Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-11-23 05:48:29 INFO
TEST-RUNNER
Test instance yeMATDm2bIDC8fB created
baseUrl
https://www.certification.openid.net/test/a/isv_op_oidc_core_test
variant
{
  "client_auth_type": "client_secret_basic",
  "response_type": "code token",
  "server_metadata": "discovery",
  "response_mode": "default",
  "client_registration": "static_client"
}
alias
isv_op_oidc_core_test
description
isv_op_oidc_core_test_static_client
planId
tFf7jwdaGAzXZ
config
{
  "server": {
    "discoveryUrl": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration",
    "login_hint": "isvdev@ibm.com"
  },
  "client": {
    "client_id": "1dc791c1-a17e-4278-98b8-e9d107eb9b1c",
    "client_secret": "P7coVadr6f"
  },
  "client_secret_post": {
    "client_id": "90f139b9-4239-4749-9c9a-811fd04f8338",
    "client_secret": "qojhizMq6p"
  },
  "client2": {
    "client_id": "0123d59f-90a2-4fec-b777-31b8d4b25fed",
    "client_secret": "BEfL8THMYy"
  },
  "consent": {},
  "alias": "isv_op_oidc_core_test",
  "description": "isv_op_oidc_core_test_static_client"
}
testName
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
2022-11-23 05:48:29 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-23 05:48:29
GetDynamicServerConfiguration
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-23 05:48:29 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK022367d9-ae7b-40f4-8faa-dd1aa9fce36b",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281637db42d0126b3cb",
  "vary": "Accept-Encoding",
  "date": "Wed, 23 Nov 2022 05:48:29 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:PN1nJqHyCLX6ZoEuqVNy3+wL6yplUn+D4hyScBzZfBA\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dEB2C80133EF8B3DE8491E557AF91915D~-1~YAAQyjhjaIF5ZqCEAQAAT9EHowjbQ9NvA8VK7KMbsGIG56kTYKBhnAo2dOM1ciCmc2Lvbro6s5mDIfk4QytAWedlhS40aGQeB2ExtqAxfM7WEHV1u+T8OJ/gcD16z+ZOuWORG84pSZZ267aEUhoYAvb3xswY1GLalnP+/NRTNlm/4vq+L/H1TgzY+aLMscIYsYH4FT1JeYp3aCXfq8dwGklzW1y+xCZZcfKRhlvYaP8RqY5ZkWIE1KaW0Wo+orrau4Yh3OgzokZyp2mA0vl9w+hUNyMsEoMZWK/Tvzm6sV3wnDGE60x97Rm5nNvnnR+C+Cc7PdvYWKjMPWlj4fkg+/cM73yNBSOAEYszL6iPh575XfXZlo1cdhK+JI5Bo1YRxI6RESI\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dThu, 23 Nov 2023 05:48:29 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d492FFD2115C2DE2D2EA5CB4E4619D37D~YAAQyjhjaIJ5ZqCEAQAAT9EHoxHD0htpbylh0ON1ecYNbHKG9RZ6H+Nc8Sqi/aF1Vr/iN8YoPfIqSb86r4KK3mgsHbbuAboimOnH9ImOTLsaAryBjvNxP0mEocBeLb5pM4J5qM9TPLJ/jucSlqZCiC9KPyBqo2wLL3xfTEVWifBlLiQ9HGQVuYmEP/HLvCk2GmhAMGbT4tbJ9fbsUwBsHr2cRd/npB9DrwZj6YsNfcx6rRJizF7VNfz01vDpBo4w/KTWKDxEaFmvvMsptCNSwY5Mrde0T3B7rhhWV9pDXzEgABI+n6Us2AnjJ9Uj~3228724~3420996; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dWed, 23 Nov 2022 09:48:29 GMT; Max-Age\u003d14400"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d92",
    "origin; dur\u003d103"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"issuer":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","authorization_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize","token_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token","introspection_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect","userinfo_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo","revocation_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke","pushed_authorization_request_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par","registration_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register","jwks_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks","response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"response_modes_supported":["query","fragment","form_post","jwt","query.jwt","fragment.jwt","form_post.jwt"],"grant_types_supported":["authorization_code","implicit","password","refresh_token","client_credentials"],"token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"authorization_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"authorization_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"authorization_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"id_token_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"id_token_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"id_token_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"userinfo_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"userinfo_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"subject_types_supported":["public"],"scopes_supported":["openid","profile","email","phone","address"],"claims_supported":["uid","family_name","name","mobile_number","employee_id","department","job_title","realmName","email","given_name","tenantId","preferred_username","groupIds","upn","iss","acr"],"claim_types_supported":["normal"],"claims_parameter_supported":true,"request_parameter_supported":true,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"tls_client_certificate_bound_access_tokens":true,"mtls_endpoint_aliases":{"introspection_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect","pushed_authorization_request_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par","revocation_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke","token_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"},"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"]}
2022-11-23 05:48:29 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize
token_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
introspection_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect
userinfo_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
revocation_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke
pushed_authorization_request_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par
registration_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "query",
  "fragment",
  "form_post",
  "jwt",
  "query.jwt",
  "fragment.jwt",
  "form_post.jwt"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "refresh_token",
  "client_credentials"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
authorization_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
authorization_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
authorization_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
id_token_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
id_token_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
id_token_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
userinfo_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
userinfo_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
subject_types_supported
[
  "public"
]
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
claims_supported
[
  "uid",
  "family_name",
  "name",
  "mobile_number",
  "employee_id",
  "department",
  "job_title",
  "realmName",
  "email",
  "given_name",
  "tenantId",
  "preferred_username",
  "groupIds",
  "upn",
  "iss",
  "acr"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
request_parameter_supported
true
request_uri_parameter_supported
true
require_request_uri_registration
true
tls_client_certificate_bound_access_tokens
true
mtls_endpoint_aliases
{
  "introspection_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par",
  "revocation_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke",
  "token_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"
}
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
2022-11-23 05:48:29 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-11-23 05:48:29 SUCCESS
ExtractTLSTestValuesFromServerConfiguration
Extracted TLS information from authorization server configuration
registration_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
authorization_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
token_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
userinfo_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
2022-11-23 05:48:29
FetchServerKeys
Fetching server key
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
2022-11-23 05:48:29
FetchServerKeys
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-23 05:48:29 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK39f3a3b3-ca2d-4389-b8fb-6fbf4303c6b6",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281637db42d02a5e717",
  "vary": "Accept-Encoding",
  "date": "Wed, 23 Nov 2022 05:48:29 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:cn/aXMfJYJlMlh+3RQRa1lshtFX/N7W8wEocmPJgg4I\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d24BCF159B297D9FA0A2CD00E91FB14E8~-1~YAAQyjhjaIZ5ZqCEAQAAS9IHowhB9j71wniYKb4h/5/dsUQxZPRi8RXTsCkqaMODDdOO3p+40FQKobVzKN5K70b+A6+Pj/mJRhP2Y+NJWYxRQKpl1iMAzckX2V6bgUXobk7VDKFw5ing0kvZrVFu4FDTNa7z7N9xYzuTeipfnUlFImGbME9rVOJCpuoLcmP5nyGs6TAfabE5xk+HM+l1o+wY8Yk4G8yUDnnDFT0ueiBraIbAfSSv03E2ZeizhB6ZGtlQC/2XSZaGshUEOWEdJXQvm8jxQkHmlzZMNqq1j0A22uJQLlBwi6TJGozSH9jVhHuTK2h9xRzo6kvEDEa8s4Naw2kkMfasyOMoYE/7tJKJhdyt6U18gWh/5C4TP9Ed9G6SnkU\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dThu, 23 Nov 2023 05:48:29 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dE44F57436B57A8AEE4548B3F8A3E19AF~YAAQyjhjaId5ZqCEAQAAS9IHoxF0X3Cf7rfdYtpnary0Xe6Qs7jUvOfKlI5MxjJcy3jxQMo7v6yDXl2qjfAqxbBZXuhUYC5FKukR7unBmQP7wMLBD7/kyde4uFzGRfLsX4JaPCtTCkmMX8SDctIztf6YP/2IxRt+QppD9cGmproSVZKPBHwAOl+G6sjgjeGHn2PTFTkkFcbs8CQF5LKH+P2S82BqGzu8vX+hCk5mdsYeJJ+Wc1fZPi/Ii6OEQC66VoyAEbgakE8m6zPndv7+bI55JfrP+lsoeMn6l5zad+JElqPo3kmxNxSKt3zo~3228724~3420996; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dWed, 23 Nov 2022 09:48:29 GMT; Max-Age\u003d14400"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d94"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-23 05:48:29
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-23 05:48:29 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-23 05:48:29 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-23 05:48:29 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-11-23 05:48:29 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-11-23 05:48:29 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-11-23 05:48:29 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-11-23 05:48:29 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
1dc791c1-a17e-4278-98b8-e9d107eb9b1c
client_secret
P7coVadr6f
2022-11-23 05:48:29 INFO
ValidateClientJWKsPrivatePart
Skipped evaluation due to missing required element: client jwks
path
jwks
mapped
object
client
2022-11-23 05:48:29 INFO
ExtractJWKsFromStaticClientConfiguration
Skipped evaluation due to missing required element: client jwks
path
jwks
mapped
object
client
2022-11-23 05:48:29 INFO
CheckDistinctKeyIdValueInClientJWKs
Skipped evaluation due to missing required element: client jwks
path
jwks
mapped
object
client
2022-11-23 05:48:29
SetScopeInClientConfigurationToOpenId
Set scope in client configuration to "openid"
scope
openid
2022-11-23 05:48:29 SUCCESS
EnsureServerConfigurationSupportsClientSecretBasic
Contents of 'token_endpoint_auth_methods_supported' in discovery document matches expectations.
actual
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
expected
[
  "client_secret_basic"
]
minimum_matches_required
1
2022-11-23 05:48:29 SUCCESS
SetProtectedResourceUrlToUserInfoEndpoint
userinfo_endpoint will be used to test access token. The user info is not a mandatory to implement feature in the OpenID Connect specification, but is mandatory for certification.
protected_resource_url
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
2022-11-23 05:48:29
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Setup Done
Make request to authorization endpoint
2022-11-23 05:48:29 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
1dc791c1-a17e-4278-98b8-e9d107eb9b1c
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
2022-11-23 05:48:29
CreateRandomStateValue
Created state value
requested_state_length
10
state
pAfJudeqqt
2022-11-23 05:48:29 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
1dc791c1-a17e-4278-98b8-e9d107eb9b1c
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
pAfJudeqqt
2022-11-23 05:48:29
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
N1yoqjoLRQ
2022-11-23 05:48:29
AddNonceToAuthorizationEndpointRequest
NOT adding nonce to request object
2022-11-23 05:48:29 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
1dc791c1-a17e-4278-98b8-e9d107eb9b1c
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
pAfJudeqqt
response_type
code token
2022-11-23 05:48:29 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "1dc791c1-a17e-4278-98b8-e9d107eb9b1c",
  "redirect_uri": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "scope": "openid",
  "state": "pAfJudeqqt",
  "response_type": "code token"
}
redirect_to_authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=1dc791c1-a17e-4278-98b8-e9d107eb9b1c&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=pAfJudeqqt&response_type=code%20token
2022-11-23 05:48:29 REDIRECT
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Redirecting to authorization endpoint
redirect_to
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=1dc791c1-a17e-4278-98b8-e9d107eb9b1c&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=pAfJudeqqt&response_type=code%20token
2022-11-23 05:48:35 INCOMING
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Incoming HTTP request to /test/a/isv_op_oidc_core_test/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669008266.1669169819.16; JSESSIONID\u003d4D796BBE98421D9BA4ADC06BB0F0AD31",
  "connection": "close"
}
incoming_path
/test/a/isv_op_oidc_core_test/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-23 05:48:35 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/cji7K5gtvLwc2ykPrdf7",
  "fullUrl": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/cji7K5gtvLwc2ykPrdf7"
}
2022-11-23 05:48:35 OUTGOING
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Response to HTTP request to test instance yeMATDm2bIDC8fB
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/cji7K5gtvLwc2ykPrdf7, returnUrl=/log-detail.html?log=yeMATDm2bIDC8fB}]
outgoing_path
callback
2022-11-23 05:48:36 INCOMING
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Incoming HTTP request to /test/a/isv_op_oidc_core_test/implicit/cji7K5gtvLwc2ykPrdf7
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669008266.1669169819.16; JSESSIONID\u003d4D796BBE98421D9BA4ADC06BB0F0AD31",
  "connection": "close",
  "content-length": "441"
}
incoming_path
/test/a/isv_op_oidc_core_test/implicit/cji7K5gtvLwc2ykPrdf7
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#access_token=Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4&code=OCA0hLM3pmj9cW2fTVvZovV3J-QbY9tPaavDI-bT3PA.AsM_L1LOHWmwkpPLjobVlqN35KC6am4HVTPznU3AGBM8m6T0zQs_JkaLtvx4VCGJQDWxQb0ACRC9S8aPRDbckg&expires_in=3599&iss=https%3A%2F%2Foidc-conformance.rel.verify.ibmcloudsecurity.com%2Foauth2&scope=openid&state=pAfJudeqqt&token_type=bearer
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-23 05:48:36 OUTGOING
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Response to HTTP request to test instance yeMATDm2bIDC8fB
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/cji7K5gtvLwc2ykPrdf7
2022-11-23 05:48:36
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "access_token",
    "value": "Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4"
  },
  {
    "name": "code",
    "value": "OCA0hLM3pmj9cW2fTVvZovV3J-QbY9tPaavDI-bT3PA.AsM_L1LOHWmwkpPLjobVlqN35KC6am4HVTPznU3AGBM8m6T0zQs_JkaLtvx4VCGJQDWxQb0ACRC9S8aPRDbckg"
  },
  {
    "name": "expires_in",
    "value": "3599"
  },
  {
    "name": "iss",
    "value": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2"
  },
  {
    "name": "scope",
    "value": "openid"
  },
  {
    "name": "state",
    "value": "pAfJudeqqt"
  },
  {
    "name": "token_type",
    "value": "bearer"
  }
]
2022-11-23 05:48:36 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
access_token
Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4
code
OCA0hLM3pmj9cW2fTVvZovV3J-QbY9tPaavDI-bT3PA.AsM_L1LOHWmwkpPLjobVlqN35KC6am4HVTPznU3AGBM8m6T0zQs_JkaLtvx4VCGJQDWxQb0ACRC9S8aPRDbckg
expires_in
3599
iss
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
scope
openid
state
pAfJudeqqt
token_type
bearer
2022-11-23 05:48:36 REDIRECT-IN
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669008266.1669169819.16; JSESSIONID\u003d4D796BBE98421D9BA4ADC06BB0F0AD31",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "access_token": "Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4",
  "code": "OCA0hLM3pmj9cW2fTVvZovV3J-QbY9tPaavDI-bT3PA.AsM_L1LOHWmwkpPLjobVlqN35KC6am4HVTPznU3AGBM8m6T0zQs_JkaLtvx4VCGJQDWxQb0ACRC9S8aPRDbckg",
  "expires_in": "3599",
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "scope": "openid",
  "state": "pAfJudeqqt",
  "token_type": "bearer"
}
post_body
Verify authorization endpoint response
2022-11-23 05:48:36 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-11-23 05:48:36 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-11-23 05:48:36 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-11-23 05:48:36 SUCCESS
ValidateIssInAuthorizationResponse
'iss' parameter in authorization response matches server's issuer value.
2022-11-23 05:48:36 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-11-23 05:48:36 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
pAfJudeqqt
2022-11-23 05:48:36 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
OCA0hLM3pmj9cW2fTVvZovV3J-QbY9tPaavDI-bT3PA.AsM_L1LOHWmwkpPLjobVlqN35KC6am4HVTPznU3AGBM8m6T0zQs_JkaLtvx4VCGJQDWxQb0ACRC9S8aPRDbckg
2022-11-23 05:48:36 SUCCESS
ExtractAccessTokenFromAuthorizationResponse
Extracted the access token
value
Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4
type
bearer
Userinfo endpoint tests
2022-11-23 05:48:36
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer Jnn7J01jC-TZQ9UHjzQuPEpjTMYwGhNJUaEECn9fCM4.quAC_t4ysRS0ptDgd-92IJF8mSt5Jvj72Uj2W_-cxv40oPZyYssDChCrl7RHMYK8O3kOld3ASaCxrV_KL9lsqQ.M18xNjY5MTgyNTE1XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-23 05:48:36 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK14fd7256-6700-4607-b664-5be916c06efe",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281637db4341409df95",
  "content-length": "828",
  "date": "Wed, 23 Nov 2022 05:48:36 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Kq/Ap5Ai+5cSKbCwOjaWE7AG9Syl67lgWo+tVKG8iSo\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d537A600485CE960B2446BA3CED998A2B~-1~YAAQyjhjaEt6ZqCEAQAA5uwHowjuKVOWF1vFzDNS8uymvntTJ75AE9I6LglWEaMTpTXRsKMddlAgWKJEk+Q2xrcWKUll55YLYgMIayLJpP/tKrBrCpHmSKQcGFRrkmWvXjHhDkx0lqRuN+kBNNGutEcCkp5M0JTWLyTR3xpzXAhfuT1lXzRA5jnnHWUZbCWdOGkALobvMIulJ84Ejf6Jwir6nzpVBoVK1hhBDX0Ib6h4wNOjZzGsX4m5yjFaNzQBmD4C8bNeMMSSsFGSJ9QHDV23668Rt9EbVf/ebe52hr6tf/FPeVwV8HWAJn43YpAkACMmhikuBt8vyJgFeCvcOwzejYxgl9s+6Rp+H3FzaROK4n8XnWpqQ5hXSbWZndsHw1zayQc\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dThu, 23 Nov 2023 05:48:36 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d2241D29C4E79DACA2CB617205C44E2B7~YAAQyjhjaEx6ZqCEAQAA5uwHoxGuU29yxwJVCVH1LZ1oaK7LQ8KvXBdtDF64V9zvmoPZLXNvFCm9v0Z8sSI3pxFdiNKUY0JKkTFvJdg73bxT7b3+gucRNEUiVLPeHYpR7ZmqVXfWjujAaI7aaWqsn/U5kxfkNzQK0ssrqbcGCe3i4cHuRbkTBGBhBfmw0Hkhz9VWNgT4K0iFLPsjLxBKLIheP4KRKRI99/TjqAcXupQFmbEkKemkyAum9n5iQAep/V7IXHVnjRQexe76MnZFx3xb/0kyeTKfmro5jfahial0B6FX9Mz9EGabgnQP~4404276~3290690; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dWed, 23 Nov 2022 09:48:36 GMT; Max-Age\u003d14400"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d110",
    "origin; dur\u003d104"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"1","address":{"address":{"country":"US","locality":"Los Angeles","postal_code":"90210","region":"CA","street_address":"1234 Hollywood Blvd."},"phone_number":"+1 (310) 123-4567"},"amr":["password"],"aud":["1dc791c1-a17e-4278-98b8-e9d107eb9b1c"],"auth_time":1669181676,"birthdate":"2022-11-23","email_verified":true,"gender":"Male","iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","locale":"en-US","middle_name":"MiddleName","name":"ISV Dev","nickname":"nickname","phone_number":"123456789","phone_number_verified":true,"picture":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","preferred_username":"isvdev@ibm.com","profile":"End-User","rat":1669182514,"realmName":"cloudIdentityRealm","sub":"6160017N67","updated_at":1669172854,"website":"www.ibm.com","zoneinfo":"America/Los_Angeles"}
2022-11-23 05:48:36 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK14fd7256-6700-4607-b664-5be916c06efe",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281637db4341409df95",
  "content-length": "828",
  "date": "Wed, 23 Nov 2022 05:48:36 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Kq/Ap5Ai+5cSKbCwOjaWE7AG9Syl67lgWo+tVKG8iSo\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d537A600485CE960B2446BA3CED998A2B~-1~YAAQyjhjaEt6ZqCEAQAA5uwHowjuKVOWF1vFzDNS8uymvntTJ75AE9I6LglWEaMTpTXRsKMddlAgWKJEk+Q2xrcWKUll55YLYgMIayLJpP/tKrBrCpHmSKQcGFRrkmWvXjHhDkx0lqRuN+kBNNGutEcCkp5M0JTWLyTR3xpzXAhfuT1lXzRA5jnnHWUZbCWdOGkALobvMIulJ84Ejf6Jwir6nzpVBoVK1hhBDX0Ib6h4wNOjZzGsX4m5yjFaNzQBmD4C8bNeMMSSsFGSJ9QHDV23668Rt9EbVf/ebe52hr6tf/FPeVwV8HWAJn43YpAkACMmhikuBt8vyJgFeCvcOwzejYxgl9s+6Rp+H3FzaROK4n8XnWpqQ5hXSbWZndsHw1zayQc\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dThu, 23 Nov 2023 05:48:36 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d2241D29C4E79DACA2CB617205C44E2B7~YAAQyjhjaEx6ZqCEAQAA5uwHoxGuU29yxwJVCVH1LZ1oaK7LQ8KvXBdtDF64V9zvmoPZLXNvFCm9v0Z8sSI3pxFdiNKUY0JKkTFvJdg73bxT7b3+gucRNEUiVLPeHYpR7ZmqVXfWjujAaI7aaWqsn/U5kxfkNzQK0ssrqbcGCe3i4cHuRbkTBGBhBfmw0Hkhz9VWNgT4K0iFLPsjLxBKLIheP4KRKRI99/TjqAcXupQFmbEkKemkyAum9n5iQAep/V7IXHVnjRQexe76MnZFx3xb/0kyeTKfmro5jfahial0B6FX9Mz9EGabgnQP~4404276~3290690; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dWed, 23 Nov 2022 09:48:36 GMT; Max-Age\u003d14400"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d110",
    "origin; dur\u003d104"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"1","address":{"address":{"country":"US","locality":"Los Angeles","postal_code":"90210","region":"CA","street_address":"1234 Hollywood Blvd."},"phone_number":"+1 (310) 123-4567"},"amr":["password"],"aud":["1dc791c1-a17e-4278-98b8-e9d107eb9b1c"],"auth_time":1669181676,"birthdate":"2022-11-23","email_verified":true,"gender":"Male","iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","locale":"en-US","middle_name":"MiddleName","name":"ISV Dev","nickname":"nickname","phone_number":"123456789","phone_number_verified":true,"picture":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","preferred_username":"isvdev@ibm.com","profile":"End-User","rat":1669182514,"realmName":"cloudIdentityRealm","sub":"6160017N67","updated_at":1669172854,"website":"www.ibm.com","zoneinfo":"America/Los_Angeles"}
2022-11-23 05:48:36 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-23 05:48:36 FINISHED
oidcc-ensure-request-without-nonce-succeeds-for-code-flow
Test has run to completion
testmodule_result
PASSED
Unregister dynamically registered client
2022-11-23 05:48:36
UnregisterDynamicallyRegisteredClient
Couldn't find registration_access_token.
2022-11-23 05:48:39
TEST-RUNNER
Alias has now been claimed by another test
alias
isv_op_oidc_core_test
new_test_id
LfnrT2puL9OTfee
Test Results