Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-10-17 09:44:58 INFO
TEST-RUNNER
Test instance kC9MLF05x1wR835 created
baseUrl
https://www.certification.openid.net/test/a/ISVAOP
variant
{
  "client_auth_type": "private_key_jwt",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "openbanking_uk",
  "fapi_response_mode": "plain_response"
}
alias
ISVAOP
description
planId
Efsx4j3w9wbcb
config
{
  "alias": "ISVAOP",
  "automated_ciba_approval_url": "http://119.81.74.189:31811/authenticator/userResponse?action\u003d{action}\u0026token\u003d{auth_req_id}",
  "server": {
    "discoveryUrl": "https://isamfed.com:6443/isvaop/oauth2/.well-known/openid-configuration"
  },
  "client": {
    "client_id": "client_ukob01",
    "scope": "openid email",
    "jwks": {
      "keys": [
        {
          "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
          "kty": "RSA",
          "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
          "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "ristrettotest",
          "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
          "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
          "alg": "PS256",
          "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
          "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
        }
      ]
    },
    "hint_type": "login_hint",
    "hint_value": "testuser"
  },
  "client2": {
    "client_id": "client_ukob02",
    "scope": "openid",
    "jwks": {
      "keys": [
        {
          "p": "_a4hJlGIgqTgO5MjxTa4j4-rnui8ofinPAs2lh5D3YQEQfpVPrEYlv8eo_sPpwkeU1M-PXVT2U59Os56IiKzDhqdQgaIRbq6Si8fhPxPrI4ei-wXuihqF1QDbbAuXf7ZV8_Yx1XCPKadrRNa8TKZWO4vDR30EdDsjL2uhyxdcI8",
          "kty": "RSA",
          "q": "x4GpCUG5Kwo6xv6Wl5UWUuV817mccDDnWVSLqK7Msb58BSfcK7kLrdzSFxBuo_DoK4RYu5K34HbAIzoZuC4cRJXR5QDf6BKxuyyF0qMNrHWpoXSpQOXHR6UowPaNHKfa4pXhcRCj4yo47VkipXEm2tD9bdTB0ydVZTJXrRKw9IE",
          "d": "moWnAjS47_t0jdjYHaubEY3f0MI5lVKwZblDqbkKoYUVfguFTI55opUg6EUGJDX74SM1acfPRpe6P7V9Iet_PoGpunQ4TdD3H4yCetqLBniZPNDn8oeVKkhhj97v-GyLyAWumaEDntO0O566TGUL-a0GwrcfT63Z_A4e0-NCTNyrn-hyy5Ljlw17r9MehxwXhi6wZdZJnu7iPT2UJGYeO9R-qedE_UiBzPYsXCjXV6FrY4awDGvWAr4R24hkI9naj6hIcmJhL-34xh6_hWomFtCHtKkNRSVHjMcIP5HOeK4yUqlRssvr61xzDwxrtv32Tj5JCDFUCc-NM8YVYy3oAQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "conformancetest",
          "qi": "ZIgXA-QKu5WscOoA4paq3INWIFNf34tPa1I2MTe30_fLShaDwwF3F_CzUscVd1k7Mbn_VpuKfK2C5Vqupoyj7uyk1gm-iuWtJYcxTkE61udn5vRq4lnjNzxtQCjHm48ZRnVmpFCMrSbcb2oJMzWFH1aM2vyCwuMcrSckR7YVVUI",
          "dp": "HSWmtWpkzu32vaGYWI6DAiu1wlpnYgzZ2jJHoVP05DzI6HPE26EpfB_v-1NbZwvLKjPEUPdsHOnBxcH3knh-Lj6slut9ONXNlbx4WKVM2jyyEc2cpE0Ec425nx7BFRe1DTvaYnzeBm32a-5vYos3x1oGmfE5G9rvcvRQW0OjsM0",
          "alg": "PS256",
          "dq": "XyYfkCKgRT6jubRB7hlUhESevePwEDHCpIAF-3UiesL2Mx9HijK-tzTRnd5gZh_HGroL96mJuKvqBuL20ThskulBKY65Ot1vlm0thb_uDYowVKhm8GSmHi1Ounjb5AbKBbalxl7BSt4gOFKCi5TjiwiRVYhayHHB8HmKByka7AE",
          "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
        }
      ]
    },
    "acr_value": "urn:acr2"
  },
  "resource": {
    "resourceUrl": "https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/",
    "resourceUrlAccountRequests": "https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/",
    "resourceUrlAccountsResource": "https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/"
  },
  "mtls": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQEL\nBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJ\nc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYD\nVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1ow\nazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2lu\nZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQD\nDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CI\nojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+\nfhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWy\nPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4\nNkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cw\nrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDR\nUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjij\nZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/\nBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ\n2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA\n86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJ\nYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFK\noPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4\nflhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d\n-----END CERTIFICATE-----\n",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQO\nZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+\njbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++\nA3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Nj\nd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqg\nDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABAoIBAEOmr/MnPlWdb41v\ntTyC9q5XB6sB6JR3fABUARhHj6MMTzWGZU9k2TE4TVWm0xiDPSXAwVADrWnJePlZ\nq0RdRd3MX9iO5daQPZnAEX3Iin9t44jHrZSmClEH6D4b0ur5osgLnMx2R/I3L+lP\nJfrd/fjpt1lMxjAHCz7Jb7INTnLMjBl8Lji9witoeQseo2+SRLanNckCw9t2/Wkq\nlpyTUnVg6icB9QLAh0ASE/zlMdFMYlo1llfxToRpZKQuE0zTXtvMqfkutqSUb8hL\nSBTYuMHOh8aycMB//JgiAMwrHVSVcRn2oMqnk5vm08i/sLK8TT8AGAf8Evn0GJJ8\n8kKHvqECgYEA2Xnd/4+98ZiEnLbkgRPVX7pWVa2ZqCAZ4Cf75cv+IlQ3crJniX0I\nEOpFS71fF8/Ei7DIAELe9zeopQvkUdfzMlC7Rg5AuhJzRIL+FaUFlLJOMz+S7eqi\nLeabclYGIbZrX+n8Xic01oQxRipgV1XMKj+D3MROUoRCWNMS1Xqghe0CgYEAxQbF\nsTjipyvk6ZvrpucqAZ1IVIGiVELGMlUEGmyJ8CgXd3gwmU88RahmwBes0GNzm5hw\ns9J+C/S/zt6gu1pP1g/lEpx4/yxg6MZk8AQEk3VG63Tg2rEzjEIQsz0fTXbO1AVS\nJvEuReB8VCgQEKNYMxrqdHXvpSFHOhQLbvebODkCgYEAgK7e0IjCkQF5fq2t+j69\nJD7DNUFayaPtC7k9EVWqk6+Xe7PbFfy42CF3TYDJkvJqz2mUfqsS+d+iV774pAEP\nM3eXyLVIUZH3SNPl+vLBoaH8KdD1ZPhQbK6mznneePZTBNcUcLXsSv6/lVAf362x\n+FHK+cfivGrsQ1jqLQ25jGUCgYBVrLY2dDgK3YlzE/wK3aZkgVI8fQprfYXVySY5\nn0z0A1sA9mCbqdrZp3rWuPTKwRQ6arVHXJa2+DyX5jMahREGUm8YAraSr2eMkQi/\nXd/nhy3JoU9NiZSSvv+oEUIVWz5g79djW6j1dcJajfk+Yuktf9zHu6jzs17XoHPA\nUydJ8QKBgQCreujKz7G5EEXkwdEqFFolM9A8ZMB2k3t6FaM4P/lEUs+nFkxYz2+r\nxI4HMCE0UOCw58ukQjNmXJhumAAB0HIC28gFVuk8FXPRI46ZRQ4uuqQcSCr3/0yP\nSrJe3uU+IC74iHff9XHmwiHwcpmgsDclyg4Ga5eCf1XNKmZLtu/4Xg\u003d\u003d\n-----END RSA PRIVATE KEY-----\n",
    "ca": "-----BEGIN CERTIFICATE-----\nMIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQEL\nBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJ\nc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYD\nVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1ow\nazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2lu\nZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQD\nDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CI\nojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+\nfhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWy\nPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4\nNkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cw\nrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDR\nUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjij\nZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/\nBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ\n2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA\n86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJ\nYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFK\noPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4\nflhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d\n-----END CERTIFICATE-----\n"
  },
  "mtls2": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIIDtzCCAp+gAwIBAgIUWzVEE6ZzNUl6kwxJgrUgERqiDXkwDQYJKoZIhvcNAQEL\nBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJ\nc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYD\nVQQDDApjbGllbnRJRDAyMB4XDTIyMDEwNDA0MzQxNloXDTQxMDkyMTA0MzQxNlow\nazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2lu\nZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQD\nDApjbGllbnRJRDAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFSV\n37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar+Qvoq2w6La1k9tGZuMMY\nC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420MIqC56cqs3JyfJEybhVRd\nLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyURUAaYhLqjlsqpS2XM79A\nsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k+7/F1HlP+J1rB2dk7zsS\nnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7HOXzrqgp2VDt9tXuJOClr\nEJEJJnAUJ7cYXtn8uQIDAQABo1MwUTAdBgNVHQ4EFgQUAZeJHIZu9VunYouyoHf/\nQODzbREwHwYDVR0jBBgwFoAUAZeJHIZu9VunYouyoHf/QODzbREwDwYDVR0TAQH/\nBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAft9Mp/WpGdRF1sCzVG2r7SHxaxTG\nfWC+iZJBVZfFTJcthDawCW3xIfQb0RUrtGWTKBgpCp8GSCxFYPuri/nZn2vRbujn\n3woK2siXWS64bYDUOJ3xHvt3/j0PPGRfQ3faSXjdvtkE7ayLRKdb132rBd2k7oBq\nIZkM3ezvXg49KupJfOYTaqNezA4TTXaLFL+7BbY8IFPYHE+t66K68DNbypr3Q8pP\n2ZCHE3YLS3RG+Ql2EYSGABKNbeRcipONYPvtsiZt4k44vCDRUC5DXdC6C9KeEjrL\np5ycJYgdT+YqD34Rd89u/yjgvlo3Bcv0mhEO1sS4jaG3IRkZZsCoUEFSvQ\u003d\u003d\n-----END CERTIFICATE-----\n",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEogIBAAKCAQEAxFSV37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar\n+Qvoq2w6La1k9tGZuMMYC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420M\nIqC56cqs3JyfJEybhVRdLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyU\nRUAaYhLqjlsqpS2XM79AsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k\n+7/F1HlP+J1rB2dk7zsSnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7H\nOXzrqgp2VDt9tXuJOClrEJEJJnAUJ7cYXtn8uQIDAQABAoIBABZVROM5pCIa9qsu\nUxgvF3wXAktoAdahrRMjcnIstNQpQ9cT5Jyk5Sey3P9bLRQCjcj9sFuOUNksFa+n\nUGw6qKifVDI02eifZAN9CudMH+P/wu3e9rVtsRhOLNG/oz6+1CYbjam7N+FDSz5T\nFp018fCBoekctbofEVZ3BzJDaX+VrBn6TSBpzMzibDfnnfbkFkep+91okF9TTLIZ\n+Bjl/f1dVfbMZ6scs2rc7Slp52Od0HZ69gerc7l4IFxCiH2pMMbI6lRESYXlaf4j\n/mTJR/sFnDvbyET1UVU5paAhZ/TLGougAGzLtOEhlxLSjNv/5RfFIs1NPLW8iu68\nOgKL94ECgYEA6Ya6XBXydFof+aeHub7AlYdEA9qnQdqQR88AHlHcLIxkyNlVsPh+\n5/t0SrkJtrspBp233Ne9JTflQYk8/+wBE59NutnKJfzzV04ftm1bmW+gBHT36rZR\nW8WT2Kto73A9SLzhhQSp1a14ff9vULoRwQLtWpAANkqTCUD0Zwe4v+kCgYEA1zl7\nLSMmUpjjR1thITcfHnVtI+0U4ilqcDXUZzoaJsSQ4/oSr8Xc2EbF2KsxqPhq6HKO\nhINsPeN+iA1F0F3+oc32k4PI8NrQtIfLsVEvTQ2LuYsR4a8TNyGH/zk0i/XpRy63\n2BrKcYp6iyb3qQgGMdjsK+PW6PChTa6TaopUpFECgYAWozHTlWkQcGAjImNc1Sn0\nFM26FesaziYoX9+iEMtoIh/u/Gp7IkujD1Qhnjhb117NvmJBbURvpDB8HuKj6Gve\nTBYL4+rdrdyk/PTECWvUvuZjKDeUMCJI5ClF2q/sbhPyxiSScXZJOWyxwh43VCI+\ndJsvqT/sA2Sng/1tM2lsaQKBgGitkWZTuTjlGW3EWQpxp9YFoO6fSc/x+s3WsJcA\nYGXIpvvqzhnlr1MVoPaP1RhssnqZ9Q0oaoXzVsBPTExa2xTRewMmTp4unuGfRofY\nh5v/YZz9sdXFdCAVU/LjXNZR5YL0iwA1j48HnjB95Gi2+WRXMA7swsMK/jktFo/z\n9dTxAoGAYk2kwzCs7xwhsa3/xH5xJauvlclDqelC4R1cS2pzQI+MQIfjR4JccZ8x\nly7HMv+2D9vBModxo/msXGq3QJaAmDHzNhee2+OTuKcDLd7wlwSwqZ9EBvxHuLwI\n7/QZejw68iLHZWQMH57daNZL9X/8VwmF/C8tawAvXmflv+ra3Ec\u003d\n-----END RSA PRIVATE KEY-----\n",
    "ca": "-----BEGIN CERTIFICATE-----\nMIIDtzCCAp+gAwIBAgIUWzVEE6ZzNUl6kwxJgrUgERqiDXkwDQYJKoZIhvcNAQEL\nBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJ\nc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYD\nVQQDDApjbGllbnRJRDAyMB4XDTIyMDEwNDA0MzQxNloXDTQxMDkyMTA0MzQxNlow\nazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2lu\nZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQD\nDApjbGllbnRJRDAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFSV\n37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar+Qvoq2w6La1k9tGZuMMY\nC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420MIqC56cqs3JyfJEybhVRd\nLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyURUAaYhLqjlsqpS2XM79A\nsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k+7/F1HlP+J1rB2dk7zsS\nnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7HOXzrqgp2VDt9tXuJOClr\nEJEJJnAUJ7cYXtn8uQIDAQABo1MwUTAdBgNVHQ4EFgQUAZeJHIZu9VunYouyoHf/\nQODzbREwHwYDVR0jBBgwFoAUAZeJHIZu9VunYouyoHf/QODzbREwDwYDVR0TAQH/\nBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAft9Mp/WpGdRF1sCzVG2r7SHxaxTG\nfWC+iZJBVZfFTJcthDawCW3xIfQb0RUrtGWTKBgpCp8GSCxFYPuri/nZn2vRbujn\n3woK2siXWS64bYDUOJ3xHvt3/j0PPGRfQ3faSXjdvtkE7ayLRKdb132rBd2k7oBq\nIZkM3ezvXg49KupJfOYTaqNezA4TTXaLFL+7BbY8IFPYHE+t66K68DNbypr3Q8pP\n2ZCHE3YLS3RG+Ql2EYSGABKNbeRcipONYPvtsiZt4k44vCDRUC5DXdC6C9KeEjrL\np5ycJYgdT+YqD34Rd89u/yjgvlo3Bcv0mhEO1sS4jaG3IRkZZsCoUEFSvQ\u003d\u003d\n-----END CERTIFICATE-----\n"
  },
  "consent": {}
}
testName
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
2022-10-17 09:44:58 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
2022-10-17 09:44:58
GetDynamicServerConfiguration
HTTP request
request_uri
https://isamfed.com:6443/isvaop/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-10-17 09:45:00 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-type": "application/json",
  "date": "Mon, 17 Oct 2022 09:44:59 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "transfer-encoding": "chunked",
  "x-correlation-id": "CORR_ID-1f2883f0-0f1e-41ad-883a-669f6f2b2f7b",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"authorization_encryption_alg_values_supported":["none"],"authorization_encryption_enc_values_supported":["none"],"authorization_endpoint":"https://isamfed.com:6443/isvaop/oauth2/authorize","authorization_signing_alg_values_supported":["PS256"],"backchannel_authentication_endpoint":"https://isamfed.com:6443/isvaop/oauth2/ciba","backchannel_authentication_request_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"backchannel_token_delivery_modes_supported":["poll","ping"],"backchannel_user_code_parameter_supported":false,"claim_types_supported":["normal"],"claims_parameter_supported":true,"claims_supported":["acr","openbanking_intent_id"],"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"grant_types_supported":["authorization_code","implicit","password","client_credentials","refresh_token","urn:openid:params:grant-type:ciba"],"id_token_encryption_alg_values_supported":["none"],"id_token_encryption_enc_values_supported":["none"],"id_token_signing_alg_values_supported":["PS256"],"introspection_endpoint":"https://isamfed.com:6443/isvaop/oauth2/introspect","issuer":"https://isamfed.com:6443/isvaop/oauth2","jwks_uri":"https://isamfed.com:6443/isvaop/oauth2/jwks","mtls_endpoint_aliases":{"backchannel_authentication_endpoint":"https://isamfed.com:6443/isvaop/oauth2/ciba","introspection_endpoint":"https://isamfed.com:6443/isvaop/oauth2/introspect","pushed_authorization_request_endpoint":"https://isamfed.com:6443/isvaop/oauth2/par","registration_endpoint":"https://isamfed.com:6443/isvaop/oauth2/register","revocation_endpoint":"https://isamfed.com:6443/isvaop/oauth2/revoke","token_endpoint":"https://isamfed.com:6443/isvaop/oauth2/token"},"pushed_authorization_request_endpoint":"https://isamfed.com:6443/isvaop/oauth2/par","registration_endpoint":"https://isamfed.com:6443/isvaop/oauth2/register","request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_parameter_supported":true,"request_uri_parameter_supported":false,"require_pushed_authorization_requests":false,"require_request_uri_registration":false,"response_modes_supported":["query","fragment","form_post","jwt","query.jwt","fragment.jwt","form_post.jwt"],"response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"revocation_endpoint":"https://isamfed.com:6443/isvaop/oauth2/revoke","scopes_supported":["openid","accounts"],"subject_types_supported":["public"],"tls_client_certificate_bound_access_tokens":true,"token_endpoint":"https://isamfed.com:6443/isvaop/oauth2/token","token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none"],"userinfo_encryption_enc_values_supported":["none"],"userinfo_endpoint":"https://isamfed.com:6443/isvaop/oauth2/userinfo","userinfo_signing_alg_values_supported":["PS256"]}
2022-10-17 09:45:00 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
authorization_encryption_alg_values_supported
[
  "none"
]
authorization_encryption_enc_values_supported
[
  "none"
]
authorization_endpoint
https://isamfed.com:6443/isvaop/oauth2/authorize
authorization_signing_alg_values_supported
[
  "PS256"
]
backchannel_authentication_endpoint
https://isamfed.com:6443/isvaop/oauth2/ciba
backchannel_authentication_request_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
backchannel_token_delivery_modes_supported
[
  "poll",
  "ping"
]
backchannel_user_code_parameter_supported
false
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
claims_supported
[
  "acr",
  "openbanking_intent_id"
]
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "client_credentials",
  "refresh_token",
  "urn:openid:params:grant-type:ciba"
]
id_token_encryption_alg_values_supported
[
  "none"
]
id_token_encryption_enc_values_supported
[
  "none"
]
id_token_signing_alg_values_supported
[
  "PS256"
]
introspection_endpoint
https://isamfed.com:6443/isvaop/oauth2/introspect
issuer
https://isamfed.com:6443/isvaop/oauth2
jwks_uri
https://isamfed.com:6443/isvaop/oauth2/jwks
mtls_endpoint_aliases
{
  "backchannel_authentication_endpoint": "https://isamfed.com:6443/isvaop/oauth2/ciba",
  "introspection_endpoint": "https://isamfed.com:6443/isvaop/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://isamfed.com:6443/isvaop/oauth2/par",
  "registration_endpoint": "https://isamfed.com:6443/isvaop/oauth2/register",
  "revocation_endpoint": "https://isamfed.com:6443/isvaop/oauth2/revoke",
  "token_endpoint": "https://isamfed.com:6443/isvaop/oauth2/token"
}
pushed_authorization_request_endpoint
https://isamfed.com:6443/isvaop/oauth2/par
registration_endpoint
https://isamfed.com:6443/isvaop/oauth2/register
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_parameter_supported
true
request_uri_parameter_supported
false
require_pushed_authorization_requests
false
require_request_uri_registration
false
response_modes_supported
[
  "query",
  "fragment",
  "form_post",
  "jwt",
  "query.jwt",
  "fragment.jwt",
  "form_post.jwt"
]
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
revocation_endpoint
https://isamfed.com:6443/isvaop/oauth2/revoke
scopes_supported
[
  "openid",
  "accounts"
]
subject_types_supported
[
  "public"
]
tls_client_certificate_bound_access_tokens
true
token_endpoint
https://isamfed.com:6443/isvaop/oauth2/token
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none"
]
userinfo_encryption_enc_values_supported
[
  "none"
]
userinfo_endpoint
https://isamfed.com:6443/isvaop/oauth2/userinfo
userinfo_signing_alg_values_supported
[
  "PS256"
]
2022-10-17 09:45:00 SUCCESS
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
2022-10-17 09:45:00 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-10-17 09:45:00
FetchServerKeys
Fetching server key
jwks_uri
https://isamfed.com:6443/isvaop/oauth2/jwks
2022-10-17 09:45:00
FetchServerKeys
HTTP request
request_uri
https://isamfed.com:6443/isvaop/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-10-17 09:45:01 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "419",
  "content-type": "application/json",
  "date": "Mon, 17 Oct 2022 09:45:00 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-e654a952-f58a-4e17-b12a-b50825ef0f78",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains"
}
response_body
{"keys":[{"use":"sig","kty":"RSA","kid":"httpserverkey","n":"3H8uKbaU0gNgxIzNOI8z19pzicShxM4nd_cs4DqmQU9SCxtjfzyVHpxe-Arg8gr01YoEkIOrz2JJ1G12fNDu7Fepgyy_ZCfqqqstPCj7vmQFC7_XHrDi_xooPT2kfrzHgxUANMe1Kd0Ry2gVexQCrJyDHnLvuYGyA_wQwN3GTHhwB2SfECwnTL87-HICyviTfEqlIU3ymu3u3YeTB5J765i9uT2JtZco9VMtoiR4Hm_e5xSnQmNx3StTiUQrsMo28IxLFgNKAq-aUDvaZ0ulgOp9V-DOlGpBnxSd0G2I58otDC7J7oQ5xhkX6FB1RnMBHgiFSZ492fyJgILkxoUCwQ","e":"AQAB"}]}
2022-10-17 09:45:01
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"use":"sig","kty":"RSA","kid":"httpserverkey","n":"3H8uKbaU0gNgxIzNOI8z19pzicShxM4nd_cs4DqmQU9SCxtjfzyVHpxe-Arg8gr01YoEkIOrz2JJ1G12fNDu7Fepgyy_ZCfqqqstPCj7vmQFC7_XHrDi_xooPT2kfrzHgxUANMe1Kd0Ry2gVexQCrJyDHnLvuYGyA_wQwN3GTHhwB2SfECwnTL87-HICyviTfEqlIU3ymu3u3YeTB5J765i9uT2JtZco9VMtoiR4Hm_e5xSnQmNx3StTiUQrsMo28IxLFgNKAq-aUDvaZ0ulgOp9V-DOlGpBnxSd0G2I58otDC7J7oQ5xhkX6FB1RnMBHgiFSZ492fyJgILkxoUCwQ","e":"AQAB"}]}
2022-10-17 09:45:01 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "httpserverkey",
      "n": "3H8uKbaU0gNgxIzNOI8z19pzicShxM4nd_cs4DqmQU9SCxtjfzyVHpxe-Arg8gr01YoEkIOrz2JJ1G12fNDu7Fepgyy_ZCfqqqstPCj7vmQFC7_XHrDi_xooPT2kfrzHgxUANMe1Kd0Ry2gVexQCrJyDHnLvuYGyA_wQwN3GTHhwB2SfECwnTL87-HICyviTfEqlIU3ymu3u3YeTB5J765i9uT2JtZco9VMtoiR4Hm_e5xSnQmNx3StTiUQrsMo28IxLFgNKAq-aUDvaZ0ulgOp9V-DOlGpBnxSd0G2I58otDC7J7oQ5xhkX6FB1RnMBHgiFSZ492fyJgILkxoUCwQ",
      "e": "AQAB"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "httpserverkey",
      "n": "3H8uKbaU0gNgxIzNOI8z19pzicShxM4nd_cs4DqmQU9SCxtjfzyVHpxe-Arg8gr01YoEkIOrz2JJ1G12fNDu7Fepgyy_ZCfqqqstPCj7vmQFC7_XHrDi_xooPT2kfrzHgxUANMe1Kd0Ry2gVexQCrJyDHnLvuYGyA_wQwN3GTHhwB2SfECwnTL87-HICyviTfEqlIU3ymu3u3YeTB5J765i9uT2JtZco9VMtoiR4Hm_e5xSnQmNx3StTiUQrsMo28IxLFgNKAq-aUDvaZ0ulgOp9V-DOlGpBnxSd0G2I58otDC7J7oQ5xhkX6FB1RnMBHgiFSZ492fyJgILkxoUCwQ",
      "e": "AQAB"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-10-17 09:45:01 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-10-17 09:45:01 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-10-17 09:45:01 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "use": "sig",
      "kty": "RSA",
      "kid": "httpserverkey",
      "n": "3H8uKbaU0gNgxIzNOI8z19pzicShxM4nd_cs4DqmQU9SCxtjfzyVHpxe-Arg8gr01YoEkIOrz2JJ1G12fNDu7Fepgyy_ZCfqqqstPCj7vmQFC7_XHrDi_xooPT2kfrzHgxUANMe1Kd0Ry2gVexQCrJyDHnLvuYGyA_wQwN3GTHhwB2SfECwnTL87-HICyviTfEqlIU3ymu3u3YeTB5J765i9uT2JtZco9VMtoiR4Hm_e5xSnQmNx3StTiUQrsMo28IxLFgNKAq-aUDvaZ0ulgOp9V-DOlGpBnxSd0G2I58otDC7J7oQ5xhkX6FB1RnMBHgiFSZ492fyJgILkxoUCwQ",
      "e": "AQAB"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
client_ukob01
scope
openid email
jwks
{
  "keys": [
    {
      "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
      "kty": "RSA",
      "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
      "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "ristrettotest",
      "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
      "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
      "alg": "PS256",
      "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
      "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
    }
  ]
}
hint_type
login_hint
hint_value
testuser
2022-10-17 09:45:01 SUCCESS
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
2022-10-17 09:45:01 SUCCESS
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
cert
MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA==
key
MIIEpAIBAAKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABAoIBAEOmr/MnPlWdb41vtTyC9q5XB6sB6JR3fABUARhHj6MMTzWGZU9k2TE4TVWm0xiDPSXAwVADrWnJePlZq0RdRd3MX9iO5daQPZnAEX3Iin9t44jHrZSmClEH6D4b0ur5osgLnMx2R/I3L+lPJfrd/fjpt1lMxjAHCz7Jb7INTnLMjBl8Lji9witoeQseo2+SRLanNckCw9t2/WkqlpyTUnVg6icB9QLAh0ASE/zlMdFMYlo1llfxToRpZKQuE0zTXtvMqfkutqSUb8hLSBTYuMHOh8aycMB//JgiAMwrHVSVcRn2oMqnk5vm08i/sLK8TT8AGAf8Evn0GJJ88kKHvqECgYEA2Xnd/4+98ZiEnLbkgRPVX7pWVa2ZqCAZ4Cf75cv+IlQ3crJniX0IEOpFS71fF8/Ei7DIAELe9zeopQvkUdfzMlC7Rg5AuhJzRIL+FaUFlLJOMz+S7eqiLeabclYGIbZrX+n8Xic01oQxRipgV1XMKj+D3MROUoRCWNMS1Xqghe0CgYEAxQbFsTjipyvk6ZvrpucqAZ1IVIGiVELGMlUEGmyJ8CgXd3gwmU88RahmwBes0GNzm5hws9J+C/S/zt6gu1pP1g/lEpx4/yxg6MZk8AQEk3VG63Tg2rEzjEIQsz0fTXbO1AVSJvEuReB8VCgQEKNYMxrqdHXvpSFHOhQLbvebODkCgYEAgK7e0IjCkQF5fq2t+j69JD7DNUFayaPtC7k9EVWqk6+Xe7PbFfy42CF3TYDJkvJqz2mUfqsS+d+iV774pAEPM3eXyLVIUZH3SNPl+vLBoaH8KdD1ZPhQbK6mznneePZTBNcUcLXsSv6/lVAf362x+FHK+cfivGrsQ1jqLQ25jGUCgYBVrLY2dDgK3YlzE/wK3aZkgVI8fQprfYXVySY5n0z0A1sA9mCbqdrZp3rWuPTKwRQ6arVHXJa2+DyX5jMahREGUm8YAraSr2eMkQi/Xd/nhy3JoU9NiZSSvv+oEUIVWz5g79djW6j1dcJajfk+Yuktf9zHu6jzs17XoHPAUydJ8QKBgQCreujKz7G5EEXkwdEqFFolM9A8ZMB2k3t6FaM4P/lEUs+nFkxYz2+rxI4HMCE0UOCw58ukQjNmXJhumAAB0HIC28gFVuk8FXPRI46ZRQ4uuqQcSCr3/0yPSrJe3uU+IC74iHff9XHmwiHwcpmgsDclyg4Ga5eCf1XNKmZLtu/4Xg==
ca
MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA==
2022-10-17 09:45:01 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-10-17 09:45:01 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
      "kty": "RSA",
      "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
      "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "ristrettotest",
      "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
      "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
      "alg": "PS256",
      "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
      "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "ristrettotest",
      "alg": "PS256",
      "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-10-17 09:45:01 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-10-17 09:45:01 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2022-10-17 09:45:01 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
      "kty": "RSA",
      "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
      "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "ristrettotest",
      "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
      "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
      "alg": "PS256",
      "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
      "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
Verify configuration of second client
2022-10-17 09:45:01 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
client_ukob02
scope
openid
jwks
{
  "keys": [
    {
      "p": "_a4hJlGIgqTgO5MjxTa4j4-rnui8ofinPAs2lh5D3YQEQfpVPrEYlv8eo_sPpwkeU1M-PXVT2U59Os56IiKzDhqdQgaIRbq6Si8fhPxPrI4ei-wXuihqF1QDbbAuXf7ZV8_Yx1XCPKadrRNa8TKZWO4vDR30EdDsjL2uhyxdcI8",
      "kty": "RSA",
      "q": "x4GpCUG5Kwo6xv6Wl5UWUuV817mccDDnWVSLqK7Msb58BSfcK7kLrdzSFxBuo_DoK4RYu5K34HbAIzoZuC4cRJXR5QDf6BKxuyyF0qMNrHWpoXSpQOXHR6UowPaNHKfa4pXhcRCj4yo47VkipXEm2tD9bdTB0ydVZTJXrRKw9IE",
      "d": "moWnAjS47_t0jdjYHaubEY3f0MI5lVKwZblDqbkKoYUVfguFTI55opUg6EUGJDX74SM1acfPRpe6P7V9Iet_PoGpunQ4TdD3H4yCetqLBniZPNDn8oeVKkhhj97v-GyLyAWumaEDntO0O566TGUL-a0GwrcfT63Z_A4e0-NCTNyrn-hyy5Ljlw17r9MehxwXhi6wZdZJnu7iPT2UJGYeO9R-qedE_UiBzPYsXCjXV6FrY4awDGvWAr4R24hkI9naj6hIcmJhL-34xh6_hWomFtCHtKkNRSVHjMcIP5HOeK4yUqlRssvr61xzDwxrtv32Tj5JCDFUCc-NM8YVYy3oAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "conformancetest",
      "qi": "ZIgXA-QKu5WscOoA4paq3INWIFNf34tPa1I2MTe30_fLShaDwwF3F_CzUscVd1k7Mbn_VpuKfK2C5Vqupoyj7uyk1gm-iuWtJYcxTkE61udn5vRq4lnjNzxtQCjHm48ZRnVmpFCMrSbcb2oJMzWFH1aM2vyCwuMcrSckR7YVVUI",
      "dp": "HSWmtWpkzu32vaGYWI6DAiu1wlpnYgzZ2jJHoVP05DzI6HPE26EpfB_v-1NbZwvLKjPEUPdsHOnBxcH3knh-Lj6slut9ONXNlbx4WKVM2jyyEc2cpE0Ec425nx7BFRe1DTvaYnzeBm32a-5vYos3x1oGmfE5G9rvcvRQW0OjsM0",
      "alg": "PS256",
      "dq": "XyYfkCKgRT6jubRB7hlUhESevePwEDHCpIAF-3UiesL2Mx9HijK-tzTRnd5gZh_HGroL96mJuKvqBuL20ThskulBKY65Ot1vlm0thb_uDYowVKhm8GSmHi1Ounjb5AbKBbalxl7BSt4gOFKCi5TjiwiRVYhayHHB8HmKByka7AE",
      "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
    }
  ]
}
acr_value
urn:acr2
2022-10-17 09:45:01 SUCCESS
ValidateMTLSCertificates2Header
MTLS certificates header is valid
2022-10-17 09:45:01 SUCCESS
ExtractMTLSCertificates2FromConfiguration
Mutual TLS authentication credentials loaded
cert
MIIDtzCCAp+gAwIBAgIUWzVEE6ZzNUl6kwxJgrUgERqiDXkwDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAyMB4XDTIyMDEwNDA0MzQxNloXDTQxMDkyMTA0MzQxNlowazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFSV37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar+Qvoq2w6La1k9tGZuMMYC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420MIqC56cqs3JyfJEybhVRdLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyURUAaYhLqjlsqpS2XM79AsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k+7/F1HlP+J1rB2dk7zsSnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7HOXzrqgp2VDt9tXuJOClrEJEJJnAUJ7cYXtn8uQIDAQABo1MwUTAdBgNVHQ4EFgQUAZeJHIZu9VunYouyoHf/QODzbREwHwYDVR0jBBgwFoAUAZeJHIZu9VunYouyoHf/QODzbREwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAft9Mp/WpGdRF1sCzVG2r7SHxaxTGfWC+iZJBVZfFTJcthDawCW3xIfQb0RUrtGWTKBgpCp8GSCxFYPuri/nZn2vRbujn3woK2siXWS64bYDUOJ3xHvt3/j0PPGRfQ3faSXjdvtkE7ayLRKdb132rBd2k7oBqIZkM3ezvXg49KupJfOYTaqNezA4TTXaLFL+7BbY8IFPYHE+t66K68DNbypr3Q8pP2ZCHE3YLS3RG+Ql2EYSGABKNbeRcipONYPvtsiZt4k44vCDRUC5DXdC6C9KeEjrLp5ycJYgdT+YqD34Rd89u/yjgvlo3Bcv0mhEO1sS4jaG3IRkZZsCoUEFSvQ==
key
MIIEogIBAAKCAQEAxFSV37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar+Qvoq2w6La1k9tGZuMMYC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420MIqC56cqs3JyfJEybhVRdLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyURUAaYhLqjlsqpS2XM79AsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k+7/F1HlP+J1rB2dk7zsSnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7HOXzrqgp2VDt9tXuJOClrEJEJJnAUJ7cYXtn8uQIDAQABAoIBABZVROM5pCIa9qsuUxgvF3wXAktoAdahrRMjcnIstNQpQ9cT5Jyk5Sey3P9bLRQCjcj9sFuOUNksFa+nUGw6qKifVDI02eifZAN9CudMH+P/wu3e9rVtsRhOLNG/oz6+1CYbjam7N+FDSz5TFp018fCBoekctbofEVZ3BzJDaX+VrBn6TSBpzMzibDfnnfbkFkep+91okF9TTLIZ+Bjl/f1dVfbMZ6scs2rc7Slp52Od0HZ69gerc7l4IFxCiH2pMMbI6lRESYXlaf4j/mTJR/sFnDvbyET1UVU5paAhZ/TLGougAGzLtOEhlxLSjNv/5RfFIs1NPLW8iu68OgKL94ECgYEA6Ya6XBXydFof+aeHub7AlYdEA9qnQdqQR88AHlHcLIxkyNlVsPh+5/t0SrkJtrspBp233Ne9JTflQYk8/+wBE59NutnKJfzzV04ftm1bmW+gBHT36rZRW8WT2Kto73A9SLzhhQSp1a14ff9vULoRwQLtWpAANkqTCUD0Zwe4v+kCgYEA1zl7LSMmUpjjR1thITcfHnVtI+0U4ilqcDXUZzoaJsSQ4/oSr8Xc2EbF2KsxqPhq6HKOhINsPeN+iA1F0F3+oc32k4PI8NrQtIfLsVEvTQ2LuYsR4a8TNyGH/zk0i/XpRy632BrKcYp6iyb3qQgGMdjsK+PW6PChTa6TaopUpFECgYAWozHTlWkQcGAjImNc1Sn0FM26FesaziYoX9+iEMtoIh/u/Gp7IkujD1Qhnjhb117NvmJBbURvpDB8HuKj6GveTBYL4+rdrdyk/PTECWvUvuZjKDeUMCJI5ClF2q/sbhPyxiSScXZJOWyxwh43VCI+dJsvqT/sA2Sng/1tM2lsaQKBgGitkWZTuTjlGW3EWQpxp9YFoO6fSc/x+s3WsJcAYGXIpvvqzhnlr1MVoPaP1RhssnqZ9Q0oaoXzVsBPTExa2xTRewMmTp4unuGfRofYh5v/YZz9sdXFdCAVU/LjXNZR5YL0iwA1j48HnjB95Gi2+WRXMA7swsMK/jktFo/z9dTxAoGAYk2kwzCs7xwhsa3/xH5xJauvlclDqelC4R1cS2pzQI+MQIfjR4JccZ8xly7HMv+2D9vBModxo/msXGq3QJaAmDHzNhee2+OTuKcDLd7wlwSwqZ9EBvxHuLwI7/QZejw68iLHZWQMH57daNZL9X/8VwmF/C8tawAvXmflv+ra3Ec=
ca
MIIDtzCCAp+gAwIBAgIUWzVEE6ZzNUl6kwxJgrUgERqiDXkwDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAyMB4XDTIyMDEwNDA0MzQxNloXDTQxMDkyMTA0MzQxNlowazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFSV37045EHSIKgQ+yofftUN/Ym1kv17rx1G92uepLHgw1Ar+Qvoq2w6La1k9tGZuMMYC8RmlqT+7S6Z5LP4AjKByW+1vX6zJPN6xmEnDFDd420MIqC56cqs3JyfJEybhVRdLCgGvz3uZ7dewKm+oiLECOGAST0jzMc5szzxtvkN5jyURUAaYhLqjlsqpS2XM79AsJIRQy/XsYux1wf42CFvS1Ves3N/aTbO5N6VA5h4KA1k+7/F1HlP+J1rB2dk7zsSnwvsGLvV1r5Eb5XP8DphKZ+xtJmANNo3NiNONxuV0T7HOXzrqgp2VDt9tXuJOClrEJEJJnAUJ7cYXtn8uQIDAQABo1MwUTAdBgNVHQ4EFgQUAZeJHIZu9VunYouyoHf/QODzbREwHwYDVR0jBBgwFoAUAZeJHIZu9VunYouyoHf/QODzbREwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAft9Mp/WpGdRF1sCzVG2r7SHxaxTGfWC+iZJBVZfFTJcthDawCW3xIfQb0RUrtGWTKBgpCp8GSCxFYPuri/nZn2vRbujn3woK2siXWS64bYDUOJ3xHvt3/j0PPGRfQ3faSXjdvtkE7ayLRKdb132rBd2k7oBqIZkM3ezvXg49KupJfOYTaqNezA4TTXaLFL+7BbY8IFPYHE+t66K68DNbypr3Q8pP2ZCHE3YLS3RG+Ql2EYSGABKNbeRcipONYPvtsiZt4k44vCDRUC5DXdC6C9KeEjrLp5ycJYgdT+YqD34Rd89u/yjgvlo3Bcv0mhEO1sS4jaG3IRkZZsCoUEFSvQ==
2022-10-17 09:45:01 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-10-17 09:45:01 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "_a4hJlGIgqTgO5MjxTa4j4-rnui8ofinPAs2lh5D3YQEQfpVPrEYlv8eo_sPpwkeU1M-PXVT2U59Os56IiKzDhqdQgaIRbq6Si8fhPxPrI4ei-wXuihqF1QDbbAuXf7ZV8_Yx1XCPKadrRNa8TKZWO4vDR30EdDsjL2uhyxdcI8",
      "kty": "RSA",
      "q": "x4GpCUG5Kwo6xv6Wl5UWUuV817mccDDnWVSLqK7Msb58BSfcK7kLrdzSFxBuo_DoK4RYu5K34HbAIzoZuC4cRJXR5QDf6BKxuyyF0qMNrHWpoXSpQOXHR6UowPaNHKfa4pXhcRCj4yo47VkipXEm2tD9bdTB0ydVZTJXrRKw9IE",
      "d": "moWnAjS47_t0jdjYHaubEY3f0MI5lVKwZblDqbkKoYUVfguFTI55opUg6EUGJDX74SM1acfPRpe6P7V9Iet_PoGpunQ4TdD3H4yCetqLBniZPNDn8oeVKkhhj97v-GyLyAWumaEDntO0O566TGUL-a0GwrcfT63Z_A4e0-NCTNyrn-hyy5Ljlw17r9MehxwXhi6wZdZJnu7iPT2UJGYeO9R-qedE_UiBzPYsXCjXV6FrY4awDGvWAr4R24hkI9naj6hIcmJhL-34xh6_hWomFtCHtKkNRSVHjMcIP5HOeK4yUqlRssvr61xzDwxrtv32Tj5JCDFUCc-NM8YVYy3oAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "conformancetest",
      "qi": "ZIgXA-QKu5WscOoA4paq3INWIFNf34tPa1I2MTe30_fLShaDwwF3F_CzUscVd1k7Mbn_VpuKfK2C5Vqupoyj7uyk1gm-iuWtJYcxTkE61udn5vRq4lnjNzxtQCjHm48ZRnVmpFCMrSbcb2oJMzWFH1aM2vyCwuMcrSckR7YVVUI",
      "dp": "HSWmtWpkzu32vaGYWI6DAiu1wlpnYgzZ2jJHoVP05DzI6HPE26EpfB_v-1NbZwvLKjPEUPdsHOnBxcH3knh-Lj6slut9ONXNlbx4WKVM2jyyEc2cpE0Ec425nx7BFRe1DTvaYnzeBm32a-5vYos3x1oGmfE5G9rvcvRQW0OjsM0",
      "alg": "PS256",
      "dq": "XyYfkCKgRT6jubRB7hlUhESevePwEDHCpIAF-3UiesL2Mx9HijK-tzTRnd5gZh_HGroL96mJuKvqBuL20ThskulBKY65Ot1vlm0thb_uDYowVKhm8GSmHi1Ounjb5AbKBbalxl7BSt4gOFKCi5TjiwiRVYhayHHB8HmKByka7AE",
      "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "conformancetest",
      "alg": "PS256",
      "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-10-17 09:45:01 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-10-17 09:45:01 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2022-10-17 09:45:01 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "_a4hJlGIgqTgO5MjxTa4j4-rnui8ofinPAs2lh5D3YQEQfpVPrEYlv8eo_sPpwkeU1M-PXVT2U59Os56IiKzDhqdQgaIRbq6Si8fhPxPrI4ei-wXuihqF1QDbbAuXf7ZV8_Yx1XCPKadrRNa8TKZWO4vDR30EdDsjL2uhyxdcI8",
      "kty": "RSA",
      "q": "x4GpCUG5Kwo6xv6Wl5UWUuV817mccDDnWVSLqK7Msb58BSfcK7kLrdzSFxBuo_DoK4RYu5K34HbAIzoZuC4cRJXR5QDf6BKxuyyF0qMNrHWpoXSpQOXHR6UowPaNHKfa4pXhcRCj4yo47VkipXEm2tD9bdTB0ydVZTJXrRKw9IE",
      "d": "moWnAjS47_t0jdjYHaubEY3f0MI5lVKwZblDqbkKoYUVfguFTI55opUg6EUGJDX74SM1acfPRpe6P7V9Iet_PoGpunQ4TdD3H4yCetqLBniZPNDn8oeVKkhhj97v-GyLyAWumaEDntO0O566TGUL-a0GwrcfT63Z_A4e0-NCTNyrn-hyy5Ljlw17r9MehxwXhi6wZdZJnu7iPT2UJGYeO9R-qedE_UiBzPYsXCjXV6FrY4awDGvWAr4R24hkI9naj6hIcmJhL-34xh6_hWomFtCHtKkNRSVHjMcIP5HOeK4yUqlRssvr61xzDwxrtv32Tj5JCDFUCc-NM8YVYy3oAQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "conformancetest",
      "qi": "ZIgXA-QKu5WscOoA4paq3INWIFNf34tPa1I2MTe30_fLShaDwwF3F_CzUscVd1k7Mbn_VpuKfK2C5Vqupoyj7uyk1gm-iuWtJYcxTkE61udn5vRq4lnjNzxtQCjHm48ZRnVmpFCMrSbcb2oJMzWFH1aM2vyCwuMcrSckR7YVVUI",
      "dp": "HSWmtWpkzu32vaGYWI6DAiu1wlpnYgzZ2jJHoVP05DzI6HPE26EpfB_v-1NbZwvLKjPEUPdsHOnBxcH3knh-Lj6slut9ONXNlbx4WKVM2jyyEc2cpE0Ec425nx7BFRe1DTvaYnzeBm32a-5vYos3x1oGmfE5G9rvcvRQW0OjsM0",
      "alg": "PS256",
      "dq": "XyYfkCKgRT6jubRB7hlUhESevePwEDHCpIAF-3UiesL2Mx9HijK-tzTRnd5gZh_HGroL96mJuKvqBuL20ThskulBKY65Ot1vlm0thb_uDYowVKhm8GSmHi1Ounjb5AbKBbalxl7BSt4gOFKCi5TjiwiRVYhayHHB8HmKByka7AE",
      "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
    }
  ]
}
2022-10-17 09:45:01 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
2022-10-17 09:45:01 SUCCESS
ValidateClientPrivateKeysAreDifferent
Client signing JWKs have different thumbprints
jwk1
{
  "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
  "kty": "RSA",
  "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
  "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "ristrettotest",
  "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
  "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
  "alg": "PS256",
  "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
  "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
}
jwk2
{
  "p": "_a4hJlGIgqTgO5MjxTa4j4-rnui8ofinPAs2lh5D3YQEQfpVPrEYlv8eo_sPpwkeU1M-PXVT2U59Os56IiKzDhqdQgaIRbq6Si8fhPxPrI4ei-wXuihqF1QDbbAuXf7ZV8_Yx1XCPKadrRNa8TKZWO4vDR30EdDsjL2uhyxdcI8",
  "kty": "RSA",
  "q": "x4GpCUG5Kwo6xv6Wl5UWUuV817mccDDnWVSLqK7Msb58BSfcK7kLrdzSFxBuo_DoK4RYu5K34HbAIzoZuC4cRJXR5QDf6BKxuyyF0qMNrHWpoXSpQOXHR6UowPaNHKfa4pXhcRCj4yo47VkipXEm2tD9bdTB0ydVZTJXrRKw9IE",
  "d": "moWnAjS47_t0jdjYHaubEY3f0MI5lVKwZblDqbkKoYUVfguFTI55opUg6EUGJDX74SM1acfPRpe6P7V9Iet_PoGpunQ4TdD3H4yCetqLBniZPNDn8oeVKkhhj97v-GyLyAWumaEDntO0O566TGUL-a0GwrcfT63Z_A4e0-NCTNyrn-hyy5Ljlw17r9MehxwXhi6wZdZJnu7iPT2UJGYeO9R-qedE_UiBzPYsXCjXV6FrY4awDGvWAr4R24hkI9naj6hIcmJhL-34xh6_hWomFtCHtKkNRSVHjMcIP5HOeK4yUqlRssvr61xzDwxrtv32Tj5JCDFUCc-NM8YVYy3oAQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "conformancetest",
  "qi": "ZIgXA-QKu5WscOoA4paq3INWIFNf34tPa1I2MTe30_fLShaDwwF3F_CzUscVd1k7Mbn_VpuKfK2C5Vqupoyj7uyk1gm-iuWtJYcxTkE61udn5vRq4lnjNzxtQCjHm48ZRnVmpFCMrSbcb2oJMzWFH1aM2vyCwuMcrSckR7YVVUI",
  "dp": "HSWmtWpkzu32vaGYWI6DAiu1wlpnYgzZ2jJHoVP05DzI6HPE26EpfB_v-1NbZwvLKjPEUPdsHOnBxcH3knh-Lj6slut9ONXNlbx4WKVM2jyyEc2cpE0Ec425nx7BFRe1DTvaYnzeBm32a-5vYos3x1oGmfE5G9rvcvRQW0OjsM0",
  "alg": "PS256",
  "dq": "XyYfkCKgRT6jubRB7hlUhESevePwEDHCpIAF-3UiesL2Mx9HijK-tzTRnd5gZh_HGroL96mJuKvqBuL20ThskulBKY65Ot1vlm0thb_uDYowVKhm8GSmHi1Ounjb5AbKBbalxl7BSt4gOFKCi5TjiwiRVYhayHHB8HmKByka7AE",
  "n": "xbLYBJ3SXWsNcLG03ieLj3UcqOQa0z4KHgjDSIytAv9GgKotTJU9skUvXWLJJuHlAh1MjI9rBZenMuUTqvaHvxMxMpDn5sc2GOLxmoM_dJBAPKmLWhNPNlKAJCVDAWHGcydBNLu8_ZkGCKaXbLStWjPl2djokKNU7gJLGEdv_PaT8-DUKH65xJ7sAaEqgsaFjXUuK7eLQG3Dxd64CLpfiCl9szHZldQkV3t44zfdB9KdaZyWiHwqRUe0mdc4Nn3-QZ7PhfY1z2q0fxEetcMyjr_5RLDWgOltneNmxyrbaxNHUMuiSnroemaRXZMxLyx_c8rDL8YRZ5VXToQw2q4EDw"
}
2022-10-17 09:45:01 SUCCESS
GetResourceEndpointConfiguration
Found a resource endpoint object
resourceUrl
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/
resourceUrlAccountRequests
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/
resourceUrlAccountsResource
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/
2022-10-17 09:45:01 SUCCESS
SetProtectedResourceUrlToAccountsEndpoint
Set protected resource URL
protected_resource_url
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/accounts
2022-10-17 09:45:01 SUCCESS
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
resource_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 6443
}
2022-10-17 09:45:01 SUCCESS
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
accounts_resource_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 6443
}
accounts_request_endpoint
{
  "testHost": "isamfed.com",
  "testPort": 6443
}
2022-10-17 09:45:01
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Setup Done
Use client_credentials grant to obtain OpenBanking UK intent_id
2022-10-17 09:45:01 SUCCESS
CreateTokenEndpointRequestForClientCredentialsGrant
Created token endpoint request
grant_type
client_credentials
scope
openid email
2022-10-17 09:45:01 SUCCESS
SetAccountScopeOnTokenEndpointRequest
Set scope parameter to accounts for OB testing
grant_type
client_credentials
scope
accounts
2022-10-17 09:45:01 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
client_ukob01
sub
client_ukob01
aud
https://isamfed.com:6443/isvaop/oauth2/token
jti
aYpmqPzVU1SNrZNicE4D
iat
1665999901
exp
1665999961
2022-10-17 09:45:01 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk5NjEsImlhdCI6MTY2NTk5OTkwMSwianRpIjoiYVlwbXFQelZVMVNOclpOaWNFNEQifQ.A5ZGybKNj4cbmAFOk2QLacV1iuEyT5fNQzD58yfOPgGwDVro-VOf5hQ0eo2ONOSQgs550xbGsNkWafZY8fpp1oRGnMj8Xz5hxg8_QktZE2Lb15J6hYXqahRgAyRYe_h88FKlI0NmuP5aHxGvYCGBCMJDkhkxodJFWaja80eTJ6xlQSayoqD5A-pzQNBJUZBsBt_qbBVR8nuIeoSPWUigA-ekVc7eCp-MJmWuoQXhGgIKFrdJeKqfXnccOz-dlOkoEOht48xXfChoDeuWEV5zx7_0klPvrZrnc23bWx05Rqe-RmAWz3OQOmedWOwOgCxFHJFb5vgl_twIQkL2zU90ng
2022-10-17 09:45:01
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
client_credentials
scope
accounts
client_assertion
eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk5NjEsImlhdCI6MTY2NTk5OTkwMSwianRpIjoiYVlwbXFQelZVMVNOclpOaWNFNEQifQ.A5ZGybKNj4cbmAFOk2QLacV1iuEyT5fNQzD58yfOPgGwDVro-VOf5hQ0eo2ONOSQgs550xbGsNkWafZY8fpp1oRGnMj8Xz5hxg8_QktZE2Lb15J6hYXqahRgAyRYe_h88FKlI0NmuP5aHxGvYCGBCMJDkhkxodJFWaja80eTJ6xlQSayoqD5A-pzQNBJUZBsBt_qbBVR8nuIeoSPWUigA-ekVc7eCp-MJmWuoQXhGgIKFrdJeKqfXnccOz-dlOkoEOht48xXfChoDeuWEV5zx7_0klPvrZrnc23bWx05Rqe-RmAWz3OQOmedWOwOgCxFHJFb5vgl_twIQkL2zU90ng
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-10-17 09:45:01
CallTokenEndpoint
HTTP request
request_uri
https://isamfed.com:6443/isvaop/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "765"
}
request_body
grant_type=client_credentials&scope=accounts&client_assertion=eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk5NjEsImlhdCI6MTY2NTk5OTkwMSwianRpIjoiYVlwbXFQelZVMVNOclpOaWNFNEQifQ.A5ZGybKNj4cbmAFOk2QLacV1iuEyT5fNQzD58yfOPgGwDVro-VOf5hQ0eo2ONOSQgs550xbGsNkWafZY8fpp1oRGnMj8Xz5hxg8_QktZE2Lb15J6hYXqahRgAyRYe_h88FKlI0NmuP5aHxGvYCGBCMJDkhkxodJFWaja80eTJ6xlQSayoqD5A-pzQNBJUZBsBt_qbBVR8nuIeoSPWUigA-ekVc7eCp-MJmWuoQXhGgIKFrdJeKqfXnccOz-dlOkoEOht48xXfChoDeuWEV5zx7_0klPvrZrnc23bWx05Rqe-RmAWz3OQOmedWOwOgCxFHJFb5vgl_twIQkL2zU90ng&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d",
  "key": "MIIEpAIBAAKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABAoIBAEOmr/MnPlWdb41vtTyC9q5XB6sB6JR3fABUARhHj6MMTzWGZU9k2TE4TVWm0xiDPSXAwVADrWnJePlZq0RdRd3MX9iO5daQPZnAEX3Iin9t44jHrZSmClEH6D4b0ur5osgLnMx2R/I3L+lPJfrd/fjpt1lMxjAHCz7Jb7INTnLMjBl8Lji9witoeQseo2+SRLanNckCw9t2/WkqlpyTUnVg6icB9QLAh0ASE/zlMdFMYlo1llfxToRpZKQuE0zTXtvMqfkutqSUb8hLSBTYuMHOh8aycMB//JgiAMwrHVSVcRn2oMqnk5vm08i/sLK8TT8AGAf8Evn0GJJ88kKHvqECgYEA2Xnd/4+98ZiEnLbkgRPVX7pWVa2ZqCAZ4Cf75cv+IlQ3crJniX0IEOpFS71fF8/Ei7DIAELe9zeopQvkUdfzMlC7Rg5AuhJzRIL+FaUFlLJOMz+S7eqiLeabclYGIbZrX+n8Xic01oQxRipgV1XMKj+D3MROUoRCWNMS1Xqghe0CgYEAxQbFsTjipyvk6ZvrpucqAZ1IVIGiVELGMlUEGmyJ8CgXd3gwmU88RahmwBes0GNzm5hws9J+C/S/zt6gu1pP1g/lEpx4/yxg6MZk8AQEk3VG63Tg2rEzjEIQsz0fTXbO1AVSJvEuReB8VCgQEKNYMxrqdHXvpSFHOhQLbvebODkCgYEAgK7e0IjCkQF5fq2t+j69JD7DNUFayaPtC7k9EVWqk6+Xe7PbFfy42CF3TYDJkvJqz2mUfqsS+d+iV774pAEPM3eXyLVIUZH3SNPl+vLBoaH8KdD1ZPhQbK6mznneePZTBNcUcLXsSv6/lVAf362x+FHK+cfivGrsQ1jqLQ25jGUCgYBVrLY2dDgK3YlzE/wK3aZkgVI8fQprfYXVySY5n0z0A1sA9mCbqdrZp3rWuPTKwRQ6arVHXJa2+DyX5jMahREGUm8YAraSr2eMkQi/Xd/nhy3JoU9NiZSSvv+oEUIVWz5g79djW6j1dcJajfk+Yuktf9zHu6jzs17XoHPAUydJ8QKBgQCreujKz7G5EEXkwdEqFFolM9A8ZMB2k3t6FaM4P/lEUs+nFkxYz2+rxI4HMCE0UOCw58ukQjNmXJhumAAB0HIC28gFVuk8FXPRI46ZRQ4uuqQcSCr3/0yPSrJe3uU+IC74iHff9XHmwiHwcpmgsDclyg4Ga5eCf1XNKmZLtu/4Xg\u003d\u003d",
  "ca": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d"
}
2022-10-17 09:45:02 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "content-length": "208",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Mon, 17 Oct 2022 09:45:02 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-8b4d20e9-879d-410f-9a93-ff2d345fb924",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache",
  "set-cookie": "PD-S-SESSION-ID\u003d1_2_1_cjEExgI9wKiCU4g+GGurjEBP9u6tyPQhPWvEw6Tv4z6zlGBb; Path\u003d/; Secure; HttpOnly"
}
response_body
{"access_token":"PXG4m2QhUBvevel17i8hlTqTXnP9xzFwz0OIH2adB8c.ABWBPKGPl7U5bxo-tCAL3ehPXUaLGqop4f5V3VoPU8KeTFEN1lHDfOm5oyWq5ZYq7O7S-ibjojsv3BiM5hQTxw","expires_in":7199,"scope":"accounts","token_type":"bearer"}
2022-10-17 09:45:02 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
PXG4m2QhUBvevel17i8hlTqTXnP9xzFwz0OIH2adB8c.ABWBPKGPl7U5bxo-tCAL3ehPXUaLGqop4f5V3VoPU8KeTFEN1lHDfOm5oyWq5ZYq7O7S-ibjojsv3BiM5hQTxw
expires_in
7199
scope
accounts
token_type
bearer
2022-10-17 09:45:02 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-10-17 09:45:02 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
PXG4m2QhUBvevel17i8hlTqTXnP9xzFwz0OIH2adB8c.ABWBPKGPl7U5bxo-tCAL3ehPXUaLGqop4f5V3VoPU8KeTFEN1lHDfOm5oyWq5ZYq7O7S-ibjojsv3BiM5hQTxw
2022-10-17 09:45:02 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
PXG4m2QhUBvevel17i8hlTqTXnP9xzFwz0OIH2adB8c.ABWBPKGPl7U5bxo-tCAL3ehPXUaLGqop4f5V3VoPU8KeTFEN1lHDfOm5oyWq5ZYq7O7S-ibjojsv3BiM5hQTxw
type
bearer
2022-10-17 09:45:02 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2022-10-17 09:45:02 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2022-10-17 09:45:02
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2022-10-17 09:45:02 SUCCESS
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Mon, 17 Oct 2022 09:45:02 GMT"
}
2022-10-17 09:45:02 SUCCESS
CreateCreateAccountRequestRequest
account_requests_endpoint_request
{
  "Data": {
    "Permissions": [
      "ReadAccountsBasic"
    ]
  },
  "Risk": {}
}
2022-10-17 09:45:02
CallAccountRequestsEndpointWithBearerToken
Found '/v3.' in the resource url, using OB V3 API 'account-access-consents'
resource_endpoint
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/
2022-10-17 09:45:02
CallAccountRequestsEndpointWithBearerToken
HTTP request
request_uri
https://isamfed.com:6443/isvaop/oauth2/open-banking/v3.1/aisp/account-access-consents
request_method
POST
request_headers
{
  "accept": "application/json",
  "x-fapi-auth-date": "Mon, 17 Oct 2022 09:45:02 GMT",
  "content-type": "application/json",
  "authorization": "Bearer PXG4m2QhUBvevel17i8hlTqTXnP9xzFwz0OIH2adB8c.ABWBPKGPl7U5bxo-tCAL3ehPXUaLGqop4f5V3VoPU8KeTFEN1lHDfOm5oyWq5ZYq7O7S-ibjojsv3BiM5hQTxw",
  "content-length": "56"
}
request_body
{"Data":{"Permissions":["ReadAccountsBasic"]},"Risk":{}}
request_mutual_tls
{
  "cert": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d",
  "key": "MIIEpAIBAAKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABAoIBAEOmr/MnPlWdb41vtTyC9q5XB6sB6JR3fABUARhHj6MMTzWGZU9k2TE4TVWm0xiDPSXAwVADrWnJePlZq0RdRd3MX9iO5daQPZnAEX3Iin9t44jHrZSmClEH6D4b0ur5osgLnMx2R/I3L+lPJfrd/fjpt1lMxjAHCz7Jb7INTnLMjBl8Lji9witoeQseo2+SRLanNckCw9t2/WkqlpyTUnVg6icB9QLAh0ASE/zlMdFMYlo1llfxToRpZKQuE0zTXtvMqfkutqSUb8hLSBTYuMHOh8aycMB//JgiAMwrHVSVcRn2oMqnk5vm08i/sLK8TT8AGAf8Evn0GJJ88kKHvqECgYEA2Xnd/4+98ZiEnLbkgRPVX7pWVa2ZqCAZ4Cf75cv+IlQ3crJniX0IEOpFS71fF8/Ei7DIAELe9zeopQvkUdfzMlC7Rg5AuhJzRIL+FaUFlLJOMz+S7eqiLeabclYGIbZrX+n8Xic01oQxRipgV1XMKj+D3MROUoRCWNMS1Xqghe0CgYEAxQbFsTjipyvk6ZvrpucqAZ1IVIGiVELGMlUEGmyJ8CgXd3gwmU88RahmwBes0GNzm5hws9J+C/S/zt6gu1pP1g/lEpx4/yxg6MZk8AQEk3VG63Tg2rEzjEIQsz0fTXbO1AVSJvEuReB8VCgQEKNYMxrqdHXvpSFHOhQLbvebODkCgYEAgK7e0IjCkQF5fq2t+j69JD7DNUFayaPtC7k9EVWqk6+Xe7PbFfy42CF3TYDJkvJqz2mUfqsS+d+iV774pAEPM3eXyLVIUZH3SNPl+vLBoaH8KdD1ZPhQbK6mznneePZTBNcUcLXsSv6/lVAf362x+FHK+cfivGrsQ1jqLQ25jGUCgYBVrLY2dDgK3YlzE/wK3aZkgVI8fQprfYXVySY5n0z0A1sA9mCbqdrZp3rWuPTKwRQ6arVHXJa2+DyX5jMahREGUm8YAraSr2eMkQi/Xd/nhy3JoU9NiZSSvv+oEUIVWz5g79djW6j1dcJajfk+Yuktf9zHu6jzs17XoHPAUydJ8QKBgQCreujKz7G5EEXkwdEqFFolM9A8ZMB2k3t6FaM4P/lEUs+nFkxYz2+rxI4HMCE0UOCw58ukQjNmXJhumAAB0HIC28gFVuk8FXPRI46ZRQ4uuqQcSCr3/0yPSrJe3uU+IC74iHff9XHmwiHwcpmgsDclyg4Ga5eCf1XNKmZLtu/4Xg\u003d\u003d",
  "ca": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d"
}
2022-10-17 09:45:05 RESPONSE
CallAccountRequestsEndpointWithBearerToken
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "content-length": "276",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Mon, 17 Oct 2022 09:45:05 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-30992c80-2d69-474b-89cc-79dd97f3cb58",
  "x-fapi-interaction-id": "c799cad9-9787-451e-aaff-4c1ef69a2caf",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "set-cookie": "PD-S-SESSION-ID\u003d1_2_1_bcB+ZRr66R-Ru2gnJW9oy0CtmyGqiKnwpIRu6faoA0TpEz+t; Path\u003d/; Secure; HttpOnly"
}
response_body
{"Data":{"Permissions":["ReadAccountsBasic"],"ConsentId":"client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe","Status":"AwaitingAuthorisation","CreationDateTime":"2022-10-17T09:45:05+07:00","StatusUpdateDateTime":"2022-10-17T09:45:05+07:00"},"Meta":{"TotalPages":1},"Risk":{}}
2022-10-17 09:45:05
CallAccountRequestsEndpointWithBearerToken
Account requests endpoint response
account_requests_endpoint_response
{"Data":{"Permissions":["ReadAccountsBasic"],"ConsentId":"client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe","Status":"AwaitingAuthorisation","CreationDateTime":"2022-10-17T09:45:05+07:00","StatusUpdateDateTime":"2022-10-17T09:45:05+07:00"},"Meta":{"TotalPages":1},"Risk":{}}
2022-10-17 09:45:05 SUCCESS
CallAccountRequestsEndpointWithBearerToken
Parsed account requests endpoint response
headers
{
  "content-length": "276",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Mon, 17 Oct 2022 09:45:05 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-correlation-id": "CORR_ID-30992c80-2d69-474b-89cc-79dd97f3cb58",
  "x-fapi-interaction-id": "c799cad9-9787-451e-aaff-4c1ef69a2caf",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "set-cookie": "PD-S-SESSION-ID\u003d1_2_1_bcB+ZRr66R-Ru2gnJW9oy0CtmyGqiKnwpIRu6faoA0TpEz+t; Path\u003d/; Secure; HttpOnly"
}
body
{"Data":{"Permissions":["ReadAccountsBasic"],"ConsentId":"client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe","Status":"AwaitingAuthorisation","CreationDateTime":"2022-10-17T09:45:05+07:00","StatusUpdateDateTime":"2022-10-17T09:45:05+07:00"},"Meta":{"TotalPages":1},"Risk":{}}
2022-10-17 09:45:05 SUCCESS
CheckIfAccountRequestsEndpointResponseError
No error from account requests endpoint
2022-10-17 09:45:05 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
c799cad9-9787-451e-aaff-4c1ef69a2caf
2022-10-17 09:45:05 SUCCESS
ExtractAccountRequestIdFromAccountRequestsEndpointResponse
Extracted the account request ID
account_request_id
client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe
Make request to authorization endpoint
2022-10-17 09:45:05 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
client_ukob01
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
scope
openid email
2022-10-17 09:45:05 SUCCESS
AddAccountRequestIdToAuthorizationEndpointRequest
Added openbanking_intent_id claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "client_ukob01",
  "redirect_uri": "https://www.certification.openid.net/test/a/ISVAOP/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "openbanking_intent_id": {
        "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
        "essential": true
      }
    }
  }
}
2022-10-17 09:45:05 SUCCESS
OpenBankingUkAddMultipleAcrClaimsToAuthorizationEndpointRequest
Added acr to request as an essential id_token claim
authorization_endpoint_request
{
  "client_id": "client_ukob01",
  "redirect_uri": "https://www.certification.openid.net/test/a/ISVAOP/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "openbanking_intent_id": {
        "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
        "essential": true
      },
      "acr": {
        "values": [
          "urn:openbanking:psd2:sca",
          "urn:openbanking:psd2:ca"
        ],
        "essential": true
      }
    }
  }
}
2022-10-17 09:45:05
CreateRandomStateValue
Created state value
requested_state_length
10
state
5pCH00jMLo
2022-10-17 09:45:05 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
client_ukob01
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
scope
openid email
claims
{
  "id_token": {
    "openbanking_intent_id": {
      "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
      "essential": true
    },
    "acr": {
      "values": [
        "urn:openbanking:psd2:sca",
        "urn:openbanking:psd2:ca"
      ],
      "essential": true
    }
  }
}
state
5pCH00jMLo
2022-10-17 09:45:05
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
cfqSxHYLsX
2022-10-17 09:45:05 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
client_ukob01
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
scope
openid email
claims
{
  "id_token": {
    "openbanking_intent_id": {
      "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
      "essential": true
    },
    "acr": {
      "values": [
        "urn:openbanking:psd2:sca",
        "urn:openbanking:psd2:ca"
      ],
      "essential": true
    }
  }
}
state
5pCH00jMLo
nonce
cfqSxHYLsX
2022-10-17 09:45:05 SUCCESS
SetAuthorizationEndpointRequestResponseTypeToCodeIdtoken
Added response_type parameter to request
client_id
client_ukob01
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
scope
openid email
claims
{
  "id_token": {
    "openbanking_intent_id": {
      "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
      "essential": true
    },
    "acr": {
      "values": [
        "urn:openbanking:psd2:sca",
        "urn:openbanking:psd2:ca"
      ],
      "essential": true
    }
  }
}
state
5pCH00jMLo
nonce
cfqSxHYLsX
response_type
code id_token
2022-10-17 09:45:05 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "client_id": "client_ukob01",
  "redirect_uri": "https://www.certification.openid.net/test/a/ISVAOP/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "openbanking_intent_id": {
        "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
        "essential": true
      },
      "acr": {
        "values": [
          "urn:openbanking:psd2:sca",
          "urn:openbanking:psd2:ca"
        ],
        "essential": true
      }
    }
  },
  "state": "5pCH00jMLo",
  "nonce": "cfqSxHYLsX",
  "response_type": "code id_token"
}
2022-10-17 09:45:05 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.665999905E9
2022-10-17 09:45:05 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.666000205E9
2022-10-17 09:45:05 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://isamfed.com:6443/isvaop/oauth2
2022-10-17 09:45:05 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
client_ukob01
2022-10-17 09:45:05 SUCCESS
AddClientIdToRequestObject
Added client_id to request object claims
client_id
client_ukob01
2022-10-17 09:45:05 SUCCESS
SignRequestObject
Signed the request object
claims
{
  "aud": "https://isamfed.com:6443/isvaop/oauth2",
  "nbf": 1665999905,
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "values": [
          "urn:openbanking:psd2:sca",
          "urn:openbanking:psd2:ca"
        ],
        "essential": true
      },
      "openbanking_intent_id": {
        "value": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
        "essential": true
      }
    }
  },
  "iss": "client_ukob01",
  "response_type": "code id_token",
  "redirect_uri": "https://www.certification.openid.net/test/a/ISVAOP/callback",
  "state": "5pCH00jMLo",
  "exp": 1666000205,
  "nonce": "cfqSxHYLsX",
  "client_id": "client_ukob01"
}
header
{
  "kid": "ristrettotest",
  "alg": "PS256"
}
request_object
eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206NjQ0M1wvaXN2YW9wXC9vYXV0aDIiLCJuYmYiOjE2NjU5OTk5MDUsInNjb3BlIjoib3BlbmlkIGVtYWlsIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZXMiOlsidXJuOm9wZW5iYW5raW5nOnBzZDI6c2NhIiwidXJuOm9wZW5iYW5raW5nOnBzZDI6Y2EiXSwiZXNzZW50aWFsIjp0cnVlfSwib3BlbmJhbmtpbmdfaW50ZW50X2lkIjp7InZhbHVlIjoiY2xpZW50X3Vrb2IwMS43ZjZlZTZkYy01OGI5LTQ1ODMtODY4Zi1iNzE4NzIwMTEyZmUiLCJlc3NlbnRpYWwiOnRydWV9fX0sImlzcyI6ImNsaWVudF91a29iMDEiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9JU1ZBT1BcL2NhbGxiYWNrIiwic3RhdGUiOiI1cENIMDBqTUxvIiwiZXhwIjoxNjY2MDAwMjA1LCJub25jZSI6ImNmcVN4SFlMc1giLCJjbGllbnRfaWQiOiJjbGllbnRfdWtvYjAxIn0.cnJt8I09nwp4AQNCdBv3_MnkoZWg-sEj4F6f-imj0NiLmV41PEkSrfZzIj1bKSkHb8JRrGEZB8Ko0Fnxkw0TI7SxNHET1vbrQDi0HQihL61WCPDwT1k7dcsE4BX5mWWFKQ03xZRvE8tD6waDmUv6NRCoAjv5zc0PcnGzv9bhD4shXAzTk-U_H1l0qRatDlNMbdS0l41j0nceIOBLjbIZM2VCJYMmAS4bodG8sDi5QXalRts2hGhIIZh7ZD0N2OjC7QisVv3zy8eUPzdMSW2lIwQH4ml7dYFWpJMa9Dj_kWi_7BJ6gMTRIBcYh6Jyhb-th__qMGnxR3MHkUR6l2E87Q
key
{
  "p": "5POsvBfNiTqioCBLGaWsOQwTCPkGAECgCeWXqQykp6Cfbfoi1mvbRDAbNPjoLP88bOOt9v528Tpsi8ZuwQRn9XiK8IyyuxIrDaGBvfZCLCK513R8rX3gj-raer-FMaEIpr1bYCTOKBhyhcP46nTwfXNxTwfKFY7O0H8sWcBfF_M",
  "kty": "RSA",
  "q": "oqadQZ4jqFife7hlA2viAEGjJMu8ZRRIx15U19XKw4LbgHYAs3p965WO2lHJqkRUwD1YXZwqOcapUs2samp8JmoZ9j3OavwuRV7qW68_xV3W5xG8lV41RfKLX0c1ny7jJhPWOAbuJzjp3okjqy3hUBZ8Y2B25A2u8fxuhf7U3x0",
  "d": "Z-mgweEYkai9vr_dBYL0LaaHcfVv4D0X638cQIl99VNzZ8h3GqwtLC_zN6kx89S9C8nprfP2NvTegKxs-2bh-FN08k16zolcx6jEkZSgmUOhMLlpmB0qhHWOnYT047y-h9rQ9rZCVxIClJu5Whh8pa_Xlm3BDlbgJBEZSZAwbuWojQ3a-1J6Z8dP6aGqICUxOofz8z2KGxfQnCTmDIyfdCePmBlx7zdFvgq7SI9fDywkfo0ReBmVA4UX9DIbeR2nShZ53Q54rAPzbBLdwD3NzGeGN7Fk53PT3uYVBUq8nNzIwtdaeTRJ7_QxBBy769uG6I2yKIEE3hHldQT0hTs5AQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "ristrettotest",
  "qi": "uzQHF2KOelrHJhOYBmoHkbiQqczkA3AQXOwAQME3P32dFJgOOB6QdCfrg1C2JTobx8Q3EVoko1j96QE2XCrWEBs9oW-4gg4CPGaU7BmVFt0lB88-ZD6E2N0byg2mekYtdGR3ifispEZHdIBP7TxW82in3fn-nB08YMqQAqqIGes",
  "dp": "UcoLBxapwkBEIFfo_DyHDcoWcrojPqvXgDGYwDdYCtoCmlMlZtwY9H8K-R2CM7DqcSvU1cuJyhtI85XrsuBUEwkA-XYJ03JmFvR_WNFESmgNY76lW4UAV-laK0eH2XbhlE9I-Uusqf4xyz97CKbF0ssOy2DI_HKLx0fnHBjw36k",
  "alg": "PS256",
  "dq": "KSaoYMKm2N_bMc0cWXpBCrmQki2ts5EnPLHEG3tuunpwGJdCZCZYl3MWWmwY7qgtHRooMj7hfA6kJlv9BEt-r6VmfiNzByRYfJqgBqRXKRMt3PZi1ROpvNG5q1hz25tcQvT_3Nr8BBZlLTVbPeL0v3OA8w-j5N0FZxnryKEJsI0",
  "n": "kXc19SlD_vUPcIA9Rf43Nd2kyvaPmsF8_BnwmX3N8svnIFlpAcSMeDKRGjpSZpOaVnrHyTeq19CFoTgRt1DT5mUJp9JmsXSZumMbcQBzCiwQvBO988nFCiZAJedAyo05PpuFQgIP0kQInEAevcduDeRWedE7pdb1TGMGnsLl7C3A7KdNBzU0sYooA04OYUGtJAdGaja-tSkZpHUAit7ywS2cBOx5UuNc2_oqWDoE7S_RfxYqouoIV36o0nR_IukvhpdGQ3aX8JVXHSdiuAgOmu3v3X6JKem20f2rt8-mKG0kqBLIYbYHErTwPtaXbs2H6vtRECrTSPlRIbh_j95jhw"
}
2022-10-17 09:45:05 SUCCESS
BuildRequestObjectByValueRedirectToAuthorizationEndpoint
Sending to authorization endpoint
redirect_to_authorization_endpoint
https://isamfed.com:6443/isvaop/oauth2/authorize?request=eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206NjQ0M1wvaXN2YW9wXC9vYXV0aDIiLCJuYmYiOjE2NjU5OTk5MDUsInNjb3BlIjoib3BlbmlkIGVtYWlsIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZXMiOlsidXJuOm9wZW5iYW5raW5nOnBzZDI6c2NhIiwidXJuOm9wZW5iYW5raW5nOnBzZDI6Y2EiXSwiZXNzZW50aWFsIjp0cnVlfSwib3BlbmJhbmtpbmdfaW50ZW50X2lkIjp7InZhbHVlIjoiY2xpZW50X3Vrb2IwMS43ZjZlZTZkYy01OGI5LTQ1ODMtODY4Zi1iNzE4NzIwMTEyZmUiLCJlc3NlbnRpYWwiOnRydWV9fX0sImlzcyI6ImNsaWVudF91a29iMDEiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9JU1ZBT1BcL2NhbGxiYWNrIiwic3RhdGUiOiI1cENIMDBqTUxvIiwiZXhwIjoxNjY2MDAwMjA1LCJub25jZSI6ImNmcVN4SFlMc1giLCJjbGllbnRfaWQiOiJjbGllbnRfdWtvYjAxIn0.cnJt8I09nwp4AQNCdBv3_MnkoZWg-sEj4F6f-imj0NiLmV41PEkSrfZzIj1bKSkHb8JRrGEZB8Ko0Fnxkw0TI7SxNHET1vbrQDi0HQihL61WCPDwT1k7dcsE4BX5mWWFKQ03xZRvE8tD6waDmUv6NRCoAjv5zc0PcnGzv9bhD4shXAzTk-U_H1l0qRatDlNMbdS0l41j0nceIOBLjbIZM2VCJYMmAS4bodG8sDi5QXalRts2hGhIIZh7ZD0N2OjC7QisVv3zy8eUPzdMSW2lIwQH4ml7dYFWpJMa9Dj_kWi_7BJ6gMTRIBcYh6Jyhb-th__qMGnxR3MHkUR6l2E87Q&client_id=client_ukob01&redirect_uri=https://www.certification.openid.net/test/a/ISVAOP/callback&scope=openid%20email&response_type=code%20id_token
2022-10-17 09:45:05 REDIRECT
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Redirecting to authorization endpoint
redirect_to
https://isamfed.com:6443/isvaop/oauth2/authorize?request=eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJhdWQiOiJodHRwczpcL1wvaXNhbWZlZC5jb206NjQ0M1wvaXN2YW9wXC9vYXV0aDIiLCJuYmYiOjE2NjU5OTk5MDUsInNjb3BlIjoib3BlbmlkIGVtYWlsIiwiY2xhaW1zIjp7ImlkX3Rva2VuIjp7ImFjciI6eyJ2YWx1ZXMiOlsidXJuOm9wZW5iYW5raW5nOnBzZDI6c2NhIiwidXJuOm9wZW5iYW5raW5nOnBzZDI6Y2EiXSwiZXNzZW50aWFsIjp0cnVlfSwib3BlbmJhbmtpbmdfaW50ZW50X2lkIjp7InZhbHVlIjoiY2xpZW50X3Vrb2IwMS43ZjZlZTZkYy01OGI5LTQ1ODMtODY4Zi1iNzE4NzIwMTEyZmUiLCJlc3NlbnRpYWwiOnRydWV9fX0sImlzcyI6ImNsaWVudF91a29iMDEiLCJyZXNwb25zZV90eXBlIjoiY29kZSBpZF90b2tlbiIsInJlZGlyZWN0X3VyaSI6Imh0dHBzOlwvXC93d3cuY2VydGlmaWNhdGlvbi5vcGVuaWQubmV0XC90ZXN0XC9hXC9JU1ZBT1BcL2NhbGxiYWNrIiwic3RhdGUiOiI1cENIMDBqTUxvIiwiZXhwIjoxNjY2MDAwMjA1LCJub25jZSI6ImNmcVN4SFlMc1giLCJjbGllbnRfaWQiOiJjbGllbnRfdWtvYjAxIn0.cnJt8I09nwp4AQNCdBv3_MnkoZWg-sEj4F6f-imj0NiLmV41PEkSrfZzIj1bKSkHb8JRrGEZB8Ko0Fnxkw0TI7SxNHET1vbrQDi0HQihL61WCPDwT1k7dcsE4BX5mWWFKQ03xZRvE8tD6waDmUv6NRCoAjv5zc0PcnGzv9bhD4shXAzTk-U_H1l0qRatDlNMbdS0l41j0nceIOBLjbIZM2VCJYMmAS4bodG8sDi5QXalRts2hGhIIZh7ZD0N2OjC7QisVv3zy8eUPzdMSW2lIwQH4ml7dYFWpJMa9Dj_kWi_7BJ6gMTRIBcYh6Jyhb-th__qMGnxR3MHkUR6l2E87Q&client_id=client_ukob01&redirect_uri=https://www.certification.openid.net/test/a/ISVAOP/callback&scope=openid%20email&response_type=code%20id_token
2022-10-17 09:45:13 INCOMING
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Incoming HTTP request to /test/a/ISVAOP/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,*/*;q\u003d0.8",
  "accept-language": "en,fr;q\u003d0.8,et;q\u003d0.5,en-US;q\u003d0.3",
  "accept-encoding": "gzip, deflate, br",
  "referer": "https://isamfed.com:6443/",
  "cookie": "__utma\u003d201319536.734078888.1579071622.1665495005.1665619380.47; __utmz\u003d201319536.1660655184.40.23.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; _ga\u003dGA1.2.734078888.1579071622; JSESSIONID\u003dE4A71C0427A072DDA46C3AA210D26FBB",
  "upgrade-insecure-requests": "1",
  "sec-fetch-dest": "document",
  "sec-fetch-mode": "navigate",
  "sec-fetch-site": "cross-site",
  "sec-fetch-user": "?1",
  "connection": "close"
}
incoming_path
/test/a/ISVAOP/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-10-17 09:45:13 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/gFKD4vPO3eGnv63WOn4p",
  "fullUrl": "https://www.certification.openid.net/test/a/ISVAOP/implicit/gFKD4vPO3eGnv63WOn4p"
}
2022-10-17 09:45:13 OUTGOING
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Response to HTTP request to test instance kC9MLF05x1wR835
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/ISVAOP/implicit/gFKD4vPO3eGnv63WOn4p, returnUrl=/log-detail.html?log=kC9MLF05x1wR835}]
outgoing_path
callback
2022-10-17 09:45:13 INCOMING
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Incoming HTTP request to /test/a/ISVAOP/implicit/gFKD4vPO3eGnv63WOn4p
incoming_headers
{
  "host": "www.certification.openid.net",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0",
  "accept": "*/*",
  "accept-language": "en,fr;q\u003d0.8,et;q\u003d0.5,en-US;q\u003d0.3",
  "accept-encoding": "gzip, deflate, br",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "origin": "https://www.certification.openid.net",
  "referer": "https://www.certification.openid.net/test/a/ISVAOP/callback",
  "cookie": "__utma\u003d201319536.734078888.1579071622.1665495005.1665619380.47; __utmz\u003d201319536.1660655184.40.23.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; _ga\u003dGA1.2.734078888.1579071622; JSESSIONID\u003dE4A71C0427A072DDA46C3AA210D26FBB",
  "sec-fetch-dest": "empty",
  "sec-fetch-mode": "cors",
  "sec-fetch-site": "same-origin",
  "connection": "close",
  "content-length": "1152"
}
incoming_path
/test/a/ISVAOP/implicit/gFKD4vPO3eGnv63WOn4p
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#code=Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA&id_token=eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw&state=5pCH00jMLo
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-10-17 09:45:13 OUTGOING
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Response to HTTP request to test instance kC9MLF05x1wR835
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/gFKD4vPO3eGnv63WOn4p
2022-10-17 09:45:13
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "code",
    "value": "Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw"
  },
  {
    "name": "state",
    "value": "5pCH00jMLo"
  }
]
2022-10-17 09:45:13 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
code
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw
state
5pCH00jMLo
2022-10-17 09:45:13 REDIRECT-IN
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,*/*;q\u003d0.8",
  "accept-language": "en,fr;q\u003d0.8,et;q\u003d0.5,en-US;q\u003d0.3",
  "accept-encoding": "gzip, deflate, br",
  "referer": "https://isamfed.com:6443/",
  "cookie": "__utma\u003d201319536.734078888.1579071622.1665495005.1665619380.47; __utmz\u003d201319536.1660655184.40.23.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; _ga\u003dGA1.2.734078888.1579071622; JSESSIONID\u003dE4A71C0427A072DDA46C3AA210D26FBB",
  "upgrade-insecure-requests": "1",
  "sec-fetch-dest": "document",
  "sec-fetch-mode": "navigate",
  "sec-fetch-site": "cross-site",
  "sec-fetch-user": "?1",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "code": "Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA",
  "id_token": "eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw",
  "state": "5pCH00jMLo"
}
post_body
Verify authorization endpoint response
2022-10-17 09:45:13 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-10-17 09:45:13 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-10-17 09:45:13 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-10-17 09:45:13 SUCCESS
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
2022-10-17 09:45:13 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-10-17 09:45:13 SUCCESS
ValidateSuccessfulHybridResponseFromAuthorizationEndpoint
authorization endpoint response does not include unexpected parameters
code
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw
state
5pCH00jMLo
2022-10-17 09:45:13 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
5pCH00jMLo
2022-10-17 09:45:13
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
2022-10-17 09:45:13 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
2022-10-17 09:45:13 SUCCESS
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
actual
1040
required
128
2022-10-17 09:45:13 SUCCESS
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
actual
741.1201097145371
expected
96.0
value
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
2022-10-17 09:45:13 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw
header
{
  "kid": "httpserverkey",
  "typ": "JWT",
  "alg": "PS256"
}
claims
{
  "sub": "clientcertuser",
  "email_verified": true,
  "rat": 1665999908,
  "iss": "https://isamfed.com:6443/isvaop/oauth2",
  "nonce": "cfqSxHYLsX",
  "acr": "urn:openbanking:psd2:ca",
  "aud": "client_ukob01",
  "c_hash": "TSTfjdf07l2k-Pw0dS1qvQ",
  "openbanking_intent_id": "client_ukob01.7f6ee6dc-58b9-4583-868f-b718720112fe",
  "s_hash": "448OHi6i66uA6dguJdBm4Q",
  "auth_time": 1665999912,
  "exp": 1666003512,
  "iat": 1665999912,
  "jti": "7533e234-985b-4f7c-96c4-112d30dffee9"
}
2022-10-17 09:45:13 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-10-17 09:45:13
ValidateIdTokenStandardClaims
sub is a string with content
2022-10-17 09:45:13
ValidateIdTokenStandardClaims
email_verified is a boolean
2022-10-17 09:45:13
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-10-17 09:45:13
ValidateIdTokenStandardClaims
Skipping unknown claim: openbanking_intent_id
2022-10-17 09:45:13 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-10-17 09:45:13 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
cfqSxHYLsX
2022-10-17 09:45:13 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:openbanking:psd2:ca
requested
[
  "urn:openbanking:psd2:sca",
  "urn:openbanking:psd2:ca"
]
2022-10-17 09:45:13 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw
2022-10-17 09:45:13 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6Imh0dHBzZXJ2ZXJrZXkiLCJ0eXAiOiJKV1QifQ.eyJhY3IiOiJ1cm46b3BlbmJhbmtpbmc6cHNkMjpjYSIsImF1ZCI6WyJjbGllbnRfdWtvYjAxIl0sImF1dGhfdGltZSI6MTY2NTk5OTkxMiwiY19oYXNoIjoiVFNUZmpkZjA3bDJrLVB3MGRTMXF2USIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJleHAiOjE2NjYwMDM1MTIsImlhdCI6MTY2NTk5OTkxMiwiaXNzIjoiaHR0cHM6Ly9pc2FtZmVkLmNvbTo2NDQzL2lzdmFvcC9vYXV0aDIiLCJqdGkiOiI3NTMzZTIzNC05ODViLTRmN2MtOTZjNC0xMTJkMzBkZmZlZTkiLCJub25jZSI6ImNmcVN4SFlMc1giLCJvcGVuYmFua2luZ19pbnRlbnRfaWQiOiJjbGllbnRfdWtvYjAxLjdmNmVlNmRjLTU4YjktNDU4My04NjhmLWI3MTg3MjAxMTJmZSIsInJhdCI6MTY2NTk5OTkwOCwic19oYXNoIjoiNDQ4T0hpNmk2NnVBNmRndUpkQm00USIsInN1YiI6ImNsaWVudGNlcnR1c2VyIn0.a4-QRDYpXWpPRbni5uka3E5CebnIPmQQ6mLyc8nuHIyV8JU4IG16rmsci5R7OeBmN_q5jLG37iX827fvtvBba8ooKBxESTx6khKVys8lnUPII6jeMa4FdR4xzWLeLYiD-pff_RX64KvF5gCGl8h76pdco6u1fW9cYo_90O8wm89XWQ_Ki67RN52L9rd8_h1fYd_sh1h61jK8rGO2fpZwjPPwc-DDoYAdJshAhUkMRSTWP9luAJNvoC1ex_nNQoyXbYso2VfBBfh8vlsmosGeoqE1qgW9mHfZA7cDFSZcGWjer9Sw3Yfm4P7RsUUswCZdghtNGEFv775lRre3-ysyqw
2022-10-17 09:45:13 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
clientcertuser
2022-10-17 09:45:13
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-10-17 09:45:13 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-10-17 09:45:13 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
httpserverkey
2022-10-17 09:45:13 SUCCESS
OBValidateIdTokenIntentId
openbanking_intent_id passed all validation checks
2022-10-17 09:45:13 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2022-10-17 09:45:13 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-10-17 09:45:13 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
448OHi6i66uA6dguJdBm4Q
alg
PS256
2022-10-17 09:45:13 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
448OHi6i66uA6dguJdBm4Q
unhashed_value
5pCH00jMLo
id_token_hash
448OHi6i66uA6dguJdBm4Q
2022-10-17 09:45:13 SUCCESS
ExtractCHash
Extracted c_hash from ID Token
c_hash
TSTfjdf07l2k-Pw0dS1qvQ
alg
PS256
2022-10-17 09:45:13 SUCCESS
ValidateCHash
c_hash validated successfully
expected_hash
TSTfjdf07l2k-Pw0dS1qvQ
unhashed_value
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
id_token_hash
TSTfjdf07l2k-Pw0dS1qvQ
2022-10-17 09:45:13 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
2022-10-17 09:45:13 SUCCESS
CreateClientAuthenticationAssertionClaims
Created client assertion claims
iss
client_ukob01
sub
client_ukob01
aud
https://isamfed.com:6443/isvaop/oauth2/token
jti
y9EFIPFDeIHlMGbYOwmt
iat
1665999913
exp
1665999973
2022-10-17 09:45:13 SUCCESS
AddExpIs5MinutesInPastToClientAssertionClaims
Added 'exp' is 5 minutes in the past to client_assertion_claims
iss
client_ukob01
sub
client_ukob01
aud
https://isamfed.com:6443/isvaop/oauth2/token
jti
y9EFIPFDeIHlMGbYOwmt
iat
1665999913
exp
1665999613
2022-10-17 09:45:13 SUCCESS
SignClientAuthenticationAssertion
Signed the client assertion
client_assertion
eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk2MTMsImlhdCI6MTY2NTk5OTkxMywianRpIjoieTlFRklQRkRlSUhsTUdiWU93bXQifQ.a1rYL4pluc71VSQJJr-ErERJg08hFlUwjuN5eqzexaIWe8oRXs4RVewM9Fx71l_h5LLLvvvcmk8aBT70Qj1T4DKp1O_NTR7VP3LEigCnk0wCK-DipDO75A-LvjjcbnaUPvdYpGPtn84z-5Hb7PW8fbVqQb_DztLUcHvyuu4vXi5_wAf7EhRpfoMGogpeTKJgK1_jDgxudTHmedafYD_v7LFYtHvFWMC594Aeg-d0ksN1DSk1GWth97nldKvh_ayPQG4Dd1zqcajeXofv-gsqBO5Cv76CSRevKcyNswbMcVqi9s1WwcDpgwJ4AJ3vmCJgpzjb7GLsbpqHAXjOEV1wnQ
2022-10-17 09:45:13
AddClientAssertionToTokenEndpointRequest
Added client assertion
grant_type
authorization_code
code
Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA
redirect_uri
https://www.certification.openid.net/test/a/ISVAOP/callback
client_assertion
eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk2MTMsImlhdCI6MTY2NTk5OTkxMywianRpIjoieTlFRklQRkRlSUhsTUdiWU93bXQifQ.a1rYL4pluc71VSQJJr-ErERJg08hFlUwjuN5eqzexaIWe8oRXs4RVewM9Fx71l_h5LLLvvvcmk8aBT70Qj1T4DKp1O_NTR7VP3LEigCnk0wCK-DipDO75A-LvjjcbnaUPvdYpGPtn84z-5Hb7PW8fbVqQb_DztLUcHvyuu4vXi5_wAf7EhRpfoMGogpeTKJgK1_jDgxudTHmedafYD_v7LFYtHvFWMC594Aeg-d0ksN1DSk1GWth97nldKvh_ayPQG4Dd1zqcajeXofv-gsqBO5Cv76CSRevKcyNswbMcVqi9s1WwcDpgwJ4AJ3vmCJgpzjb7GLsbpqHAXjOEV1wnQ
client_assertion_type
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
2022-10-17 09:45:13
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://isamfed.com:6443/isvaop/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "973"
}
request_body
grant_type=authorization_code&code=Qj_NHM-EK-RTYOPhhy5rJPculfL4D29LaibQPmFzxuw.YzfVsWiO4frXCHmGvBdXKUMZsysMHZQObneM3YHS_6KNzbOVkiNL54pcNEnaJ_1nwCDIrOIUIi17ciz1pB4LZA&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2FISVAOP%2Fcallback&client_assertion=eyJraWQiOiJyaXN0cmV0dG90ZXN0IiwiYWxnIjoiUFMyNTYifQ.eyJzdWIiOiJjbGllbnRfdWtvYjAxIiwiYXVkIjoiaHR0cHM6XC9cL2lzYW1mZWQuY29tOjY0NDNcL2lzdmFvcFwvb2F1dGgyXC90b2tlbiIsImlzcyI6ImNsaWVudF91a29iMDEiLCJleHAiOjE2NjU5OTk2MTMsImlhdCI6MTY2NTk5OTkxMywianRpIjoieTlFRklQRkRlSUhsTUdiWU93bXQifQ.a1rYL4pluc71VSQJJr-ErERJg08hFlUwjuN5eqzexaIWe8oRXs4RVewM9Fx71l_h5LLLvvvcmk8aBT70Qj1T4DKp1O_NTR7VP3LEigCnk0wCK-DipDO75A-LvjjcbnaUPvdYpGPtn84z-5Hb7PW8fbVqQb_DztLUcHvyuu4vXi5_wAf7EhRpfoMGogpeTKJgK1_jDgxudTHmedafYD_v7LFYtHvFWMC594Aeg-d0ksN1DSk1GWth97nldKvh_ayPQG4Dd1zqcajeXofv-gsqBO5Cv76CSRevKcyNswbMcVqi9s1WwcDpgwJ4AJ3vmCJgpzjb7GLsbpqHAXjOEV1wnQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
request_mutual_tls
{
  "cert": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d",
  "key": "MIIEpAIBAAKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABAoIBAEOmr/MnPlWdb41vtTyC9q5XB6sB6JR3fABUARhHj6MMTzWGZU9k2TE4TVWm0xiDPSXAwVADrWnJePlZq0RdRd3MX9iO5daQPZnAEX3Iin9t44jHrZSmClEH6D4b0ur5osgLnMx2R/I3L+lPJfrd/fjpt1lMxjAHCz7Jb7INTnLMjBl8Lji9witoeQseo2+SRLanNckCw9t2/WkqlpyTUnVg6icB9QLAh0ASE/zlMdFMYlo1llfxToRpZKQuE0zTXtvMqfkutqSUb8hLSBTYuMHOh8aycMB//JgiAMwrHVSVcRn2oMqnk5vm08i/sLK8TT8AGAf8Evn0GJJ88kKHvqECgYEA2Xnd/4+98ZiEnLbkgRPVX7pWVa2ZqCAZ4Cf75cv+IlQ3crJniX0IEOpFS71fF8/Ei7DIAELe9zeopQvkUdfzMlC7Rg5AuhJzRIL+FaUFlLJOMz+S7eqiLeabclYGIbZrX+n8Xic01oQxRipgV1XMKj+D3MROUoRCWNMS1Xqghe0CgYEAxQbFsTjipyvk6ZvrpucqAZ1IVIGiVELGMlUEGmyJ8CgXd3gwmU88RahmwBes0GNzm5hws9J+C/S/zt6gu1pP1g/lEpx4/yxg6MZk8AQEk3VG63Tg2rEzjEIQsz0fTXbO1AVSJvEuReB8VCgQEKNYMxrqdHXvpSFHOhQLbvebODkCgYEAgK7e0IjCkQF5fq2t+j69JD7DNUFayaPtC7k9EVWqk6+Xe7PbFfy42CF3TYDJkvJqz2mUfqsS+d+iV774pAEPM3eXyLVIUZH3SNPl+vLBoaH8KdD1ZPhQbK6mznneePZTBNcUcLXsSv6/lVAf362x+FHK+cfivGrsQ1jqLQ25jGUCgYBVrLY2dDgK3YlzE/wK3aZkgVI8fQprfYXVySY5n0z0A1sA9mCbqdrZp3rWuPTKwRQ6arVHXJa2+DyX5jMahREGUm8YAraSr2eMkQi/Xd/nhy3JoU9NiZSSvv+oEUIVWz5g79djW6j1dcJajfk+Yuktf9zHu6jzs17XoHPAUydJ8QKBgQCreujKz7G5EEXkwdEqFFolM9A8ZMB2k3t6FaM4P/lEUs+nFkxYz2+rxI4HMCE0UOCw58ukQjNmXJhumAAB0HIC28gFVuk8FXPRI46ZRQ4uuqQcSCr3/0yPSrJe3uU+IC74iHff9XHmwiHwcpmgsDclyg4Ga5eCf1XNKmZLtu/4Xg\u003d\u003d",
  "ca": "MIIDtzCCAp+gAwIBAgIUecoZmREQNgLwFH/TMEWLTwb1CB8wDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMB4XDTIyMDEwNDA0MzE1M1oXDTQxMDkyMTA0MzE1M1owazELMAkGA1UEBhMCU0cxEjAQBgNVBAgMCXNpbmdhcG9yZTESMBAGA1UEBwwJc2luZ2Fwb3JlMQwwCgYDVQQKDANJQk0xETAPBgNVBAsMCHNlY3VyaXR5MRMwEQYDVQQDDApjbGllbnRJRDAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2CIojMF5NdBrY48wKHtvzUHUPlMcHSYgJM4wv67sDXVSCQOZd07spVW6VG4OdDLvCK+fhdX+EH5+jUkCfCxn1vCiyK/T6ArZJzdcsjFTtEbqAH+jbITYLa1Og38EI0ARvWyPbU4jRd53PKliCRYoZXoKHnEL2fz6voUlIgyBh+0Et++A3RLWPDUnFslJpwwDZl4NkttpTrAgbxMt07vyZuO9nmsiC/Ax9u9lFNrtUtX87Njd957IoLE+hOgEKpNp0cwrw/P8y0/Vk8HtdzHWf6mqmw4gxnmk9s2MIUxoYRJewqgDU4/f7ukY2Kl++ptLUDRUfCuTckS7r+aLIipxQIDAQABo1MwUTAdBgNVHQ4EFgQU/UtMjt5v2kVdyNfPDjijZi42WIQwHwYDVR0jBBgwFoAU/UtMjt5v2kVdyNfPDjijZi42WIQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAWex3c0yfWkszPtF6B4cPUwwTMiwQ2GyQxxeV9iOuXoMQ6Nf7IBi3KijaWb17E690/Es4cS0P6WWyWa0pd9e/OWq/7HtA86TTiHUp8lkYM0Bc6317SjOYR3E0oIx53pHXtM/afK+ROzAux9xzztKjGyE13cNJYErSggLeMhW0kwUwRU3Wsl4DYwfqbuT62vvbya/Zf6u/lGvMGHoFozRTqPXtboFKoPLmQXzo92tw1UxRyPmeFiZfIjzee7gOShseCuD2dS59Ie+aD/ymI1FdElDB29J4flhKfJxQl0EQTjXaXR4kRw+zB4OzNIjv3FD2F4kq7qsxzyFb14z8bkp/gA\u003d\u003d"
}
2022-10-17 09:45:14 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
401 UNAUTHORIZED
response_status_text
Unauthorized
response_headers
{
  "content-length": "93",
  "content-type": "application/json;charset\u003dUTF-8",
  "date": "Mon, 17 Oct 2022 09:45:14 GMT",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "cache-control": "no-store",
  "x-correlation-id": "CORR_ID-5c541ccd-9343-412e-93f8-ef7e46fb8f41",
  "strict-transport-security": "max-age\u003d31536000; includeSubDomains",
  "pragma": "no-cache",
  "set-cookie": "PD-S-SESSION-ID\u003d1_2_1_YS9L7ZlQerftK1B1SeVniRqnYyld6g+eIRceOqovxaz+tReY; Path\u003d/; Secure; HttpOnly"
}
response_body
{"error":"invalid_client","error_description":"CSIAQ5146E The client_assertion has expired."}
2022-10-17 09:45:14 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error
invalid_client
error_description
CSIAQ5146E The client_assertion has expired.
2022-10-17 09:45:14 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2022-10-17 09:45:14 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
invalid_client
2022-10-17 09:45:14 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
CSIAQ5146E The client_assertion has expired.
2022-10-17 09:45:14 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
CSIAQ5146E The client_assertion has expired.
2022-10-17 09:45:14 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
2022-10-17 09:45:14 SUCCESS
CheckTokenEndpointHttpStatusIs400Allowing401ForInvalidClientError
Token endpoint http status code was 401 for error 'invalid_client'
2022-10-17 09:45:14 SUCCESS
CheckErrorFromTokenEndpointResponseErrorInvalidClientOrInvalidRequest
Token Endpoint response error returned expected 'error' of 'invalid_client'
expected
[
  "invalid_request",
  "invalid_client"
]
2022-10-17 09:45:14 FINISHED
fapi1-advanced-final-ensure-client-assertion-with-exp-is-5-minutes-in-past-fails
Test has run to completion
testmodule_result
PASSED
2022-10-17 09:45:23
TEST-RUNNER
Alias has now been claimed by another test
alias
ISVAOP
new_test_id
jxcukiO3HUPsQqQ
Test Results