from stored client configuration.
client_name
2022-08-17 07:25:20 SUCCESS
GenerateRS256ClientJWKs
Generated client JWKs
client_jwks
{
  "keys": [
    {
      "p": "91FUsDGTMsQVmMmeTyhWZXQOjC68hVVI4CP3LGh3AkIVov7CRst8a2miXercy9lYk5sm6vdWqW9o8xa-wHBF-9c-drSjrH7eBDD9MNEeTAALqtANGI-y2bxZYYxEnC7WhLkz2OJnFhxSIkI37p_x8hf8YNCpSs2GPW6RVmDdpo8",
      "kty": "RSA",
      "q": "zowl5DgPQX8Y5q00smEsYuro1ltEwzvAiLrXvNwYQsnq_SUcl1DJFWohFklyCQzddBX2C6fGVaJ0UVvqXAwp-Kjf9rRbndPsD4pmz7Nm6Z8jyRG0g4oCh8cNK0tC9SdQg4tq1epop3SzJsh77cCeLVqt-4T0SVtgmUcVkBJpsnc",
      "d": "iwW0huVB6M7vAZDUWDoOD0Xtb1yNfqvUofB_m2LI9SUBm_b2OSKLwpNA-NduHQH70CGo1fu4moW_N3Z6oemTBssyaepNIe5Ys8TSs7vqqUPRMxi1sQe5oo298EKbn39Fn4Q-uGzJBOOmPMUaP_YazeRDFhEGCcFWMax7BheBhmLqWnVfpRUB1IXvwJ_vTvfUfZjIJ3dTYfxyRyjXbeXzW5aI0s5OZvtTX7p6zwNTOF1VaCXcZSIvKVf56HiHyW__jdish4gaxEw-zSgVGZ6qTZhV-dNwQeIMOu_c4A-KR5Jqb8__YbUyG8GOcyVitsQGv2bs70OgR3h_QJIgPkQtsQ",
      "e": "AQAB",
      "use": "sig",
      "qi": "D0cvYHd4G05P1hODZOkOQE-2Xbe0KNJ2SJOvr3Uz2le55zSl-fa5snXGXfJn46EVFQ3nq6kQQiU89idyZP_MNcVoLv_W1gtgXO0WS3afkFR7KLHbSqx8RqMk8Lh1NWa6V_x83su2lafKjRLbyY_QSAaKkN9c8-aIgF75QztrrDE",
      "dp": "ijF77OgGpDtFBhbCyuBzRkVPS61h0e8RxYzTNJE6zpw2ktlfnUdewnZIL8pojc9o2zG60VhbqFmEfzCabdVOhaaEVLgjLOPHEvh8waZYE4eC_XM7nhnNijTgjM1gGRVi8M671djMWWKB0nrF3iSpgOk-MKrnrdChzfnWZDnEIKk",
      "alg": "RS256",
      "dq": "Ir2B1gvzzPFir9HsLiCYBZ87QGqjey7-qEC87qAaWIl7w85NK8pDuB1cqVH7IziNuuvCsZ0rh9XGOLT8CzVkjdVhri4Rxs8RQl_mAQNMyPiiXTxkH0fEOzAor-J9xZwyN53of0hpB9liFKDd71RZholdABQRvpDnA4DoSI5ARus",
      "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "alg": "RS256",
      "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
    }
  ]
}
2022-08-17 07:25:20 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-08-17 07:25:20
CreateEmptyDynamicRegistrationRequest
Created empty dynamic registration request
2022-08-17 07:25:20
AddClientNameToDynamicRegistrationRequest
Added client_name to registration request
client_name
OIDF Conformance Test bGm6dI6LfgPQo8I
2022-08-17 07:25:20
AddAuthorizationCodeGrantTypeToDynamicRegistrationRequest
Added 'authorization_code' to 'grant_types'
grant_types
[
  "authorization_code"
]
2022-08-17 07:25:20
AddImplicitGrantTypeToDynamicRegistrationRequest
Added 'implicit' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit"
]
2022-08-17 07:25:20
AddPublicJwksToDynamicRegistrationRequest
Added client public JWKS to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
      }
    ]
  }
}
2022-08-17 07:25:20
AddTokenEndpointAuthMethodToDynamicRegistrationRequestFromEnvironment
Added token endpoint auth method to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt"
}
2022-08-17 07:25:20
AddResponseTypesArrayToDynamicRegistrationRequestFromEnvironment
Added response_types array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ]
}
2022-08-17 07:25:20
AddRedirectUriToDynamicRegistrationRequest
Added redirect_uris array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ]
}
2022-08-17 07:25:20
AddContactsToDynamicRegistrationRequest
Added contacts array to dynamic registration request
dynamic_registration_request
{
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"
      }
    ]
  },
  "token_endpoint_auth_method": "private_key_jwt",
  "response_types": [
    "code token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ],
  "contacts": [
    "certification@oidf.org"
  ]
}
2022-08-17 07:25:20
AddRefreshTokenGrantTypeToDynamicRegistrationRequest
Added 'refresh_token' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit",
  "refresh_token"
]
2022-08-17 07:25:20
CallDynamicRegistrationEndpoint
HTTP request
request_uri
https://isamfed.com:8843/oauth2/register
request_method
POST
request_headers
{
  "accept": "application/json",
  "accept-charset": "utf-8",
  "content-type": "application/json",
  "content-length": "753"
}
request_body
{"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"kty":"RSA","e":"AQAB","use":"sig","alg":"RS256","n":"x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ"}]},"token_endpoint_auth_method":"private_key_jwt","response_types":["code token"],"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"contacts":["certification@oidf.org"]}
2022-08-17 07:25:21 RESPONSE
CallDynamicRegistrationEndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "content-length": "1168",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:25:21 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-ae746d83-016f-474b-b899-54c127272329",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"client_id":"4f84e8e1-f965-4611-9fbc-eff60f14e763","client_id_issued_at":1660721121,"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","client_secret":"PSTUSVrKyPYDE2YS","client_secret_expires_at":0,"contacts":["certification@oidf.org"],"grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"alg":"RS256","e":"AQAB","kty":"RSA","n":"x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ","use":"sig"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"registration_access_token":"Ri50H8yR-B9x3RVWSxKiyReQfHpJzdYxtOuqyZG4OCU.Y5PBxXAAT88SRZpIsEYPaj_pYmbvOqndsmjxkuGWSgqxpzZjW8Vg2bo8DQGqqku_CKpwXCZ0dXPiw45Q0LmDpQ","registration_client_uri":"https://isamfed.com:8843/oauth2/register/4f84e8e1-f965-4611-9fbc-eff60f14e763","response_types":["code token"],"token_endpoint_auth_method":"private_key_jwt"}
2022-08-17 07:25:21
CallDynamicRegistrationEndpoint
Parsed registration endpoint response
status
201
endpoint_name
dynamic registration
headers
{
  "content-length": "1168",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:25:21 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-ae746d83-016f-474b-b899-54c127272329",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
body
{"client_id":"4f84e8e1-f965-4611-9fbc-eff60f14e763","client_id_issued_at":1660721121,"client_name":"OIDF Conformance Test bGm6dI6LfgPQo8I","client_secret":"PSTUSVrKyPYDE2YS","client_secret_expires_at":0,"contacts":["certification@oidf.org"],"grant_types":["authorization_code","implicit","refresh_token"],"jwks":{"keys":[{"alg":"RS256","e":"AQAB","kty":"RSA","n":"x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ","use":"sig"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"],"registration_access_token":"Ri50H8yR-B9x3RVWSxKiyReQfHpJzdYxtOuqyZG4OCU.Y5PBxXAAT88SRZpIsEYPaj_pYmbvOqndsmjxkuGWSgqxpzZjW8Vg2bo8DQGqqku_CKpwXCZ0dXPiw45Q0LmDpQ","registration_client_uri":"https://isamfed.com:8843/oauth2/register/4f84e8e1-f965-4611-9fbc-eff60f14e763","response_types":["code token"],"token_endpoint_auth_method":"private_key_jwt"}
body_json
{
  "client_id": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "client_id_issued_at": 1660721121,
  "client_name": "OIDF Conformance Test bGm6dI6LfgPQo8I",
  "client_secret": "PSTUSVrKyPYDE2YS",
  "client_secret_expires_at": 0,
  "contacts": [
    "certification@oidf.org"
  ],
  "grant_types": [
    "authorization_code",
    "implicit",
    "refresh_token"
  ],
  "jwks": {
    "keys": [
      {
        "alg": "RS256",
        "e": "AQAB",
        "kty": "RSA",
        "n": "x4rXO1QU-wDrH6SfR6TkttghIaDwNRGfmQuxZN2wbg75WECC4eKmB9gCwk58wwXEq8YZkHm5TSkpoW-4A0DF-_-DbSHKpfoBIhjXExPLMSDS8FWhGan8g6QNtsH3n85Uz4vo7T-h6EECiVwCzy3gwnp_7z93y9UHwQp_5B2OX_kTVZ3kG7SokeXWUH7Q6Pno8UMsoHk8sBMCfZV3-9w497HMWbwF_gFW6BHqoBRx-UEeZVoUOBPNmA959dj-WxC2-N14gzHxSruP3wrvo9OczubPdkA-AXSxIiMFxBDJdyVcj1BuiO3nPZG7to6TZtuY0VCzbegfT9xysVqQg37aeQ",
        "use": "sig"
      }
    ]
  },
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback"
  ],
  "registration_access_token": "Ri50H8yR-B9x3RVWSxKiyReQfHpJzdYxtOuqyZG4OCU.Y5PBxXAAT88SRZpIsEYPaj_pYmbvOqndsmjxkuGWSgqxpzZjW8Vg2bo8DQGqqku_CKpwXCZ0dXPiw45Q0LmDpQ",
  "registration_client_uri": "https://isamfed.com:8843/oauth2/register/4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "response_types": [
    "code token"
  ],
  "token_endpoint_auth_method": "private_key_jwt"
}
2022-08-17 07:25:21 SUCCESS
EnsureContentTypeJson
endpoint_response Content-Type: header is application/json
2022-08-17 07:25:21 SUCCESS
EnsureHttpStatusCodeIs201
dynamic registration endpoint returned the expected http status
expected_status
201
http_status
201
2022-08-17 07:25:21 SUCCESS
CheckNoErrorFromDynamicRegistrationEndpoint
Dynamic registration endpoint did not return an error.
2022-08-17 07:25:21 SUCCESS
ExtractDynamicRegistrationResponse
Extracted client from dynamic registration response
client_id
4f84e8e1-f965-4611-9fbc-eff60f14e763
2022-08-17 07:25:21 SUCCESS
VerifyClientManagementCredentials
Verified dynamic registration management credentials
registration_client_uri
https://isamfed.com:8843/oauth2/register/4f84e8e1-f965-4611-9fbc-eff60f14e763
registration_access_token
Ri50H8yR-B9x3RVWSxKiyReQfHpJzdYxtOuqyZG4OCU.Y5PBxXAAT88SRZpIsEYPaj_pYmbvOqndsmjxkuGWSgqxpzZjW8Vg2bo8DQGqqku_CKpwXCZ0dXPiw45Q0LmDpQ
2022-08-17 07:25:21
SetScopeInClientConfigurationToOpenId
Set scope in client configuration to "openid"
scope
openid
2022-08-17 07:25:21
SetScopeInClientConfigurationToOpenIdOfflineAccessIfServerSupportsOfflineAccess
scopes supported does not contain 'offline_access' so not adding it to the list of scopes to be requested
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
2022-08-17 07:25:21 SUCCESS
EnsureServerConfigurationSupportsPrivateKeyJwt
Found supported private_key_jwt method
method
private_key_jwt
2022-08-17 07:25:21 SUCCESS
SetProtectedResourceUrlToUserInfoEndpoint
userinfo_endpoint will be used to test access token. The user info is not a mandatory to implement feature in the OpenID Connect specification, but is mandatory for certification.
protected_resource_url
https://isamfed.com:8843/oauth2/userinfo
2022-08-17 07:25:21
oidcc-refresh-token
Setup Done
Make request to authorization endpoint
2022-08-17 07:25:21 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
7a2c2baa-aa8c-4654-b935-937981ceed81
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
2022-08-17 07:25:21
CreateRandomStateValue
Created state value
requested_state_length
10
state
pUIdFMKNSK
2022-08-17 07:25:21 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
7a2c2baa-aa8c-4654-b935-937981ceed81
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
pUIdFMKNSK
2022-08-17 07:25:21
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
iMzKcBW08I
2022-08-17 07:25:21 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
7a2c2baa-aa8c-4654-b935-937981ceed81
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
pUIdFMKNSK
nonce
iMzKcBW08I
2022-08-17 07:25:21 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
7a2c2baa-aa8c-4654-b935-937981ceed81
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
pUIdFMKNSK
nonce
iMzKcBW08I
response_type
code token
2022-08-17 07:25:21 SUCCESS
AddPromptConsentToAuthorizationEndpointRequestIfScopeContainsOfflineAccess
Not adding prompt=consent as the scope in the configuration does not contain offline_access
2022-08-17 07:25:21 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "redirect_uri": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback",
  "scope": "openid",
  "state": "pUIdFMKNSK",
  "nonce": "iMzKcBW08I",
  "response_type": "code token"
}
redirect_to_authorization_endpoint
https://isamfed.com:8843/oauth2/authorize?client_id=7a2c2baa-aa8c-4654-b935-937981ceed81&redirect_uri=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback&scope=openid&state=pUIdFMKNSK&nonce=iMzKcBW08I&response_type=code%20token
2022-08-17 07:25:21 REDIRECT
oidcc-refresh-token
Redirecting to authorization endpoint
redirect_to
https://isamfed.com:8843/oauth2/authorize?client_id=7a2c2baa-aa8c-4654-b935-937981ceed81&redirect_uri=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback&scope=openid&state=pUIdFMKNSK&nonce=iMzKcBW08I&response_type=code%20token
2022-08-17 07:27:13 INCOMING
oidcc-refresh-token
Incoming HTTP request to /test/a/isva_op_oidc_core_test_gh/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"macOS\"",
  "referer": "https://isamfed.com:8843/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "connection": "close"
}
incoming_path
/test/a/isva_op_oidc_core_test_gh/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-08-17 07:27:13 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/tLLcEfF5qbpOXKu940I8",
  "fullUrl": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/implicit/tLLcEfF5qbpOXKu940I8"
}
2022-08-17 07:27:13 OUTGOING
oidcc-refresh-token
Response to HTTP request to test instance bGm6dI6LfgPQo8I
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/implicit/tLLcEfF5qbpOXKu940I8, returnUrl=/log-detail.html?log=bGm6dI6LfgPQo8I}]
outgoing_path
callback
2022-08-17 07:27:14 INCOMING
oidcc-refresh-token
Incoming HTTP request to /test/a/isva_op_oidc_core_test_gh/implicit/tLLcEfF5qbpOXKu940I8
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"macOS\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "connection": "close",
  "content-length": "344"
}
incoming_path
/test/a/isva_op_oidc_core_test_gh/implicit/tLLcEfF5qbpOXKu940I8
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#access_token=W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg&code=xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng&expires_in=7200&scope=openid&state=pUIdFMKNSK&token_type=bearer
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-08-17 07:27:14 OUTGOING
oidcc-refresh-token
Response to HTTP request to test instance bGm6dI6LfgPQo8I
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/tLLcEfF5qbpOXKu940I8
2022-08-17 07:27:14
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "access_token",
    "value": "W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg"
  },
  {
    "name": "code",
    "value": "xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng"
  },
  {
    "name": "expires_in",
    "value": "7200"
  },
  {
    "name": "scope",
    "value": "openid"
  },
  {
    "name": "state",
    "value": "pUIdFMKNSK"
  },
  {
    "name": "token_type",
    "value": "bearer"
  }
]
2022-08-17 07:27:14 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
access_token
W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg
code
xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng
expires_in
7200
scope
openid
state
pUIdFMKNSK
token_type
bearer
2022-08-17 07:27:14 REDIRECT-IN
oidcc-refresh-token
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"macOS\"",
  "referer": "https://isamfed.com:8843/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "access_token": "W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg",
  "code": "xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng",
  "expires_in": "7200",
  "scope": "openid",
  "state": "pUIdFMKNSK",
  "token_type": "bearer"
}
post_body
Verify authorization endpoint response
2022-08-17 07:27:14 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-08-17 07:27:14 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-08-17 07:27:14 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-08-17 07:27:14
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2022-08-17 07:27:14 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-08-17 07:27:14 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
pUIdFMKNSK
2022-08-17 07:27:14 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng
2022-08-17 07:27:14 SUCCESS
ExtractAccessTokenFromAuthorizationResponse
Extracted the access token
value
W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg
type
bearer
Userinfo endpoint tests
2022-08-17 07:27:14
CallProtectedResource
HTTP request
request_uri
https://isamfed.com:8843/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer W79Q81l7Xzp45EnRXY0TNe0Gw65NaF9dSYZmWaIWEcY.KbK6L5f1C3aFQsPyqO4oKxeMm52e1YYLsnU9zRhBq9wJFKfGjmgOkT7enYBX2_v3l0IBmYtGLivqCeVIgVOEjg",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:15 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:15 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-ff1e0dd0-5d2c-4341-960a-2397b113a2c8",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"aud":["7a2c2baa-aa8c-4654-b935-937981ceed81"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721228,"sub":"testuser"}
2022-08-17 07:27:15 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:15 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-ff1e0dd0-5d2c-4341-960a-2397b113a2c8",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
body
{"aud":["7a2c2baa-aa8c-4654-b935-937981ceed81"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721228,"sub":"testuser"}
2022-08-17 07:27:15 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-08-17 07:27:15 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
2022-08-17 07:27:15 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
7a2c2baa-aa8c-4654-b935-937981ceed81
sub
7a2c2baa-aa8c-4654-b935-937981ceed81
aud
https://isamfed.com:8843/oauth2/token
jti
4jJ9Sw5mnh3TmUsQC1nl
iat
1660721235
exp
1660721295
2022-08-17 07:27:15 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NSwiaWF0IjoxNjYwNzIxMjM1LCJqdGkiOiI0ako5U3c1bW5oM1RtVXNRQzFubCJ9.iqnRWOmdsjTSS8vls_BoIMIxSX10HiMnk4wMODOTKe3zt7890veN6FC8SFMogtKbYGZum6YhgUm5N2V9A-xWh8DmQR2Ezl5wYAcKY1UugvdGZW6GzcUpM2Kte7SVAffvA1gMX6QLNGkqlBchZoRBXvBtprRXVpv8SdSmKt2Z_yvHE8SmOIDUWYt9vE5xfOgdZbgtfGMyjGjLGlre3L5UyFsDEy2SQ6Kqj5aFyC-PX2LDoScjR_eBOp7uC6FTGVxru4osDFf-Sda2vuWUrSGZMLKd0-K4TKLi1SYDAxgNoAtsT77tJbqdAO2fna7UMXlYjmmccRUT_iKDYl245z6OcA
2022-08-17 07:27:15
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NSwiaWF0IjoxNjYwNzIxMjM1LCJqdGkiOiI0ako5U3c1bW5oM1RtVXNRQzFubCJ9.iqnRWOmdsjTSS8vls_BoIMIxSX10HiMnk4wMODOTKe3zt7890veN6FC8SFMogtKbYGZum6YhgUm5N2V9A-xWh8DmQR2Ezl5wYAcKY1UugvdGZW6GzcUpM2Kte7SVAffvA1gMX6QLNGkqlBchZoRBXvBtprRXVpv8SdSmKt2Z_yvHE8SmOIDUWYt9vE5xfOgdZbgtfGMyjGjLGlre3L5UyFsDEy2SQ6Kqj5aFyC-PX2LDoScjR_eBOp7uC6FTGVxru4osDFf-Sda2vuWUrSGZMLKd0-K4TKLi1SYDAxgNoAtsT77tJbqdAO2fna7UMXlYjmmccRUT_iKDYl245z6OcA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-08-17 07:27:15
CallTokenEndpoint
HTTP request
request_uri
https://isamfed.com:8843/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1012"
}
request_body
grant_type=authorization_code&code=xsV_Cxqv6ivkCd4kFMLWaqYGWZZMmOndrgRYyFYWGVU.i3mjBK_QY6oDG2jKNfULGWy3v7E0quDmzC-gK-I_FpvEXYbQ8Psq4c2TmSQlPNMBx_50cuDalQNn6ygXyT5dng&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fisva_op_oidc_core_test_gh%2Fcallback&client_assertion=eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NSwiaWF0IjoxNjYwNzIxMjM1LCJqdGkiOiI0ako5U3c1bW5oM1RtVXNRQzFubCJ9.iqnRWOmdsjTSS8vls_BoIMIxSX10HiMnk4wMODOTKe3zt7890veN6FC8SFMogtKbYGZum6YhgUm5N2V9A-xWh8DmQR2Ezl5wYAcKY1UugvdGZW6GzcUpM2Kte7SVAffvA1gMX6QLNGkqlBchZoRBXvBtprRXVpv8SdSmKt2Z_yvHE8SmOIDUWYt9vE5xfOgdZbgtfGMyjGjLGlre3L5UyFsDEy2SQ6Kqj5aFyC-PX2LDoScjR_eBOp7uC6FTGVxru4osDFf-Sda2vuWUrSGZMLKd0-K4TKLi1SYDAxgNoAtsT77tJbqdAO2fna7UMXlYjmmccRUT_iKDYl245z6OcA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-08-17 07:27:16 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "1236",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:16 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-d03fca29-eaff-403f-9138-1b7a8c06637a",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"access_token":"U-efWaYYrsEMElv0Sxcdo5TE16INjbEQFhFX7u4sC_k.I_aswLsv5u5HMtS8NX-t9TE-wbb7SrcN3TElsIwSz9zFkzOhhZ6w8Mzj1XODJ4W9e6CLzWjqMz7lnpflxGQ0Mw","expires_in":7196,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiT1h2YU9nYTVfZGJ4NkNpU0VzSXh1QSIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzYsImlhdCI6MTY2MDcyMTIzNiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI0YTUzMTYyYy0xMTdjLTQ5OTQtOGY0Yi1hMTc2NjVkODczYzYiLCJub25jZSI6ImlNektjQlcwOEkiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiItazA4Y2JFOHMtenp4RnA4M216Z0l3Iiwic19oYXNoIjoiVS04SkpOek9ZeXdhWjZ6NExKai10dyIsInN1YiI6InRlc3R1c2VyIn0.EqiqTjuanMFz_waUdgn5b2dyIE9w_74Qhhxzj2y6gMpzfBDaPVJPmYwSTYbqMyRvZh1McS_eEex56r8KF9Z6Te6_8qmkECma-6L77rXmkbRsY_lvZrV0QoWbITaHTiSXzJ5PCv2-xjAmU8c6HLQ1dnAdLE9HDZ3j_PbyIoThqio8beGzSlCjHXfXqb1nOX_8Vo8Kfk_hmVNkAxLiTI6EldIykiofd5VImmyitKUsX52HHHUC6LdsnKdEwFn3M4ET2uiXlFYkv0fIDN4KN8nIenFzgtLEMxN6H1CYG04s2omRJTV7TXsNIvzwUCtIQHngjg_lIfwMjKnMC-F_Aa0hcw","refresh_token":"L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ","scope":"openid","token_type":"bearer"}
2022-08-17 07:27:16 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
U-efWaYYrsEMElv0Sxcdo5TE16INjbEQFhFX7u4sC_k.I_aswLsv5u5HMtS8NX-t9TE-wbb7SrcN3TElsIwSz9zFkzOhhZ6w8Mzj1XODJ4W9e6CLzWjqMz7lnpflxGQ0Mw
expires_in
7196
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiT1h2YU9nYTVfZGJ4NkNpU0VzSXh1QSIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzYsImlhdCI6MTY2MDcyMTIzNiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI0YTUzMTYyYy0xMTdjLTQ5OTQtOGY0Yi1hMTc2NjVkODczYzYiLCJub25jZSI6ImlNektjQlcwOEkiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiItazA4Y2JFOHMtenp4RnA4M216Z0l3Iiwic19oYXNoIjoiVS04SkpOek9ZeXdhWjZ6NExKai10dyIsInN1YiI6InRlc3R1c2VyIn0.EqiqTjuanMFz_waUdgn5b2dyIE9w_74Qhhxzj2y6gMpzfBDaPVJPmYwSTYbqMyRvZh1McS_eEex56r8KF9Z6Te6_8qmkECma-6L77rXmkbRsY_lvZrV0QoWbITaHTiSXzJ5PCv2-xjAmU8c6HLQ1dnAdLE9HDZ3j_PbyIoThqio8beGzSlCjHXfXqb1nOX_8Vo8Kfk_hmVNkAxLiTI6EldIykiofd5VImmyitKUsX52HHHUC6LdsnKdEwFn3M4ET2uiXlFYkv0fIDN4KN8nIenFzgtLEMxN6H1CYG04s2omRJTV7TXsNIvzwUCtIQHngjg_lIfwMjKnMC-F_Aa0hcw
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
scope
openid
token_type
bearer
2022-08-17 07:27:16 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-08-17 07:27:16 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
U-efWaYYrsEMElv0Sxcdo5TE16INjbEQFhFX7u4sC_k.I_aswLsv5u5HMtS8NX-t9TE-wbb7SrcN3TElsIwSz9zFkzOhhZ6w8Mzj1XODJ4W9e6CLzWjqMz7lnpflxGQ0Mw
2022-08-17 07:27:16 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
U-efWaYYrsEMElv0Sxcdo5TE16INjbEQFhFX7u4sC_k.I_aswLsv5u5HMtS8NX-t9TE-wbb7SrcN3TElsIwSz9zFkzOhhZ6w8Mzj1XODJ4W9e6CLzWjqMz7lnpflxGQ0Mw
type
bearer
2022-08-17 07:27:16 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7196
2022-08-17 07:27:16 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7196
2022-08-17 07:27:16 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
2022-08-17 07:27:16 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiT1h2YU9nYTVfZGJ4NkNpU0VzSXh1QSIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzYsImlhdCI6MTY2MDcyMTIzNiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI0YTUzMTYyYy0xMTdjLTQ5OTQtOGY0Yi1hMTc2NjVkODczYzYiLCJub25jZSI6ImlNektjQlcwOEkiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiItazA4Y2JFOHMtenp4RnA4M216Z0l3Iiwic19oYXNoIjoiVS04SkpOek9ZeXdhWjZ6NExKai10dyIsInN1YiI6InRlc3R1c2VyIn0.EqiqTjuanMFz_waUdgn5b2dyIE9w_74Qhhxzj2y6gMpzfBDaPVJPmYwSTYbqMyRvZh1McS_eEex56r8KF9Z6Te6_8qmkECma-6L77rXmkbRsY_lvZrV0QoWbITaHTiSXzJ5PCv2-xjAmU8c6HLQ1dnAdLE9HDZ3j_PbyIoThqio8beGzSlCjHXfXqb1nOX_8Vo8Kfk_hmVNkAxLiTI6EldIykiofd5VImmyitKUsX52HHHUC6LdsnKdEwFn3M4ET2uiXlFYkv0fIDN4KN8nIenFzgtLEMxN6H1CYG04s2omRJTV7TXsNIvzwUCtIQHngjg_lIfwMjKnMC-F_Aa0hcw
header
{
  "kid": "rsa256",
  "typ": "JWT",
  "alg": "RS256"
}
claims
{
  "at_hash": "OXvaOga5_dbx6CiSEsIxuA",
  "aud": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "sub": "testuser",
  "s_hash": "U-8JJNzOYywaZ6z4LJj-tw",
  "rat": 1660721228,
  "auth_time": 1660719842,
  "iss": "https://isamfed.com:8843/oauth2/",
  "exp": 1660724836,
  "iat": 1660721236,
  "nonce": "iMzKcBW08I",
  "jti": "4a53162c-117c-4994-8f4b-a17665d873c6",
  "rt_hash": "-k08cbE8s-zzxFp83mzgIw"
}
2022-08-17 07:27:16 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-08-17 07:27:16
ValidateIdTokenStandardClaims
sub is a string with content
2022-08-17 07:27:16
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-08-17 07:27:16
ValidateIdTokenStandardClaims
Skipping unknown claim: rt_hash
2022-08-17 07:27:16 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-08-17 07:27:16 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
iMzKcBW08I
2022-08-17 07:27:16 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-08-17 07:27:16 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiT1h2YU9nYTVfZGJ4NkNpU0VzSXh1QSIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzYsImlhdCI6MTY2MDcyMTIzNiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI0YTUzMTYyYy0xMTdjLTQ5OTQtOGY0Yi1hMTc2NjVkODczYzYiLCJub25jZSI6ImlNektjQlcwOEkiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiItazA4Y2JFOHMtenp4RnA4M216Z0l3Iiwic19oYXNoIjoiVS04SkpOek9ZeXdhWjZ6NExKai10dyIsInN1YiI6InRlc3R1c2VyIn0.EqiqTjuanMFz_waUdgn5b2dyIE9w_74Qhhxzj2y6gMpzfBDaPVJPmYwSTYbqMyRvZh1McS_eEex56r8KF9Z6Te6_8qmkECma-6L77rXmkbRsY_lvZrV0QoWbITaHTiSXzJ5PCv2-xjAmU8c6HLQ1dnAdLE9HDZ3j_PbyIoThqio8beGzSlCjHXfXqb1nOX_8Vo8Kfk_hmVNkAxLiTI6EldIykiofd5VImmyitKUsX52HHHUC6LdsnKdEwFn3M4ET2uiXlFYkv0fIDN4KN8nIenFzgtLEMxN6H1CYG04s2omRJTV7TXsNIvzwUCtIQHngjg_lIfwMjKnMC-F_Aa0hcw
2022-08-17 07:27:16 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiT1h2YU9nYTVfZGJ4NkNpU0VzSXh1QSIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzYsImlhdCI6MTY2MDcyMTIzNiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI0YTUzMTYyYy0xMTdjLTQ5OTQtOGY0Yi1hMTc2NjVkODczYzYiLCJub25jZSI6ImlNektjQlcwOEkiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiItazA4Y2JFOHMtenp4RnA4M216Z0l3Iiwic19oYXNoIjoiVS04SkpOek9ZeXdhWjZ6NExKai10dyIsInN1YiI6InRlc3R1c2VyIn0.EqiqTjuanMFz_waUdgn5b2dyIE9w_74Qhhxzj2y6gMpzfBDaPVJPmYwSTYbqMyRvZh1McS_eEex56r8KF9Z6Te6_8qmkECma-6L77rXmkbRsY_lvZrV0QoWbITaHTiSXzJ5PCv2-xjAmU8c6HLQ1dnAdLE9HDZ3j_PbyIoThqio8beGzSlCjHXfXqb1nOX_8Vo8Kfk_hmVNkAxLiTI6EldIykiofd5VImmyitKUsX52HHHUC6LdsnKdEwFn3M4ET2uiXlFYkv0fIDN4KN8nIenFzgtLEMxN6H1CYG04s2omRJTV7TXsNIvzwUCtIQHngjg_lIfwMjKnMC-F_Aa0hcw
2022-08-17 07:27:16 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
testuser
2022-08-17 07:27:16
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-08-17 07:27:16 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-08-17 07:27:16 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
2022-08-17 07:27:16 SUCCESS
EnsureServerConfigurationSupportsRefreshToken
The server configuration indicates support for refresh tokens
supported_grant_types
[
  "authorization_code",
  "implicit",
  "password",
  "client_credentials",
  "refresh_token",
  "urn:openid:params:grant-type:ciba"
]
2022-08-17 07:27:16 SUCCESS
EnsureRefreshTokenContainsAllowedCharactersOnly
Refresh token does not contain any illegal characters
Refresh Token Request
2022-08-17 07:27:16 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
2022-08-17 07:27:16 SUCCESS
AddScopeToTokenEndpointRequest
Added scope of 'openid' to token endpoint request
grant_type
refresh_token
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
scope
openid
2022-08-17 07:27:16 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
7a2c2baa-aa8c-4654-b935-937981ceed81
sub
7a2c2baa-aa8c-4654-b935-937981ceed81
aud
https://isamfed.com:8843/oauth2/token
jti
UsLV4d2X8Ofsm57ztfTF
iat
1660721236
exp
1660721296
2022-08-17 07:27:16 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NiwiaWF0IjoxNjYwNzIxMjM2LCJqdGkiOiJVc0xWNGQyWDhPZnNtNTd6dGZURiJ9.iSS2zrMTU2wvSbg6cMH5zJWBMeM3YgMavdRP5cvOdM8wQrbJzivVIueh-JFhbIGg0XV3UWaY-cpcRDXbVnpEsuEIcE-sQH9WSrOQ1urk5bVxruiZv-H1TRYo-r_kkWskYVmMzmVH_vJkEkYD6gyu9EctlD8o6dBWuMT1HJW7nCsF3VhZXpkeSVZw86SUhRAF6-7jltjppGFNf17DwWAS7OanoDam4mqahpuO5PZ-0a9KUAujc9skQ78leVvOLq6K8W_-7SjHaQb6vRVJZBUrviULMEDRUVPQEpS2Cl3Up5xlpEpEJPIIINwEEC1Fa6tkOSGjhnrCfuVIuPqX-iEIiA
2022-08-17 07:27:16
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ
scope
openid
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NiwiaWF0IjoxNjYwNzIxMjM2LCJqdGkiOiJVc0xWNGQyWDhPZnNtNTd6dGZURiJ9.iSS2zrMTU2wvSbg6cMH5zJWBMeM3YgMavdRP5cvOdM8wQrbJzivVIueh-JFhbIGg0XV3UWaY-cpcRDXbVnpEsuEIcE-sQH9WSrOQ1urk5bVxruiZv-H1TRYo-r_kkWskYVmMzmVH_vJkEkYD6gyu9EctlD8o6dBWuMT1HJW7nCsF3VhZXpkeSVZw86SUhRAF6-7jltjppGFNf17DwWAS7OanoDam4mqahpuO5PZ-0a9KUAujc9skQ78leVvOLq6K8W_-7SjHaQb6vRVJZBUrviULMEDRUVPQEpS2Cl3Up5xlpEpEJPIIINwEEC1Fa6tkOSGjhnrCfuVIuPqX-iEIiA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-08-17 07:27:16 SUCCESS
WaitForOneSecond
Pausing for 1 seconds
2022-08-17 07:27:17 SUCCESS
WaitForOneSecond
Woke up after 1 seconds sleep
2022-08-17 07:27:17
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://isamfed.com:8843/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "923"
}
request_body
grant_type=refresh_token&refresh_token=L-rIf2whVIdBJioYlq0bqwGc53KcDGMlcAbvWr755K4.Nbm4S0wA2GqhHsqHSi3hAdY7gdtcO2gV_eSP3FJKvu4iGLMZF7Y9So33vifGvsBUZxA94F4KUKcqr6pvVepAKQ&scope=openid&client_assertion=eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTI5NiwiaWF0IjoxNjYwNzIxMjM2LCJqdGkiOiJVc0xWNGQyWDhPZnNtNTd6dGZURiJ9.iSS2zrMTU2wvSbg6cMH5zJWBMeM3YgMavdRP5cvOdM8wQrbJzivVIueh-JFhbIGg0XV3UWaY-cpcRDXbVnpEsuEIcE-sQH9WSrOQ1urk5bVxruiZv-H1TRYo-r_kkWskYVmMzmVH_vJkEkYD6gyu9EctlD8o6dBWuMT1HJW7nCsF3VhZXpkeSVZw86SUhRAF6-7jltjppGFNf17DwWAS7OanoDam4mqahpuO5PZ-0a9KUAujc9skQ78leVvOLq6K8W_-7SjHaQb6vRVJZBUrviULMEDRUVPQEpS2Cl3Up5xlpEpEJPIIINwEEC1Fa6tkOSGjhnrCfuVIuPqX-iEIiA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-08-17 07:27:18 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "1163",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:18 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-d28f6ef9-6e77-4b88-98b4-734e897facef",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"access_token":"97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w","expires_in":7199,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiTnpFYnJhSWVKbUZoT1JXY0pBSDI2USIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzgsImlhdCI6MTY2MDcyMTIzOCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiJmMDExYWRjOC01NTIyLTQxMzAtODFiYy0xYTdmNjY3MTlhZjIiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiJJcy1HQXJTbXpMcExoNEFuZlp2eGlRIiwic3ViIjoidGVzdHVzZXIifQ.OIAR2pvgT74yzq38F6zN3X1qr5XSsyWbpcwd1ZbTjZ74Unas06l8ga-IqoSudyAUBMVEgOjA1m9F4kWFaZ42M4sqWnrOkvI1IyqTiuKBRjh-lj1KWnRvQWMIHcPAwBXNg2KGk6A3YWHM_ERS1m0oNrIe7BJUS9Iym7Npg182COFSfA3jpz3q0WOQW_3J6L_6-Jcslga400VyqGbzU2ALnYDDSRK-k3f12JKpXDHa9dJwTaM3RHJ5o9_k7eDrju0OU4DoM5F3oc94YB_ygLAt81ZRtFGOZjqMyZUA7ZqzQ2-q8h8Qq_2Vac2K8CcKODfJ8dO7UyOYX5DaI7-jhddcmw","refresh_token":"m8VEmXMaWgIjSOL2P47vF7xr_-DuRUHESuu9C33Vwlg.IYaV5Pv7lPFcyCFIUkHOqgGMW9Fc4H3f84kWvKCQrSMxYOE6N3qY2jls33_sVXLYpqH4YautpsNhjZwVD12m7Q","scope":"openid","token_type":"bearer"}
2022-08-17 07:27:18 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w
expires_in
7199
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiTnpFYnJhSWVKbUZoT1JXY0pBSDI2USIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzgsImlhdCI6MTY2MDcyMTIzOCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiJmMDExYWRjOC01NTIyLTQxMzAtODFiYy0xYTdmNjY3MTlhZjIiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiJJcy1HQXJTbXpMcExoNEFuZlp2eGlRIiwic3ViIjoidGVzdHVzZXIifQ.OIAR2pvgT74yzq38F6zN3X1qr5XSsyWbpcwd1ZbTjZ74Unas06l8ga-IqoSudyAUBMVEgOjA1m9F4kWFaZ42M4sqWnrOkvI1IyqTiuKBRjh-lj1KWnRvQWMIHcPAwBXNg2KGk6A3YWHM_ERS1m0oNrIe7BJUS9Iym7Npg182COFSfA3jpz3q0WOQW_3J6L_6-Jcslga400VyqGbzU2ALnYDDSRK-k3f12JKpXDHa9dJwTaM3RHJ5o9_k7eDrju0OU4DoM5F3oc94YB_ygLAt81ZRtFGOZjqMyZUA7ZqzQ2-q8h8Qq_2Vac2K8CcKODfJ8dO7UyOYX5DaI7-jhddcmw
refresh_token
m8VEmXMaWgIjSOL2P47vF7xr_-DuRUHESuu9C33Vwlg.IYaV5Pv7lPFcyCFIUkHOqgGMW9Fc4H3f84kWvKCQrSMxYOE6N3qY2jls33_sVXLYpqH4YautpsNhjZwVD12m7Q
scope
openid
token_type
bearer
2022-08-17 07:27:18 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2022-08-17 07:27:18 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2022-08-17 07:27:18 SUCCESS
CheckTokenEndpointCacheHeaders
'cache-control' header in token endpoint response contains expected value.
cache_control_header
no-store
2022-08-17 07:27:18 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-08-17 07:27:18 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w
type
bearer
2022-08-17 07:27:18 SUCCESS
CheckTokenTypeIsBearer
Token type is bearer
2022-08-17 07:27:18 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
730.0656258020439
expected
96.0
value
97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w
2022-08-17 07:27:18 SUCCESS
EnsureAccessTokenContainsAllowedCharactersOnly
Access token does not contain any illegal characters
2022-08-17 07:27:18 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2022-08-17 07:27:18 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2022-08-17 07:27:18 SUCCESS
EnsureAccessTokenValuesAreDifferent
Access token values are not the same
first_access_token
U-efWaYYrsEMElv0Sxcdo5TE16INjbEQFhFX7u4sC_k.I_aswLsv5u5HMtS8NX-t9TE-wbb7SrcN3TElsIwSz9zFkzOhhZ6w8Mzj1XODJ4W9e6CLzWjqMz7lnpflxGQ0Mw
second_access_token
97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w
2022-08-17 07:27:18 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiTnpFYnJhSWVKbUZoT1JXY0pBSDI2USIsImF1ZCI6WyI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4MzgsImlhdCI6MTY2MDcyMTIzOCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiJmMDExYWRjOC01NTIyLTQxMzAtODFiYy0xYTdmNjY3MTlhZjIiLCJyYXQiOjE2NjA3MjEyMjgsInJ0X2hhc2giOiJJcy1HQXJTbXpMcExoNEFuZlp2eGlRIiwic3ViIjoidGVzdHVzZXIifQ.OIAR2pvgT74yzq38F6zN3X1qr5XSsyWbpcwd1ZbTjZ74Unas06l8ga-IqoSudyAUBMVEgOjA1m9F4kWFaZ42M4sqWnrOkvI1IyqTiuKBRjh-lj1KWnRvQWMIHcPAwBXNg2KGk6A3YWHM_ERS1m0oNrIe7BJUS9Iym7Npg182COFSfA3jpz3q0WOQW_3J6L_6-Jcslga400VyqGbzU2ALnYDDSRK-k3f12JKpXDHa9dJwTaM3RHJ5o9_k7eDrju0OU4DoM5F3oc94YB_ygLAt81ZRtFGOZjqMyZUA7ZqzQ2-q8h8Qq_2Vac2K8CcKODfJ8dO7UyOYX5DaI7-jhddcmw
header
{
  "kid": "rsa256",
  "typ": "JWT",
  "alg": "RS256"
}
claims
{
  "at_hash": "NzEbraIeJmFhORWcJAH26Q",
  "aud": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "sub": "testuser",
  "rat": 1660721228,
  "auth_time": 1660719842,
  "iss": "https://isamfed.com:8843/oauth2/",
  "exp": 1660724838,
  "iat": 1660721238,
  "jti": "f011adc8-5522-4130-81bc-1a7f66719af2",
  "rt_hash": "Is-GArSmzLpLh4AnfZvxiQ"
}
2022-08-17 07:27:18 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
m8VEmXMaWgIjSOL2P47vF7xr_-DuRUHESuu9C33Vwlg.IYaV5Pv7lPFcyCFIUkHOqgGMW9Fc4H3f84kWvKCQrSMxYOE6N3qY2jls33_sVXLYpqH4YautpsNhjZwVD12m7Q
2022-08-17 07:27:18 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
1040
required
128
2022-08-17 07:27:18 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
723.3456722037198
expected
96.0
value
m8VEmXMaWgIjSOL2P47vF7xr_-DuRUHESuu9C33Vwlg.IYaV5Pv7lPFcyCFIUkHOqgGMW9Fc4H3f84kWvKCQrSMxYOE6N3qY2jls33_sVXLYpqH4YautpsNhjZwVD12m7Q
2022-08-17 07:27:18 SUCCESS
CompareIdTokenClaims
Validated id token claims successfully
iss
{
  "first": "https://isamfed.com:8843/oauth2/",
  "second": "https://isamfed.com:8843/oauth2/",
  "note": "Values are expected to be equal"
}
sub
{
  "first": "testuser",
  "second": "testuser",
  "note": "Values are expected to be equal"
}
iat
{
  "first": 1660721236,
  "second": 1660721238,
  "note": "Values are expected to be different"
}
aud
{
  "first": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "second": "7a2c2baa-aa8c-4654-b935-937981ceed81",
  "note": "Values are expected to be equal"
}
auth_time
{
  "first": 1660719842,
  "second": 1660719842,
  "note": "Values are expected to be equal"
}
azp
Id tokens do not contain azp claims
Userinfo endpoint tests
2022-08-17 07:27:18
CallProtectedResource
HTTP request
request_uri
https://isamfed.com:8843/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer 97cDIto9Mp1W2pZNrrudBUlq1lI9NJq2zNeZ1UkO60w.wzB2B7zpDxsy5JCL794j5kRbQPLBxTMnbKl92xwVj1EoUYIIlygYKGivShIBAowAPtCjAP4ijNPjuv-K4WvU8w",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:19 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:19 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-39830d72-d753-44b4-99b9-c3583c3ac9c0",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"aud":["7a2c2baa-aa8c-4654-b935-937981ceed81"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721228,"sub":"testuser"}
2022-08-17 07:27:19 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:19 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-39830d72-d753-44b4-99b9-c3583c3ac9c0",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
body
{"aud":["7a2c2baa-aa8c-4654-b935-937981ceed81"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721228,"sub":"testuser"}
2022-08-17 07:27:19 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
Second client: Make request to authorization endpoint
2022-08-17 07:27:19 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
4f84e8e1-f965-4611-9fbc-eff60f14e763
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
2022-08-17 07:27:19
CreateRandomStateValue
Created state value
requested_state_length
10
state
lgWCqjSSvn
2022-08-17 07:27:19 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
4f84e8e1-f965-4611-9fbc-eff60f14e763
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
lgWCqjSSvn
2022-08-17 07:27:19
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
U1IOhre7Ux
2022-08-17 07:27:19 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
4f84e8e1-f965-4611-9fbc-eff60f14e763
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
lgWCqjSSvn
nonce
U1IOhre7Ux
2022-08-17 07:27:19 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
4f84e8e1-f965-4611-9fbc-eff60f14e763
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
scope
openid
state
lgWCqjSSvn
nonce
U1IOhre7Ux
response_type
code token
2022-08-17 07:27:19 SUCCESS
AddPromptConsentToAuthorizationEndpointRequestIfScopeContainsOfflineAccess
Not adding prompt=consent as the scope in the configuration does not contain offline_access
2022-08-17 07:27:19 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "redirect_uri": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback",
  "scope": "openid",
  "state": "lgWCqjSSvn",
  "nonce": "U1IOhre7Ux",
  "response_type": "code token"
}
redirect_to_authorization_endpoint
https://isamfed.com:8843/oauth2/authorize?client_id=4f84e8e1-f965-4611-9fbc-eff60f14e763&redirect_uri=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback&scope=openid&state=lgWCqjSSvn&nonce=U1IOhre7Ux&response_type=code%20token
2022-08-17 07:27:19 REDIRECT
oidcc-refresh-token
Redirecting to authorization endpoint
redirect_to
https://isamfed.com:8843/oauth2/authorize?client_id=4f84e8e1-f965-4611-9fbc-eff60f14e763&redirect_uri=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback&scope=openid&state=lgWCqjSSvn&nonce=U1IOhre7Ux&response_type=code%20token
2022-08-17 07:27:39 INCOMING
oidcc-refresh-token
Incoming HTTP request to /test/a/isva_op_oidc_core_test_gh/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"macOS\"",
  "referer": "https://isamfed.com:8843/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "connection": "close"
}
incoming_path
/test/a/isva_op_oidc_core_test_gh/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-08-17 07:27:39 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/XE1izO48ipboKYNQIRwM",
  "fullUrl": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/implicit/XE1izO48ipboKYNQIRwM"
}
2022-08-17 07:27:39 OUTGOING
oidcc-refresh-token
Response to HTTP request to test instance bGm6dI6LfgPQo8I
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/implicit/XE1izO48ipboKYNQIRwM, returnUrl=/log-detail.html?log=bGm6dI6LfgPQo8I}]
outgoing_path
callback
2022-08-17 07:27:40 INCOMING
oidcc-refresh-token
Incoming HTTP request to /test/a/isva_op_oidc_core_test_gh/implicit/XE1izO48ipboKYNQIRwM
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"macOS\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "connection": "close",
  "content-length": "344"
}
incoming_path
/test/a/isva_op_oidc_core_test_gh/implicit/XE1izO48ipboKYNQIRwM
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#access_token=nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning&code=XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA&expires_in=7199&scope=openid&state=lgWCqjSSvn&token_type=bearer
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-08-17 07:27:40 OUTGOING
oidcc-refresh-token
Response to HTTP request to test instance bGm6dI6LfgPQo8I
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/XE1izO48ipboKYNQIRwM
2022-08-17 07:27:40
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "access_token",
    "value": "nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning"
  },
  {
    "name": "code",
    "value": "XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA"
  },
  {
    "name": "expires_in",
    "value": "7199"
  },
  {
    "name": "scope",
    "value": "openid"
  },
  {
    "name": "state",
    "value": "lgWCqjSSvn"
  },
  {
    "name": "token_type",
    "value": "bearer"
  }
]
2022-08-17 07:27:40 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
access_token
nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning
code
XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA
expires_in
7199
scope
openid
state
lgWCqjSSvn
token_type
bearer
2022-08-17 07:27:40 REDIRECT-IN
oidcc-refresh-token
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Chromium\";v\u003d\"104\", \" Not A;Brand\";v\u003d\"99\", \"Google Chrome\";v\u003d\"104\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"macOS\"",
  "referer": "https://isamfed.com:8843/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh;q\u003d0.8",
  "cookie": "__utmc\u003d201319536; __utmz\u003d201319536.1660191481.2.2.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utma\u003d201319536.1003316269.1659326830.1660191481.1660648933.3; JSESSIONID\u003d991B293FC0AEF736DB7A349F282D96D4",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "access_token": "nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning",
  "code": "XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA",
  "expires_in": "7199",
  "scope": "openid",
  "state": "lgWCqjSSvn",
  "token_type": "bearer"
}
post_body
Second client: Verify authorization endpoint response
2022-08-17 07:27:40 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-08-17 07:27:40 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-08-17 07:27:40 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-08-17 07:27:40
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2022-08-17 07:27:40 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-08-17 07:27:40 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
lgWCqjSSvn
2022-08-17 07:27:40 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA
2022-08-17 07:27:40 SUCCESS
ExtractAccessTokenFromAuthorizationResponse
Extracted the access token
value
nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning
type
bearer
Second client: Userinfo endpoint tests
2022-08-17 07:27:40
CallProtectedResource
HTTP request
request_uri
https://isamfed.com:8843/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer nEtDr06YMDMsV7tG7WxxQQsyiZ3b_RIOOnhXMfJtJys.NEt_2m5iJuhC8cMmQMsFSsuPEn_cmfhsF3i3TPVuTDoMbIBH8a_vaXfeosg-vnuDGaGeXOjgxIdR4HoSWoning",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:41 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:41 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-f85234f7-99da-463b-9207-9d0453264dcb",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"aud":["4f84e8e1-f965-4611-9fbc-eff60f14e763"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721255,"sub":"testuser"}
2022-08-17 07:27:41 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:41 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-f85234f7-99da-463b-9207-9d0453264dcb",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
body
{"aud":["4f84e8e1-f965-4611-9fbc-eff60f14e763"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721255,"sub":"testuser"}
2022-08-17 07:27:41 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-08-17 07:27:41 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
2022-08-17 07:27:41 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
4f84e8e1-f965-4611-9fbc-eff60f14e763
sub
4f84e8e1-f965-4611-9fbc-eff60f14e763
aud
https://isamfed.com:8843/oauth2/token
jti
M8FTKfQM2n06G5C1PZZR
iat
1660721261
exp
1660721321
2022-08-17 07:27:41 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMSwiaWF0IjoxNjYwNzIxMjYxLCJqdGkiOiJNOEZUS2ZRTTJuMDZHNUMxUFpaUiJ9.jX4gQEJm6RqgFH1hA3yCPZsaZGzSqx6glAa3v9zYxRkOOUApiIx4llWiQk0ttEGApG54TDIPPAt7b70QdzCsdE_GYKq2BmzBVsHN-WdVseAdijvyPbDXk6EBWVQxlVvcy1YT8YjD3tIWDWNUO8x61Mxgf8F20QknrJTHXtjPfcD945Y2tXWXNZuk_E9nW3ADl786Ox3C__sZKtCVAojCJgXCpVtsP6ln0jJJlKRTQYF2ayoY3096xTovP479XgZWdQ2pX1IxHsmwjfsdPD80xg_x3fjRGDr5fwhai3FojOo2U4l0WR0DmxAHR4XicG1MFfpJpfa1UHqKLihZvF2MMg
2022-08-17 07:27:41
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA
redirect_uri
https://www.certification.openid.net/test/a/isva_op_oidc_core_test_gh/callback
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMSwiaWF0IjoxNjYwNzIxMjYxLCJqdGkiOiJNOEZUS2ZRTTJuMDZHNUMxUFpaUiJ9.jX4gQEJm6RqgFH1hA3yCPZsaZGzSqx6glAa3v9zYxRkOOUApiIx4llWiQk0ttEGApG54TDIPPAt7b70QdzCsdE_GYKq2BmzBVsHN-WdVseAdijvyPbDXk6EBWVQxlVvcy1YT8YjD3tIWDWNUO8x61Mxgf8F20QknrJTHXtjPfcD945Y2tXWXNZuk_E9nW3ADl786Ox3C__sZKtCVAojCJgXCpVtsP6ln0jJJlKRTQYF2ayoY3096xTovP479XgZWdQ2pX1IxHsmwjfsdPD80xg_x3fjRGDr5fwhai3FojOo2U4l0WR0DmxAHR4XicG1MFfpJpfa1UHqKLihZvF2MMg
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-08-17 07:27:41
CallTokenEndpoint
HTTP request
request_uri
https://isamfed.com:8843/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "1012"
}
request_body
grant_type=authorization_code&code=XRchHH0ZwJLzldfxeLkioktsmFvfGBnw4kBvDbt03vE.qd_6XZxMIMM2qZotYtRMQP9B7fM9qpdCOueJC40LpyVX-hohajoMrmqh02vjC6YA8pMpmEXBI5XagoASiwk2MA&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fisva_op_oidc_core_test_gh%2Fcallback&client_assertion=eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMSwiaWF0IjoxNjYwNzIxMjYxLCJqdGkiOiJNOEZUS2ZRTTJuMDZHNUMxUFpaUiJ9.jX4gQEJm6RqgFH1hA3yCPZsaZGzSqx6glAa3v9zYxRkOOUApiIx4llWiQk0ttEGApG54TDIPPAt7b70QdzCsdE_GYKq2BmzBVsHN-WdVseAdijvyPbDXk6EBWVQxlVvcy1YT8YjD3tIWDWNUO8x61Mxgf8F20QknrJTHXtjPfcD945Y2tXWXNZuk_E9nW3ADl786Ox3C__sZKtCVAojCJgXCpVtsP6ln0jJJlKRTQYF2ayoY3096xTovP479XgZWdQ2pX1IxHsmwjfsdPD80xg_x3fjRGDr5fwhai3FojOo2U4l0WR0DmxAHR4XicG1MFfpJpfa1UHqKLihZvF2MMg&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-08-17 07:27:42 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "1236",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:42 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-d9575a44-5146-4fdc-bb78-2ad69b48132f",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"access_token":"MJHDjYMF1sL1zDO1tX1oSzE-Kv2W8Knxy6agHI4LprY.p0wn_IN_Zv5ZbMsp5kPhNY0W5WlGU6U85paO-tjOsIXvUHgC9oNophDxEuiZ86V4i4KPbhond0zwwvwNzVaRzA","expires_in":7196,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiRk1MZnlJSkVSMVpnWDdTZVcyTzZwdyIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjIsImlhdCI6MTY2MDcyMTI2MiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiIxN2RmYzExZC0xZTRhLTQ4OGMtYjAzYy0zNjI3YjMyMzM2YzAiLCJub25jZSI6IlUxSU9ocmU3VXgiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJyMnRsbUtWWHNHMFZNQlRPXzk4SzN3Iiwic19oYXNoIjoiVU5qTTV0VHlUbVZ2bmlrdWJybUZaUSIsInN1YiI6InRlc3R1c2VyIn0.DrGQlnH72UXRCJamx_wl-bdWIDYhefveu7EBtPWIsHv-40BhwkdfPti3Yy5Lc-f0Zd6NOjdhpmNqY6UQgluK_GSJGJFSvOFsrq9r_prbftWOSk0VhE45A3F6CJnkT2vZkd0MPT4LWAd5vOdzvqD-rGQOMOyGxE6HyeV5vhvNu0GNVrlkT_DNET8fKolWoXpYfPsdZ3yuLzXk_6zwqd93NtIznd71xPLGDdz5VwHyUe6v5_QpBslsJOYOFtlFBeKTy5ALBF-Su2PDLz_49Iqu6efk0b3jOzimpmXElVHM5Y3GovzFSGk9tJbScCtjMoVrS9-TkjFI7NSf4BnDYkSO_w","refresh_token":"rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg","scope":"openid","token_type":"bearer"}
2022-08-17 07:27:42 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
MJHDjYMF1sL1zDO1tX1oSzE-Kv2W8Knxy6agHI4LprY.p0wn_IN_Zv5ZbMsp5kPhNY0W5WlGU6U85paO-tjOsIXvUHgC9oNophDxEuiZ86V4i4KPbhond0zwwvwNzVaRzA
expires_in
7196
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiRk1MZnlJSkVSMVpnWDdTZVcyTzZwdyIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjIsImlhdCI6MTY2MDcyMTI2MiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiIxN2RmYzExZC0xZTRhLTQ4OGMtYjAzYy0zNjI3YjMyMzM2YzAiLCJub25jZSI6IlUxSU9ocmU3VXgiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJyMnRsbUtWWHNHMFZNQlRPXzk4SzN3Iiwic19oYXNoIjoiVU5qTTV0VHlUbVZ2bmlrdWJybUZaUSIsInN1YiI6InRlc3R1c2VyIn0.DrGQlnH72UXRCJamx_wl-bdWIDYhefveu7EBtPWIsHv-40BhwkdfPti3Yy5Lc-f0Zd6NOjdhpmNqY6UQgluK_GSJGJFSvOFsrq9r_prbftWOSk0VhE45A3F6CJnkT2vZkd0MPT4LWAd5vOdzvqD-rGQOMOyGxE6HyeV5vhvNu0GNVrlkT_DNET8fKolWoXpYfPsdZ3yuLzXk_6zwqd93NtIznd71xPLGDdz5VwHyUe6v5_QpBslsJOYOFtlFBeKTy5ALBF-Su2PDLz_49Iqu6efk0b3jOzimpmXElVHM5Y3GovzFSGk9tJbScCtjMoVrS9-TkjFI7NSf4BnDYkSO_w
refresh_token
rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg
scope
openid
token_type
bearer
2022-08-17 07:27:42 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-08-17 07:27:42 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
MJHDjYMF1sL1zDO1tX1oSzE-Kv2W8Knxy6agHI4LprY.p0wn_IN_Zv5ZbMsp5kPhNY0W5WlGU6U85paO-tjOsIXvUHgC9oNophDxEuiZ86V4i4KPbhond0zwwvwNzVaRzA
2022-08-17 07:27:42 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
MJHDjYMF1sL1zDO1tX1oSzE-Kv2W8Knxy6agHI4LprY.p0wn_IN_Zv5ZbMsp5kPhNY0W5WlGU6U85paO-tjOsIXvUHgC9oNophDxEuiZ86V4i4KPbhond0zwwvwNzVaRzA
type
bearer
2022-08-17 07:27:42 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7196
2022-08-17 07:27:42 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7196
2022-08-17 07:27:42 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg
2022-08-17 07:27:42 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiRk1MZnlJSkVSMVpnWDdTZVcyTzZwdyIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjIsImlhdCI6MTY2MDcyMTI2MiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiIxN2RmYzExZC0xZTRhLTQ4OGMtYjAzYy0zNjI3YjMyMzM2YzAiLCJub25jZSI6IlUxSU9ocmU3VXgiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJyMnRsbUtWWHNHMFZNQlRPXzk4SzN3Iiwic19oYXNoIjoiVU5qTTV0VHlUbVZ2bmlrdWJybUZaUSIsInN1YiI6InRlc3R1c2VyIn0.DrGQlnH72UXRCJamx_wl-bdWIDYhefveu7EBtPWIsHv-40BhwkdfPti3Yy5Lc-f0Zd6NOjdhpmNqY6UQgluK_GSJGJFSvOFsrq9r_prbftWOSk0VhE45A3F6CJnkT2vZkd0MPT4LWAd5vOdzvqD-rGQOMOyGxE6HyeV5vhvNu0GNVrlkT_DNET8fKolWoXpYfPsdZ3yuLzXk_6zwqd93NtIznd71xPLGDdz5VwHyUe6v5_QpBslsJOYOFtlFBeKTy5ALBF-Su2PDLz_49Iqu6efk0b3jOzimpmXElVHM5Y3GovzFSGk9tJbScCtjMoVrS9-TkjFI7NSf4BnDYkSO_w
header
{
  "kid": "rsa256",
  "typ": "JWT",
  "alg": "RS256"
}
claims
{
  "at_hash": "FMLfyIJER1ZgX7SeW2O6pw",
  "aud": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "sub": "testuser",
  "s_hash": "UNjM5tTyTmVvnikubrmFZQ",
  "rat": 1660721255,
  "auth_time": 1660719842,
  "iss": "https://isamfed.com:8843/oauth2/",
  "exp": 1660724862,
  "iat": 1660721262,
  "nonce": "U1IOhre7Ux",
  "jti": "17dfc11d-1e4a-488c-b03c-3627b32336c0",
  "rt_hash": "r2tlmKVXsG0VMBTO_98K3w"
}
2022-08-17 07:27:42 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-08-17 07:27:42
ValidateIdTokenStandardClaims
sub is a string with content
2022-08-17 07:27:42
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-08-17 07:27:42
ValidateIdTokenStandardClaims
Skipping unknown claim: rt_hash
2022-08-17 07:27:42 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-08-17 07:27:42 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
U1IOhre7Ux
2022-08-17 07:27:42 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-08-17 07:27:42 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiRk1MZnlJSkVSMVpnWDdTZVcyTzZwdyIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjIsImlhdCI6MTY2MDcyMTI2MiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiIxN2RmYzExZC0xZTRhLTQ4OGMtYjAzYy0zNjI3YjMyMzM2YzAiLCJub25jZSI6IlUxSU9ocmU3VXgiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJyMnRsbUtWWHNHMFZNQlRPXzk4SzN3Iiwic19oYXNoIjoiVU5qTTV0VHlUbVZ2bmlrdWJybUZaUSIsInN1YiI6InRlc3R1c2VyIn0.DrGQlnH72UXRCJamx_wl-bdWIDYhefveu7EBtPWIsHv-40BhwkdfPti3Yy5Lc-f0Zd6NOjdhpmNqY6UQgluK_GSJGJFSvOFsrq9r_prbftWOSk0VhE45A3F6CJnkT2vZkd0MPT4LWAd5vOdzvqD-rGQOMOyGxE6HyeV5vhvNu0GNVrlkT_DNET8fKolWoXpYfPsdZ3yuLzXk_6zwqd93NtIznd71xPLGDdz5VwHyUe6v5_QpBslsJOYOFtlFBeKTy5ALBF-Su2PDLz_49Iqu6efk0b3jOzimpmXElVHM5Y3GovzFSGk9tJbScCtjMoVrS9-TkjFI7NSf4BnDYkSO_w
2022-08-17 07:27:42 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiRk1MZnlJSkVSMVpnWDdTZVcyTzZwdyIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjIsImlhdCI6MTY2MDcyMTI2MiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiIxN2RmYzExZC0xZTRhLTQ4OGMtYjAzYy0zNjI3YjMyMzM2YzAiLCJub25jZSI6IlUxSU9ocmU3VXgiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJyMnRsbUtWWHNHMFZNQlRPXzk4SzN3Iiwic19oYXNoIjoiVU5qTTV0VHlUbVZ2bmlrdWJybUZaUSIsInN1YiI6InRlc3R1c2VyIn0.DrGQlnH72UXRCJamx_wl-bdWIDYhefveu7EBtPWIsHv-40BhwkdfPti3Yy5Lc-f0Zd6NOjdhpmNqY6UQgluK_GSJGJFSvOFsrq9r_prbftWOSk0VhE45A3F6CJnkT2vZkd0MPT4LWAd5vOdzvqD-rGQOMOyGxE6HyeV5vhvNu0GNVrlkT_DNET8fKolWoXpYfPsdZ3yuLzXk_6zwqd93NtIznd71xPLGDdz5VwHyUe6v5_QpBslsJOYOFtlFBeKTy5ALBF-Su2PDLz_49Iqu6efk0b3jOzimpmXElVHM5Y3GovzFSGk9tJbScCtjMoVrS9-TkjFI7NSf4BnDYkSO_w
2022-08-17 07:27:42 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
testuser
2022-08-17 07:27:42
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-08-17 07:27:42 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-08-17 07:27:42 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg
2022-08-17 07:27:42 SUCCESS
EnsureServerConfigurationSupportsRefreshToken
The server configuration indicates support for refresh tokens
supported_grant_types
[
  "authorization_code",
  "implicit",
  "password",
  "client_credentials",
  "refresh_token",
  "urn:openid:params:grant-type:ciba"
]
2022-08-17 07:27:42 SUCCESS
EnsureRefreshTokenContainsAllowedCharactersOnly
Refresh token does not contain any illegal characters
Second client: Refresh Token Request
2022-08-17 07:27:42 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg
2022-08-17 07:27:42 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
4f84e8e1-f965-4611-9fbc-eff60f14e763
sub
4f84e8e1-f965-4611-9fbc-eff60f14e763
aud
https://isamfed.com:8843/oauth2/token
jti
GcghFGLx8822jz07uY3a
iat
1660721262
exp
1660721322
2022-08-17 07:27:42 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMiwiaWF0IjoxNjYwNzIxMjYyLCJqdGkiOiJHY2doRkdMeDg4MjJqejA3dVkzYSJ9.wd63Iim3m0Bu8-aO7KsEj2lMnPLIPOm5gHmBCpCgEv1aCyY8gRbobjh4FN7GVAnpvfdufw_7oFhZc9cd-U33votQ3CcEqfUa8XyOt9amQwGLnj2jjnb2kFKlL0-t6szSmYQ2l62EXPT3BcqmJk8j1Vi6J03NcTOsZHmEtD_S2mi7_iz72CJHM88g1ASzuTrh8zmRnG5d5iVGcaTbVAFbUDTTRYblZOOP3iNXyYBg2XlGI7w_lGlG-xQDkZA-rzoXahhe8AZHg0iH3diZgCndeJGz8ALnhkMdFgeJIbQ35e3_WXqPG_v1hlljrKq7JZ5lRgPfhqi-9R47o9XXdE9pWQ
2022-08-17 07:27:42
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMiwiaWF0IjoxNjYwNzIxMjYyLCJqdGkiOiJHY2doRkdMeDg4MjJqejA3dVkzYSJ9.wd63Iim3m0Bu8-aO7KsEj2lMnPLIPOm5gHmBCpCgEv1aCyY8gRbobjh4FN7GVAnpvfdufw_7oFhZc9cd-U33votQ3CcEqfUa8XyOt9amQwGLnj2jjnb2kFKlL0-t6szSmYQ2l62EXPT3BcqmJk8j1Vi6J03NcTOsZHmEtD_S2mi7_iz72CJHM88g1ASzuTrh8zmRnG5d5iVGcaTbVAFbUDTTRYblZOOP3iNXyYBg2XlGI7w_lGlG-xQDkZA-rzoXahhe8AZHg0iH3diZgCndeJGz8ALnhkMdFgeJIbQ35e3_WXqPG_v1hlljrKq7JZ5lRgPfhqi-9R47o9XXdE9pWQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-08-17 07:27:42 SUCCESS
WaitForOneSecond
Pausing for 1 seconds
2022-08-17 07:27:43 SUCCESS
WaitForOneSecond
Woke up after 1 seconds sleep
2022-08-17 07:27:43
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://isamfed.com:8843/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "910"
}
request_body
grant_type=refresh_token&refresh_token=rOnzcZkCX5PTUmKaW_ZA5AC_RTvwrUbjWckJW_KnPAM.i_mHA2dnpDCfxXFSIWfjwf1VjgyuWklurODNYVIocUtzS7vv9ApIZtD77fABeXdTRpYNE_zAEJS4cbeeV4qQTg&client_assertion=eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjRmODRlOGUxLWY5NjUtNDYxMS05ZmJjLWVmZjYwZjE0ZTc2MyIsImV4cCI6MTY2MDcyMTMyMiwiaWF0IjoxNjYwNzIxMjYyLCJqdGkiOiJHY2doRkdMeDg4MjJqejA3dVkzYSJ9.wd63Iim3m0Bu8-aO7KsEj2lMnPLIPOm5gHmBCpCgEv1aCyY8gRbobjh4FN7GVAnpvfdufw_7oFhZc9cd-U33votQ3CcEqfUa8XyOt9amQwGLnj2jjnb2kFKlL0-t6szSmYQ2l62EXPT3BcqmJk8j1Vi6J03NcTOsZHmEtD_S2mi7_iz72CJHM88g1ASzuTrh8zmRnG5d5iVGcaTbVAFbUDTTRYblZOOP3iNXyYBg2XlGI7w_lGlG-xQDkZA-rzoXahhe8AZHg0iH3diZgCndeJGz8ALnhkMdFgeJIbQ35e3_WXqPG_v1hlljrKq7JZ5lRgPfhqi-9R47o9XXdE9pWQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-08-17 07:27:44 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "1163",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:44 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-c6404b3e-7cde-4150-bbef-789111bb9728",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"access_token":"KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg","expires_in":7200,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiLUhubTFsMnRWa1NEOThzQjBNRTFoQSIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjQsImlhdCI6MTY2MDcyMTI2NCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI3MTVhYjJmMC02NzEwLTRkYWMtYmNkYS05MzI4MjI1NzE0MDIiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJXRHhZN2dTOFZNUlNrSGZfOUd6eUp3Iiwic3ViIjoidGVzdHVzZXIifQ.RMEjLBkHUK0kipoQe31dOCyBxUPzdxttP3hIZyxmFaZtP1X70k6soY2i6uFfiELIiSySSX7NMBoe5tKI9FEUbzZ2nHgqOVUypiB5twxWxc15nc7Y5pIPi1sRTSMmHeu-0KotEYmUdouHjpuu18AUmukedPzayvgLZUYmDQuZ0GcCJYGFrs_1DcwQk2VU6y4NbjcEOGTlxEQ5vE7TRR7kZJfek5BQ0h2GkNPDSH1D-X_ou0f025aV95Mf47lCzbLY4mqnub_g1Td5UXTTS9xRX6R1wUluX4XmrHTb5oevcUsDJ5HSY4hZXq3aumz7TuVtbMXacgVj_3Kjj80QnVzjmA","refresh_token":"OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ","scope":"openid","token_type":"bearer"}
2022-08-17 07:27:44 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
access_token
KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg
expires_in
7200
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiLUhubTFsMnRWa1NEOThzQjBNRTFoQSIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjQsImlhdCI6MTY2MDcyMTI2NCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI3MTVhYjJmMC02NzEwLTRkYWMtYmNkYS05MzI4MjI1NzE0MDIiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJXRHhZN2dTOFZNUlNrSGZfOUd6eUp3Iiwic3ViIjoidGVzdHVzZXIifQ.RMEjLBkHUK0kipoQe31dOCyBxUPzdxttP3hIZyxmFaZtP1X70k6soY2i6uFfiELIiSySSX7NMBoe5tKI9FEUbzZ2nHgqOVUypiB5twxWxc15nc7Y5pIPi1sRTSMmHeu-0KotEYmUdouHjpuu18AUmukedPzayvgLZUYmDQuZ0GcCJYGFrs_1DcwQk2VU6y4NbjcEOGTlxEQ5vE7TRR7kZJfek5BQ0h2GkNPDSH1D-X_ou0f025aV95Mf47lCzbLY4mqnub_g1Td5UXTTS9xRX6R1wUluX4XmrHTb5oevcUsDJ5HSY4hZXq3aumz7TuVtbMXacgVj_3Kjj80QnVzjmA
refresh_token
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
scope
openid
token_type
bearer
2022-08-17 07:27:44 SUCCESS
CheckTokenEndpointHttpStatus200
Token endpoint http status code was 200
2022-08-17 07:27:44 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2022-08-17 07:27:44 SUCCESS
CheckTokenEndpointCacheHeaders
'cache-control' header in token endpoint response contains expected value.
cache_control_header
no-store
2022-08-17 07:27:44 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-08-17 07:27:44 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg
type
bearer
2022-08-17 07:27:44 SUCCESS
CheckTokenTypeIsBearer
Token type is bearer
2022-08-17 07:27:44 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
719.7493001976277
expected
96.0
value
KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg
2022-08-17 07:27:44 SUCCESS
EnsureAccessTokenContainsAllowedCharactersOnly
Access token does not contain any illegal characters
2022-08-17 07:27:44 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7200
2022-08-17 07:27:44 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7200
2022-08-17 07:27:44 SUCCESS
EnsureAccessTokenValuesAreDifferent
Access token values are not the same
first_access_token
MJHDjYMF1sL1zDO1tX1oSzE-Kv2W8Knxy6agHI4LprY.p0wn_IN_Zv5ZbMsp5kPhNY0W5WlGU6U85paO-tjOsIXvUHgC9oNophDxEuiZ86V4i4KPbhond0zwwvwNzVaRzA
second_access_token
KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg
2022-08-17 07:27:44 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InJzYTI1NiIsInR5cCI6IkpXVCJ9.eyJhdF9oYXNoIjoiLUhubTFsMnRWa1NEOThzQjBNRTFoQSIsImF1ZCI6WyI0Zjg0ZThlMS1mOTY1LTQ2MTEtOWZiYy1lZmY2MGYxNGU3NjMiXSwiYXV0aF90aW1lIjoxNjYwNzE5ODQyLCJleHAiOjE2NjA3MjQ4NjQsImlhdCI6MTY2MDcyMTI2NCwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo4ODQzL29hdXRoMi8iLCJqdGkiOiI3MTVhYjJmMC02NzEwLTRkYWMtYmNkYS05MzI4MjI1NzE0MDIiLCJyYXQiOjE2NjA3MjEyNTUsInJ0X2hhc2giOiJXRHhZN2dTOFZNUlNrSGZfOUd6eUp3Iiwic3ViIjoidGVzdHVzZXIifQ.RMEjLBkHUK0kipoQe31dOCyBxUPzdxttP3hIZyxmFaZtP1X70k6soY2i6uFfiELIiSySSX7NMBoe5tKI9FEUbzZ2nHgqOVUypiB5twxWxc15nc7Y5pIPi1sRTSMmHeu-0KotEYmUdouHjpuu18AUmukedPzayvgLZUYmDQuZ0GcCJYGFrs_1DcwQk2VU6y4NbjcEOGTlxEQ5vE7TRR7kZJfek5BQ0h2GkNPDSH1D-X_ou0f025aV95Mf47lCzbLY4mqnub_g1Td5UXTTS9xRX6R1wUluX4XmrHTb5oevcUsDJ5HSY4hZXq3aumz7TuVtbMXacgVj_3Kjj80QnVzjmA
header
{
  "kid": "rsa256",
  "typ": "JWT",
  "alg": "RS256"
}
claims
{
  "at_hash": "-Hnm1l2tVkSD98sB0ME1hA",
  "aud": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "sub": "testuser",
  "rat": 1660721255,
  "auth_time": 1660719842,
  "iss": "https://isamfed.com:8843/oauth2/",
  "exp": 1660724864,
  "iat": 1660721264,
  "jti": "715ab2f0-6710-4dac-bcda-932822571402",
  "rt_hash": "WDxY7gS8VMRSkHf_9GzyJw"
}
2022-08-17 07:27:44 SUCCESS
ExtractRefreshTokenFromTokenResponse
Extracted refresh token from response
refresh_token
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
2022-08-17 07:27:44 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
1040
required
128
2022-08-17 07:27:44 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
730.3464658187114
expected
96.0
value
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
2022-08-17 07:27:44 SUCCESS
CompareIdTokenClaims
Validated id token claims successfully
iss
{
  "first": "https://isamfed.com:8843/oauth2/",
  "second": "https://isamfed.com:8843/oauth2/",
  "note": "Values are expected to be equal"
}
sub
{
  "first": "testuser",
  "second": "testuser",
  "note": "Values are expected to be equal"
}
iat
{
  "first": 1660721262,
  "second": 1660721264,
  "note": "Values are expected to be different"
}
aud
{
  "first": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "second": "4f84e8e1-f965-4611-9fbc-eff60f14e763",
  "note": "Values are expected to be equal"
}
auth_time
{
  "first": 1660719842,
  "second": 1660719842,
  "note": "Values are expected to be equal"
}
azp
Id tokens do not contain azp claims
Second client: Userinfo endpoint tests
2022-08-17 07:27:44
CallProtectedResource
HTTP request
request_uri
https://isamfed.com:8843/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer KOlpZaa10s39-sIUfs_a8a2KOxXCBKB4fcSeww4QUJE.z5kCerncw8CJwemFjUB2cStEaSwnJt19cpJYzFzWWsZLgUw662QizXO3ThCKyoro01vG6ss-TYItdQvnm6SQeg",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:45 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:45 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-83c2d96e-e436-44f1-91ee-026d2496be43",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"aud":["4f84e8e1-f965-4611-9fbc-eff60f14e763"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721255,"sub":"testuser"}
2022-08-17 07:27:45 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "content-length": "147",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:45 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-83c2d96e-e436-44f1-91ee-026d2496be43",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
body
{"aud":["4f84e8e1-f965-4611-9fbc-eff60f14e763"],"auth_time":1660719842,"iss":"https://isamfed.com:8843/oauth2/","rat":1660721255,"sub":"testuser"}
2022-08-17 07:27:45 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
Attempting to use refresh_token issued to client 2 with client 1
2022-08-17 07:27:45 SUCCESS
CreateRefreshTokenRequest
Created token endpoint request parameters
grant_type
refresh_token
refresh_token
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
2022-08-17 07:27:45 SUCCESS
AddScopeToTokenEndpointRequest
Added scope of 'openid' to token endpoint request
grant_type
refresh_token
refresh_token
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
scope
openid
2022-08-17 07:27:45 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
7a2c2baa-aa8c-4654-b935-937981ceed81
sub
7a2c2baa-aa8c-4654-b935-937981ceed81
aud
https://isamfed.com:8843/oauth2/token
jti
6KTSDNaFv2gh3uyVe7m4
iat
1660721265
exp
1660721325
2022-08-17 07:27:45 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTMyNSwiaWF0IjoxNjYwNzIxMjY1LCJqdGkiOiI2S1RTRE5hRnYyZ2gzdXlWZTdtNCJ9.Uov9B8paHY4phRUyFRtgab-1Em4lZO289uFo5UHdT-iB65tCiWs3TM-WWjTk7NgtspbDwk9AhJ82Gj18aV9D2XxQqX9246W4I5kr3rrch21ttEh2KoMZnqkOgj7xc5nEAQAz4yCW2gtXD_AI7QOGS7J7AMnMHAmImuso6NPRWZyLmsFjpCMzU7KpN4_hSvf3b2vzlPH9EaA27FZQ0cErNLRXr9Qdx4U1YT43cltKCKYFGqPgHh4Q0Xjb26siWknr-6A67itGRQqnOoXzu6hm720TXjCkMUCbkzjNMCewUOxKWlG9Kv1zYZ-LcELwD1yyVP3NBE9mWyaEmv9do62AfA
2022-08-17 07:27:45
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
refresh_token
refresh_token
OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ
scope
openid
client_assertion
eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTMyNSwiaWF0IjoxNjYwNzIxMjY1LCJqdGkiOiI2S1RTRE5hRnYyZ2gzdXlWZTdtNCJ9.Uov9B8paHY4phRUyFRtgab-1Em4lZO289uFo5UHdT-iB65tCiWs3TM-WWjTk7NgtspbDwk9AhJ82Gj18aV9D2XxQqX9246W4I5kr3rrch21ttEh2KoMZnqkOgj7xc5nEAQAz4yCW2gtXD_AI7QOGS7J7AMnMHAmImuso6NPRWZyLmsFjpCMzU7KpN4_hSvf3b2vzlPH9EaA27FZQ0cErNLRXr9Qdx4U1YT43cltKCKYFGqPgHh4Q0Xjb26siWknr-6A67itGRQqnOoXzu6hm720TXjCkMUCbkzjNMCewUOxKWlG9Kv1zYZ-LcELwD1yyVP3NBE9mWyaEmv9do62AfA
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-08-17 07:27:45
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://isamfed.com:8843/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "923"
}
request_body
grant_type=refresh_token&refresh_token=OUhU8TVO6sx7xUpTGS-lUWycEW2cbM3e2vTQmTJXINk.pCYphR8YD12JkCPMba9vbhNPAhHhTt0XhPc81Fn463Ogj1IqPKy8K6EhDLUozacWV1BcrIrLKT3TMOpBoEwuMQ&scope=openid&client_assertion=eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiI3YTJjMmJhYS1hYThjLTQ2NTQtYjkzNS05Mzc5ODFjZWVkODEiLCJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206ODg0M1wvb2F1dGgyXC90b2tlbiIsImlzcyI6IjdhMmMyYmFhLWFhOGMtNDY1NC1iOTM1LTkzNzk4MWNlZWQ4MSIsImV4cCI6MTY2MDcyMTMyNSwiaWF0IjoxNjYwNzIxMjY1LCJqdGkiOiI2S1RTRE5hRnYyZ2gzdXlWZTdtNCJ9.Uov9B8paHY4phRUyFRtgab-1Em4lZO289uFo5UHdT-iB65tCiWs3TM-WWjTk7NgtspbDwk9AhJ82Gj18aV9D2XxQqX9246W4I5kr3rrch21ttEh2KoMZnqkOgj7xc5nEAQAz4yCW2gtXD_AI7QOGS7J7AMnMHAmImuso6NPRWZyLmsFjpCMzU7KpN4_hSvf3b2vzlPH9EaA27FZQ0cErNLRXr9Qdx4U1YT43cltKCKYFGqPgHh4Q0Xjb26siWknr-6A67itGRQqnOoXzu6hm720TXjCkMUCbkzjNMCewUOxKWlG9Kv1zYZ-LcELwD1yyVP3NBE9mWyaEmv9do62AfA&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
2022-08-17 07:27:46 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "content-length": "157",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Wed, 17 Aug 2022 07:27:46 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-35dc8636-3de3-4dbb-a9b7-829ba75b29da",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body
{"error":"invalid_grant","error_description":"CSIAQ5087E The OAuth 2.0 Client ID from this request does not match the ID during the initial token issuance."}
2022-08-17 07:27:46 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error
invalid_grant
error_description
CSIAQ5087E The OAuth 2.0 Client ID from this request does not match the ID during the initial token issuance.
2022-08-17 07:27:46 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
invalid_grant
2022-08-17 07:27:47 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2022-08-17 07:27:47 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2022-08-17 07:27:47 SUCCESS
CheckErrorFromTokenEndpointResponseErrorInvalidGrant
Token Endpoint response error returned expected 'error' of 'invalid_grant'
expected
[
  "invalid_grant"
]
2022-08-17 07:27:47 FINISHED
oidcc-refresh-token
Test has run to completion
testmodule_result
PASSED
Unregister dynamically registered client
2022-08-17 07:27:47
UnregisterDynamicallyRegisteredClient
HTTP request
request_uri
https://isamfed.com:8843/oauth2/register/7a2c2baa-aa8c-4654-b935-937981ceed81
request_method
DELETE
request_headers
{
  "accept": "application/json",
  "authorization": "Bearer v8EMQOOr6i8BY_ZmHVHBknrLMIumJYI5pqYvNsK9bhw.rInJfdvVtSVch1HLM2hQAiSKSh7INck1RGr8pd2tMpb2lATyexUvSVqC-bF9G_cdugFHxjqN13RYSOGmtnEQfw",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:48 RESPONSE
UnregisterDynamicallyRegisteredClient
HTTP response
response_status_code
204 NO_CONTENT
response_status_text
No Content
response_headers
{
  "date": "Wed, 17 Aug 2022 07:27:47 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-33c06bd7-5613-4bd2-949c-4fcd3b42d7cd",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body

                                
2022-08-17 07:27:48 SUCCESS
UnregisterDynamicallyRegisteredClient
Client successfully unregistered
Second client: Unregister dynamically registered client
2022-08-17 07:27:48
UnregisterDynamicallyRegisteredClient
HTTP request
request_uri
https://isamfed.com:8843/oauth2/register/4f84e8e1-f965-4611-9fbc-eff60f14e763
request_method
DELETE
request_headers
{
  "accept": "application/json",
  "authorization": "Bearer Ri50H8yR-B9x3RVWSxKiyReQfHpJzdYxtOuqyZG4OCU.Y5PBxXAAT88SRZpIsEYPaj_pYmbvOqndsmjxkuGWSgqxpzZjW8Vg2bo8DQGqqku_CKpwXCZ0dXPiw45Q0LmDpQ",
  "content-length": "0"
}
request_body

                                
2022-08-17 07:27:49 RESPONSE
UnregisterDynamicallyRegisteredClient
HTTP response
response_status_code
204 NO_CONTENT
response_status_text
No Content
response_headers
{
  "date": "Wed, 17 Aug 2022 07:27:49 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-cd61322a-6e58-47ec-a2ca-c3fdb97f237a",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache"
}
response_body

                                
2022-08-17 07:27:49 SUCCESS
UnregisterDynamicallyRegisteredClient
Client successfully unregistered
Test Results