Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-11-27 18:28:00 INFO
TEST-RUNNER
Test instance 61w1ztweyful7WF created
baseUrl
https://www.certification.openid.net/test/a/isv_op_oidc_core_test
variant
{
  "client_auth_type": "client_secret_basic",
  "response_type": "code id_token token",
  "server_metadata": "discovery",
  "response_mode": "default",
  "client_registration": "dynamic_client"
}
alias
isv_op_oidc_core_test
description
isv_op_oidc_core_test_dynamic_client
planId
rdCLwWmseshp4
config
{
  "server": {
    "discoveryUrl": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration",
    "login_hint": "isvdev@ibm.com"
  },
  "client": {
    "client_name": "Ristretto Core Conformance Test Dynamic Client One"
  },
  "client2": {
    "client_name": "Ristretto Core Conformance Test Dynamic Client Two"
  },
  "consent": {},
  "alias": "isv_op_oidc_core_test",
  "description": "isv_op_oidc_core_test_dynamic_client"
}
testName
oidcc-id-token-hint
2022-11-27 18:28:00 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-27 18:28:00
GetDynamicServerConfiguration
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:00 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKb15ca6ff-c4dd-4bcc-bc68-bf1509bbdf2f",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac3003dae837",
  "vary": "Accept-Encoding",
  "date": "Sun, 27 Nov 2022 18:28:00 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:BMF0PTyWBWeGCi4L9IGKCZB1BuscCZF8D7S+/Ws7wXY\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dCEE31A73022F721A3497DAFA6EF52066~-1~YAAQLdoHYJFhzraEAQAAPZ5YuginEvb236a2XVAfYR7lkKYKnhJ0AU8ELrWwKDRa/UlPJNhUe/mmYWWG7PHMsZT41iqNzJ7gZ6m2sHHAh+UPA2t7qUuiQR67n6Fs3SRz7uUMNdYO6Y6LoAjVRmGU+EshtNedICuDs5PWJBTSB6LghUHwGdIYlo9s/u+vMVNC0qiq569dGt5q3zTx//bUmmgn8t/tpaLTW4ddqtpfJdgYjor6GsrUNsfKvk2geKRwU9iF0tpvkwUHo0FMnGmC/Bkm1gTMlNCSYVSFQbMvpF6DpudbsKWMP1hbJi4so4TEPf7+yn1uVI2T8x46RxKT0KYGsa4impEu21EM07+RE8MGngC6t2lEGXlYg6796aFAi0F+rYo\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:00 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d689DD637B527A7FE9530EFC9897418B2~YAAQLdoHYJJhzraEAQAAPZ5YuhE3lWpoLhJP/JqcebV7frRfvbEMRCSiPkhsyPAtM1MFOOxrZzATk3IXf13iopNl5ZbcLOy4zVd7rL2pccEuIuGa7I/iiOuFZwgnNCFwXwtcxXRDWrD08xGYm8PrUKHdcuHZUfXs6nDn1IfJia6tR/Rc2n7ymcmXW198NATBnTa+boK9RQL1LIqnvXFDMiMx3/Y/wZE+aSmzQqYB0FEFXHRMasmM//zPZv1Lv3wvgUwEGw8OOOmTZcgzh1LSjUJVpaPHK0sKGT6q9NdnGfpSC8VIA1hUlLys/FCw~3223606~3486265; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:00 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d90",
    "origin; dur\u003d93"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"issuer":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","authorization_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize","token_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token","introspection_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect","userinfo_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo","revocation_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke","pushed_authorization_request_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par","registration_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register","jwks_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks","response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"response_modes_supported":["query","fragment","form_post","jwt","query.jwt","fragment.jwt","form_post.jwt"],"grant_types_supported":["authorization_code","implicit","password","refresh_token","client_credentials"],"token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"authorization_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"authorization_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"authorization_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"id_token_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"id_token_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"id_token_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"userinfo_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"userinfo_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"subject_types_supported":["public"],"scopes_supported":["openid","profile","email","phone","address"],"claims_supported":["email","name","mobile_number","department","upn","preferred_username","given_name","tenantId","employee_id","realmName","groupIds","family_name","job_title","uid","iss","acr"],"claim_types_supported":["normal"],"claims_parameter_supported":true,"request_parameter_supported":true,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"tls_client_certificate_bound_access_tokens":true,"mtls_endpoint_aliases":{"introspection_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect","pushed_authorization_request_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par","revocation_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke","token_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"},"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"]}
2022-11-27 18:28:00 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize
token_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
introspection_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect
userinfo_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
revocation_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke
pushed_authorization_request_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par
registration_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "query",
  "fragment",
  "form_post",
  "jwt",
  "query.jwt",
  "fragment.jwt",
  "form_post.jwt"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "refresh_token",
  "client_credentials"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
authorization_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
authorization_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
authorization_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
id_token_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
id_token_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
id_token_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
userinfo_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
userinfo_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
subject_types_supported
[
  "public"
]
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
claims_supported
[
  "email",
  "name",
  "mobile_number",
  "department",
  "upn",
  "preferred_username",
  "given_name",
  "tenantId",
  "employee_id",
  "realmName",
  "groupIds",
  "family_name",
  "job_title",
  "uid",
  "iss",
  "acr"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
request_parameter_supported
true
request_uri_parameter_supported
true
require_request_uri_registration
true
tls_client_certificate_bound_access_tokens
true
mtls_endpoint_aliases
{
  "introspection_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par",
  "revocation_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke",
  "token_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"
}
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
2022-11-27 18:28:00 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-11-27 18:28:00 SUCCESS
ExtractTLSTestValuesFromServerConfiguration
Extracted TLS information from authorization server configuration
registration_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
authorization_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
token_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
userinfo_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
2022-11-27 18:28:00
FetchServerKeys
Fetching server key
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
2022-11-27 18:28:00
FetchServerKeys
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:00 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKaa5168a8-0e5d-47ec-9d99-ff7b14522fbe",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac3007b30ba3",
  "vary": "Accept-Encoding",
  "date": "Sun, 27 Nov 2022 18:28:00 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:g3T8BW530yFxI/YQxCS/2m50Xk5wmG9mM3WkkIagf8s\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d63146F8E428D0A6A2F6221C6A25632E0~-1~YAAQLdoHYJVhzraEAQAAOZ9Yugg1p2jUfhXRcD56Gyo23D7HGKrRL87z4B7AoCRLz4TBVuoGCnMjQLG1m4NJttM7Dg+qf8lrNtBeg4VR+/LuKvzkDkQFT9+9/Gcpt2pzt8WU2bGc/cZyifsl9CPDElCuPq2+IZICxwA34t+bWkDpPjhQEPR/jKfifyX0zQlbs2hMUHJ+JuiESw+Ae68hOCvHKrOrdSd25+cgymL5BW9btnehJME/bbjrcdgSI4WFR19gUd7VvEw8q9ZcJ0V0Lr5UEVzyIlHEDrGNL1YxWyGUMvVDxmt9O/ksaJM3agKFyK2M19SmyftB7A4GEq0fQZRnpmubUZGVLEPziOuTRY6E+RcIqOWuTt8e0ueKJKm3oL905JE\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:00 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dD43EE21E728C36C06E81D2DEF3893FDC~YAAQLdoHYJZhzraEAQAAOZ9YuhEjF86diZBkGsKA4nIH84T+nc64DllEQk3DQbf7edohq/LNegayvf8LNHj3pKzJTk4VDDDiavUTL+bpXKqZWM6ZcEry/9Vd/5Q4NXm3rMQATuBGmwTzy/AGl1WsU+JmCoru5asVluEyOP9Mju9c/8jTPv9JTZqYOLQIyAaqpZ3lUc9Y+nGFqcUd42QOc1GTiU6u8YGbwvb4So2cU/TnlS446EulQNygcbcgciB+V7732cwJx0OPX6WVqjOp1lEvWhoNYu6MdqZt82w5uWNBn/dozqzyI7XmWMyE~3223606~3486265; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:00 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d94",
    "origin; dur\u003d93"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-27 18:28:00
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-27 18:28:00 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-27 18:28:00 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-27 18:28:00 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-11-27 18:28:00 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-11-27 18:28:00 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-11-27 18:28:00 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-11-27 18:28:00
StoreOriginalClientConfiguration
Created original_client_config object from the client configuration.
client_name
Ristretto Core Conformance Test Dynamic Client One
2022-11-27 18:28:00
ExtractClientNameFromStoredConfig
Extracted client_name from stored client configuration.
client_name
Ristretto Core Conformance Test Dynamic Client One
2022-11-27 18:28:01 SUCCESS
GenerateRS256ClientJWKs
Generated client JWKs
client_jwks
{
  "keys": [
    {
      "p": "77nnVnAyj7IvaMbdvq28HpriQa2jJZSHSjyS6vnbz8tFzMZ7k5LqZ3YYgKQgh7RIfypojXyrfN5d9JH6yLLDzWzUsSf0TlOL_W5NEWJpH8K11eHYoGwrabbaFwSCkZuorDAap55CmnXp3LZhVuhCssPdi6frh5mRsJ0JOKRhvFc",
      "kty": "RSA",
      "q": "3bBCa5jfgs5kA6l_FjXEZPtz7hjx-rEwsGe1Y7gimfa4brQAIxTGJXuX4eUizVcJnBg7GJ-HhInNMsEyljgmuLd6OPeDJUT9uzH5wIEaN3mtw3h9tXPNAIkWopETJa_pnaUbORfA-gY4QLjOgsrRStX-Vl0krCwxGe-X2xTN0Gc",
      "d": "vvM3FTO2liPueP23izSNrDNODVajeimTpdWOiHUp6LYxDQn0Simva28_-TgcJC9pYjeE1idyr8UoLFn-FCkBgZEPri46UM7qEZvud-w7NhFfKP2WquXv_KDNRuF1EPAmLCxjejiGzsyFPdZWg1ABaBxsW_EAo6Zq-YbYLN9ER63ZFQHUacNr2NHkvMUMYevHKRyGw3YSyFayKTrM0tlPbsUdgWUHO_qdT9-E9xNmojQ_UL750pYkib_taARgNLX15uPz1AmQshLPv3Y1UowFDwlwUBX7MqBgAV4CzvBvpLJVObZ5S2eQMVMvyKFf6riu9mo184bfdIEGAY0gKBsQaQ",
      "e": "AQAB",
      "use": "sig",
      "qi": "lEp4BInJeF_TEjkbolN-n-PzKv66PEHa5mQf3pi4sNlHsV-ELry19snx9QOihCTLweJ17zeiL6yn16L6j34LPeM8cvSUXpn-xoTEBhwskYvrTBdmD9bnuR58ZM1ZA-3JiRoAgRLbYOt-ziHZnYu-8T-Nr6NEkY-xxzs-yv8RMMQ",
      "dp": "dVkqbjyz83WFEaQvjhSbvtuQoBfwggfoBiYKwS2YNWrK-0e53G6Rgh3kNqyhI-zThDRtQ71gcNqlYYBIJBCmGpwIrcPiKqlpIKDq5vSmgx6cRlus4DKzOaeBsLzLcZ2h_s_5bE3jSpsn5Jv-oD1H0RxiCegkOpepIqxshCarlTc",
      "alg": "RS256",
      "dq": "EOcwmU2ltS6Rd6oD06iz2dNGaqAiSzAZe0ndDcZrdPvX4jD9Va9u0ErVMNcsySVayTkbwGvhhFyRdc4_Ui7j3O-4dQGCUWQqSIyt81ykqBgyBJZ6V0yGFAVf4XNYV2ZLVMbTBY5nG2k__sdYj6ZxQNiCNQmTE0GnWMfo9z5l1v8",
      "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "alg": "RS256",
      "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
    }
  ]
}
2022-11-27 18:28:01 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-11-27 18:28:01
CreateEmptyDynamicRegistrationRequest
Created empty dynamic registration request
2022-11-27 18:28:01
AddClientNameToDynamicRegistrationRequest
Added client_name to registration request
client_name
Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF
2022-11-27 18:28:01
AddAuthorizationCodeGrantTypeToDynamicRegistrationRequest
Added 'authorization_code' to 'grant_types'
grant_types
[
  "authorization_code"
]
2022-11-27 18:28:01
AddImplicitGrantTypeToDynamicRegistrationRequest
Added 'implicit' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit"
]
2022-11-27 18:28:01
AddPublicJwksToDynamicRegistrationRequest
Added client public JWKS to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
      }
    ]
  }
}
2022-11-27 18:28:01
AddTokenEndpointAuthMethodToDynamicRegistrationRequestFromEnvironment
Added token endpoint auth method to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic"
}
2022-11-27 18:28:01
AddResponseTypesArrayToDynamicRegistrationRequestFromEnvironment
Added response_types array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token token"
  ]
}
2022-11-27 18:28:01
AddRedirectUriToDynamicRegistrationRequest
Added redirect_uris array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ]
}
2022-11-27 18:28:01
AddContactsToDynamicRegistrationRequest
Added contacts array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ],
  "contacts": [
    "certification@oidf.org"
  ]
}
2022-11-27 18:28:01
CallDynamicRegistrationEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register
request_method
POST
request_headers
{
  "accept": "application/json",
  "accept-charset": "utf-8",
  "content-type": "application/json",
  "content-length": "775"
}
request_body
{"client_name":"Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF","grant_types":["authorization_code","implicit"],"jwks":{"keys":[{"kty":"RSA","e":"AQAB","use":"sig","alg":"RS256","n":"z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ"}]},"token_endpoint_auth_method":"client_secret_basic","response_types":["code id_token token"],"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"contacts":["certification@oidf.org"]}
2022-11-27 18:28:02 RESPONSE
CallDynamicRegistrationEndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK3f19c973-3ce5-408c-9b5b-cc172803d76b",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383ac31206883c5",
  "content-length": "1443",
  "date": "Sun, 27 Nov 2022 18:28:02 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:LXJ8Mhz6eUv1gBKK6YIJRbmK6SG+BMcfhTy1tSS8JQA\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d19AB2D792551A113CFD94B57DED090BC~-1~YAAQLdoHYLFhzraEAQAALaVYughU5/s2wOpGWgJ6wpTfKsRNGgeM/fRJAyc+cnO5Ti46HW216gTKt2WIA6F/UJR90j2fLlrieic0W/Z/X6RFoclDROCQ9nZ8WwrjFXN+1e0buSvyKF3iPoLXYwORHAYh8SD7dHlvQDuCGDMz87FwL7Co6M70IN5lf+NbsqPX10pLFwftzL+HdoAt5ORmaYi+HDE5QhNaUL96XRHsdvSMQlfP8pS3ACUbO2jjyOraNg6u3wsPc6CNOPq6xi2ycixtEQ2/wsHvAndU4KOzaXnP3lsfJW4KcGYOzRuWjLTsnwvKoLwo9qFL52bf0uqXGpNofKh70CZVMHooWkeCPRIc2h6xTX+IkPj9zk/NXuwvp2nu1V0\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:02 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dEE26C400871946F6ABDDC1289FCB18A5~YAAQLdoHYLJhzraEAQAALaVYuhG7hqe+udOJ4JiZrIFa2n+47FMjp9BXKEtUjGp9TiqVoABk87bZdH3YdoDhLOwANcRlMbkI3oCBnU8iUlhF14Od8rd28wHDC1mjGuysfaMrI3mMXNqQVZFFbo8oLwC2H7MldiN/w6vqIT25AGtImRTco9qA7fj4CuUpk3IQe4iTEl5lIWdoEzntGUcPZbIds8BHRde+7WOSamNh06j/7Tr1Y3ffYLIvjqmpdgOksTlzRlUAr2+9k5gHZmPpyEI0yldSq8aoS89rYTfd2MVS4mWjkHJ+0VpnvJQB~3160129~3163715; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:01 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d94",
    "origin; dur\u003d1182"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"all_users_entitled":true,"client_id":"b21d2344-1e3d-46ea-9940-ef45c8a7e73d","client_id_issued_at":"2022-11-27T18:28:01Z","client_name":"Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF","client_secret":"kYnkb4h7B7","client_secret_expires_at":0,"consent_action":"always_prompt","enforce_pkce":false,"grant_types":["authorization_code","implicit"],"id_token_map":[],"id_token_signed_response_alg":"RS256","initiate_login_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","jwks":{"keys":[{"use":"sig","kty":"RSA","alg":"RS256","n":"z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ","e":"AQAB"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"registration_access_token":"fnQln9fcyea9oFBqbG1mUPJ0V85Zr9p82B_yx_AFu5Y.rbleSLZZ2LI7tczrGk5FO2U_bDTCOnmu0o2fxmdiWwsb5aXhM4SoDAGaHWsm1PEcVZxDABUf14-GXWmMIYT9XQ.M18xNjY5NTczNjgyXzE4","registration_client_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b21d2344-1e3d-46ea-9940-ef45c8a7e73d","response_types":["code token id_token"],"token_endpoint_auth_method":"client_secret_basic","token_map":[]}
2022-11-27 18:28:02
CallDynamicRegistrationEndpoint
Parsed registration endpoint response
status
201
endpoint_name
dynamic registration
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK3f19c973-3ce5-408c-9b5b-cc172803d76b",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383ac31206883c5",
  "content-length": "1443",
  "date": "Sun, 27 Nov 2022 18:28:02 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:LXJ8Mhz6eUv1gBKK6YIJRbmK6SG+BMcfhTy1tSS8JQA\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d19AB2D792551A113CFD94B57DED090BC~-1~YAAQLdoHYLFhzraEAQAALaVYughU5/s2wOpGWgJ6wpTfKsRNGgeM/fRJAyc+cnO5Ti46HW216gTKt2WIA6F/UJR90j2fLlrieic0W/Z/X6RFoclDROCQ9nZ8WwrjFXN+1e0buSvyKF3iPoLXYwORHAYh8SD7dHlvQDuCGDMz87FwL7Co6M70IN5lf+NbsqPX10pLFwftzL+HdoAt5ORmaYi+HDE5QhNaUL96XRHsdvSMQlfP8pS3ACUbO2jjyOraNg6u3wsPc6CNOPq6xi2ycixtEQ2/wsHvAndU4KOzaXnP3lsfJW4KcGYOzRuWjLTsnwvKoLwo9qFL52bf0uqXGpNofKh70CZVMHooWkeCPRIc2h6xTX+IkPj9zk/NXuwvp2nu1V0\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:02 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dEE26C400871946F6ABDDC1289FCB18A5~YAAQLdoHYLJhzraEAQAALaVYuhG7hqe+udOJ4JiZrIFa2n+47FMjp9BXKEtUjGp9TiqVoABk87bZdH3YdoDhLOwANcRlMbkI3oCBnU8iUlhF14Od8rd28wHDC1mjGuysfaMrI3mMXNqQVZFFbo8oLwC2H7MldiN/w6vqIT25AGtImRTco9qA7fj4CuUpk3IQe4iTEl5lIWdoEzntGUcPZbIds8BHRde+7WOSamNh06j/7Tr1Y3ffYLIvjqmpdgOksTlzRlUAr2+9k5gHZmPpyEI0yldSq8aoS89rYTfd2MVS4mWjkHJ+0VpnvJQB~3160129~3163715; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:01 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d94",
    "origin; dur\u003d1182"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"all_users_entitled":true,"client_id":"b21d2344-1e3d-46ea-9940-ef45c8a7e73d","client_id_issued_at":"2022-11-27T18:28:01Z","client_name":"Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF","client_secret":"kYnkb4h7B7","client_secret_expires_at":0,"consent_action":"always_prompt","enforce_pkce":false,"grant_types":["authorization_code","implicit"],"id_token_map":[],"id_token_signed_response_alg":"RS256","initiate_login_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","jwks":{"keys":[{"use":"sig","kty":"RSA","alg":"RS256","n":"z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ","e":"AQAB"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"registration_access_token":"fnQln9fcyea9oFBqbG1mUPJ0V85Zr9p82B_yx_AFu5Y.rbleSLZZ2LI7tczrGk5FO2U_bDTCOnmu0o2fxmdiWwsb5aXhM4SoDAGaHWsm1PEcVZxDABUf14-GXWmMIYT9XQ.M18xNjY5NTczNjgyXzE4","registration_client_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b21d2344-1e3d-46ea-9940-ef45c8a7e73d","response_types":["code token id_token"],"token_endpoint_auth_method":"client_secret_basic","token_map":[]}
body_json
{
  "all_users_entitled": true,
  "client_id": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "client_id_issued_at": "2022-11-27T18:28:01Z",
  "client_name": "Ristretto Core Conformance Test Dynamic Client One 61w1ztweyful7WF",
  "client_secret": "kYnkb4h7B7",
  "client_secret_expires_at": 0,
  "consent_action": "always_prompt",
  "enforce_pkce": false,
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "id_token_map": [],
  "id_token_signed_response_alg": "RS256",
  "initiate_login_uri": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "jwks": {
    "keys": [
      {
        "use": "sig",
        "kty": "RSA",
        "alg": "RS256",
        "n": "z5iKt1nIcacPP-WSHbo0cQjVj6bsrk5rPD-4GnJ7-lOq6OKcJLeITG9hT6BI9a2483WE9FtTI4KjEB8HPK56kiYJ7x-JxIAXyKX-4NUHNCS_aujnqx6QJOYT4-X-MU0KPGYoRRXf-hpLuGYTSXy6lXU4OC5kvBL8RWp44IePTg_jQUEUElPlAzZEFL5F30gN7FtMk6sF60UkSN0JKq1jG5eqwuZ-0KtzlbekT8xSPV4fZG-PqQLrqc7COBUScpLZXSmdUSIuR5FzDsRsf192gTAVbl_crStg0ivoZUM40Or-SLySFBUKb8xWEVBqnVQ5mDuwrjAKK0sPzG_BKgR3AQ",
        "e": "AQAB"
      }
    ]
  },
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ],
  "registration_access_token": "fnQln9fcyea9oFBqbG1mUPJ0V85Zr9p82B_yx_AFu5Y.rbleSLZZ2LI7tczrGk5FO2U_bDTCOnmu0o2fxmdiWwsb5aXhM4SoDAGaHWsm1PEcVZxDABUf14-GXWmMIYT9XQ.M18xNjY5NTczNjgyXzE4",
  "registration_client_uri": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "response_types": [
    "code token id_token"
  ],
  "token_endpoint_auth_method": "client_secret_basic",
  "token_map": []
}
2022-11-27 18:28:02 SUCCESS
EnsureContentTypeJson
endpoint_response Content-Type: header is application/json
2022-11-27 18:28:02 SUCCESS
EnsureHttpStatusCodeIs201
dynamic registration endpoint returned the expected http status
expected_status
201
http_status
201
2022-11-27 18:28:02 SUCCESS
CheckNoErrorFromDynamicRegistrationEndpoint
Dynamic registration endpoint did not return an error.
2022-11-27 18:28:02 SUCCESS
ExtractDynamicRegistrationResponse
Extracted client from dynamic registration response
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
2022-11-27 18:28:02 SUCCESS
VerifyClientManagementCredentials
Verified dynamic registration management credentials
registration_client_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b21d2344-1e3d-46ea-9940-ef45c8a7e73d
registration_access_token
fnQln9fcyea9oFBqbG1mUPJ0V85Zr9p82B_yx_AFu5Y.rbleSLZZ2LI7tczrGk5FO2U_bDTCOnmu0o2fxmdiWwsb5aXhM4SoDAGaHWsm1PEcVZxDABUf14-GXWmMIYT9XQ.M18xNjY5NTczNjgyXzE4
2022-11-27 18:28:02
SetScopeInClientConfigurationToOpenId
Set scope in client configuration to "openid"
scope
openid
2022-11-27 18:28:02 SUCCESS
EnsureServerConfigurationSupportsClientSecretBasic
Contents of 'token_endpoint_auth_methods_supported' in discovery document matches expectations.
actual
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
expected
[
  "client_secret_basic"
]
minimum_matches_required
1
2022-11-27 18:28:02 SUCCESS
SetProtectedResourceUrlToUserInfoEndpoint
userinfo_endpoint will be used to test access token. The user info is not a mandatory to implement feature in the OpenID Connect specification, but is mandatory for certification.
protected_resource_url
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
2022-11-27 18:28:02
oidcc-id-token-hint
Setup Done
Make request to authorization endpoint
2022-11-27 18:28:02 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
2022-11-27 18:28:02
CreateRandomStateValue
Created state value
requested_state_length
10
state
0uo7hZ6Jqx
2022-11-27 18:28:02 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
0uo7hZ6Jqx
2022-11-27 18:28:02
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
VHZZ1bBLKV
2022-11-27 18:28:02 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
0uo7hZ6Jqx
nonce
VHZZ1bBLKV
2022-11-27 18:28:02 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
0uo7hZ6Jqx
nonce
VHZZ1bBLKV
response_type
code id_token token
2022-11-27 18:28:02 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "redirect_uri": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "scope": "openid",
  "state": "0uo7hZ6Jqx",
  "nonce": "VHZZ1bBLKV",
  "response_type": "code id_token token"
}
redirect_to_authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b21d2344-1e3d-46ea-9940-ef45c8a7e73d&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=0uo7hZ6Jqx&nonce=VHZZ1bBLKV&response_type=code%20id_token%20token
2022-11-27 18:28:02 REDIRECT
oidcc-id-token-hint
Redirecting to authorization endpoint
redirect_to
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b21d2344-1e3d-46ea-9940-ef45c8a7e73d&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=0uo7hZ6Jqx&nonce=VHZZ1bBLKV&response_type=code%20id_token%20token
2022-11-27 18:28:14 INCOMING
oidcc-id-token-hint
Incoming HTTP request to /test/a/isv_op_oidc_core_test/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close"
}
incoming_path
/test/a/isv_op_oidc_core_test/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 18:28:14 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/9EfSE3FsC7q9qYgRRESn",
  "fullUrl": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/9EfSE3FsC7q9qYgRRESn"
}
2022-11-27 18:28:14 OUTGOING
oidcc-id-token-hint
Response to HTTP request to test instance 61w1ztweyful7WF
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/9EfSE3FsC7q9qYgRRESn, returnUrl=/log-detail.html?log=61w1ztweyful7WF}]
outgoing_path
callback
2022-11-27 18:28:27 INCOMING
oidcc-id-token-hint
Incoming HTTP request to /test/a/isv_op_oidc_core_test/implicit/9EfSE3FsC7q9qYgRRESn
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close",
  "content-length": "1537"
}
incoming_path
/test/a/isv_op_oidc_core_test/implicit/9EfSE3FsC7q9qYgRRESn
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#access_token=XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4&code=SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA&expires_in=7200&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw&iss=https%3A%2F%2Foidc-conformance.rel.verify.ibmcloudsecurity.com%2Foauth2&scope=openid&state=0uo7hZ6Jqx&token_type=bearer
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 18:28:27 OUTGOING
oidcc-id-token-hint
Response to HTTP request to test instance 61w1ztweyful7WF
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/9EfSE3FsC7q9qYgRRESn
2022-11-27 18:28:27
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "access_token",
    "value": "XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4"
  },
  {
    "name": "code",
    "value": "SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA"
  },
  {
    "name": "expires_in",
    "value": "7200"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw"
  },
  {
    "name": "iss",
    "value": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2"
  },
  {
    "name": "scope",
    "value": "openid"
  },
  {
    "name": "state",
    "value": "0uo7hZ6Jqx"
  },
  {
    "name": "token_type",
    "value": "bearer"
  }
]
2022-11-27 18:28:27 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
access_token
XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4
code
SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA
expires_in
7200
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw
iss
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
scope
openid
state
0uo7hZ6Jqx
token_type
bearer
2022-11-27 18:28:27 REDIRECT-IN
oidcc-id-token-hint
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "access_token": "XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4",
  "code": "SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA",
  "expires_in": "7200",
  "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw",
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "scope": "openid",
  "state": "0uo7hZ6Jqx",
  "token_type": "bearer"
}
post_body
Verify authorization endpoint response
2022-11-27 18:28:27 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-11-27 18:28:27 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-11-27 18:28:27 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-11-27 18:28:27 SUCCESS
ValidateIssInAuthorizationResponse
'iss' parameter in authorization response matches server's issuer value.
2022-11-27 18:28:27 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-11-27 18:28:27 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
0uo7hZ6Jqx
2022-11-27 18:28:27 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA
2022-11-27 18:28:27 SUCCESS
ExtractAccessTokenFromAuthorizationResponse
Extracted the access token
value
XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4
type
bearer
2022-11-27 18:28:27 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "at_hash": "QNfasFPO2SDjmm2UzhGm8A",
  "sub": "6160017N67",
  "rat": 1669573691,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "VHZZ1bBLKV",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "c_hash": "EjNiLtGSS3xdcc4uNmX1mA",
  "s_hash": "AuU_vvkmMoHD2IRnuHdxYQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580893,
  "iat": 1669573693,
  "jti": "dc47c122-d160-4924-8fc2-459fc5919ef7"
}
2022-11-27 18:28:27 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 18:28:27
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 18:28:27
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 18:28:27
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 18:28:27
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 18:28:27
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 18:28:27 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 18:28:27 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
VHZZ1bBLKV
2022-11-27 18:28:27 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 18:28:27 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw
2022-11-27 18:28:27 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJRTmZhc0ZQTzJTRGptbTJVemhHbThBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6IkVqTmlMdEdTUzN4ZGNjNHVObVgxbUEiLCJleHAiOjE2Njk1ODA4OTMsImlhdCI6MTY2OTU3MzY5MywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiZGM0N2MxMjItZDE2MC00OTI0LThmYzItNDU5ZmM1OTE5ZWY3IiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IlZIWloxYkJMS1YiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzY5MSwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiQXVVX3Z2a21Nb0hEMklSbnVIZHhZUSIsInN1YiI6IjYxNjAwMTdONjcifQ.achIcfs-TvMLjuMHzcP6ew7dteHdKWVxCQY8K3EjsYv9-QQjLmo0Wuo_1ep6aRrGFN_Aj9wMWpUPWVigV94wdoEaTN3ZbvX6z-cwKDCX3VSZbxDI6v2K_bgNM9LmVc9TqLq7_1QBRKWdjKMXuHoiiE0S1dgM1i4Z3CiHmQzsZtUiziPebS5aZujowqtzOXJsvaTFjk7Oe7UJc4MSY_Q5qEG3QNU4DXLxrliQd7_-Os50LuOY_h0NkbJHUzFXDNq9QcgYtuPNdiNur0cFiV7usiVwxnr9s4hV63yTVYxE9E-WXYVRINT4lGkcd7SG7DBecpZfjPFQa4autEu14h26Qw
2022-11-27 18:28:27 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 18:28:27
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 18:28:27 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
Userinfo endpoint tests
2022-11-27 18:28:27
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer XgfxLfawcaAtvOcC7bqVvqv53F4iu4oT4YDFnUqlhZw.cxG74YXWWPFfIP72Wo3rJQBebNTCbIb1kplGYTN8eraZvxFkSAsmIE2qaLXO2NZlyd8L4PrGvhwxe66TUY-_1Q.M18xNjY5NTczNjkzXzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:27 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK8ff2c226-3fe0-4e5a-89f6-35aa41c34d62",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac4b20688df5",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:27 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:XAu6ZnvbxtfnbijozpR2BIHzoOivfGp5od59zMdAb1k\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d4314916F5AD77F1E467A6375CB43B0DD~-1~YAAQLdoHYLdkzraEAQAAAwhZugjo8VbfJo/O9rnJycw1RrUAWHMglAEaE8vTB0UXKIg6b5LqOn+aAU30+xWV//uY7VqngfxRoqovukkDx/S3TEXVtI4GycjFPW8kD2QlVtumtdtXtSuiKUPqPs4gnQQWclYdTOK7Qn78BoYpt8p+48moX2o/PBzhbbKVb5VxpATjc42IGZktPSvegvoiEelNCwV9xU3nbaZQSvyioNJHdZDO++/R6ZrCnvkPdJ4R4XbLQ9uWmJOBmYK0cEPTF7obIeE1jlN4s788kMvECdvOq35L6fCKlXN1TlpAhNlKVsDqLoAgLc/faqvqCHti2Y5FsiIysOuDr7CUH26Kehtf6n0gT/tsZ8ND+cBCNA3uY/PBF/4\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:27 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d658E2F25125F1B378C597848F37D1C3C~YAAQLdoHYLhkzraEAQAAAwhZuhGouZvVjLEGB88vwrsN/BAe3g3eYY79373q6tMyTTzWB9sv7GWbc3qTgCCC5QeWMPQvirSxAOxouMwihgP9e+fYqBp/NWP7R866+apfoWuDocYsuwLZ2q9A3TZ7A2eUZRcZbx7ZchpGg5nhbtiqwkKYC7MLWRUF7s+r4Yuin5ceCZ/cz7Y1Fv/SbfvkUwWt17rWB9XIPFpvXMlsKu+MV71OcPES7jb8qjQvNLLAv8k3uE+VIfVs5x2+c71RySlYokumtP2j7JNuDzWPZKnNYIo/jb3bYsw3KcxP~4600118~4342840; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:27 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d109"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573691,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:27 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK8ff2c226-3fe0-4e5a-89f6-35aa41c34d62",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac4b20688df5",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:27 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:XAu6ZnvbxtfnbijozpR2BIHzoOivfGp5od59zMdAb1k\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d4314916F5AD77F1E467A6375CB43B0DD~-1~YAAQLdoHYLdkzraEAQAAAwhZugjo8VbfJo/O9rnJycw1RrUAWHMglAEaE8vTB0UXKIg6b5LqOn+aAU30+xWV//uY7VqngfxRoqovukkDx/S3TEXVtI4GycjFPW8kD2QlVtumtdtXtSuiKUPqPs4gnQQWclYdTOK7Qn78BoYpt8p+48moX2o/PBzhbbKVb5VxpATjc42IGZktPSvegvoiEelNCwV9xU3nbaZQSvyioNJHdZDO++/R6ZrCnvkPdJ4R4XbLQ9uWmJOBmYK0cEPTF7obIeE1jlN4s788kMvECdvOq35L6fCKlXN1TlpAhNlKVsDqLoAgLc/faqvqCHti2Y5FsiIysOuDr7CUH26Kehtf6n0gT/tsZ8ND+cBCNA3uY/PBF/4\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:27 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d658E2F25125F1B378C597848F37D1C3C~YAAQLdoHYLhkzraEAQAAAwhZuhGouZvVjLEGB88vwrsN/BAe3g3eYY79373q6tMyTTzWB9sv7GWbc3qTgCCC5QeWMPQvirSxAOxouMwihgP9e+fYqBp/NWP7R866+apfoWuDocYsuwLZ2q9A3TZ7A2eUZRcZbx7ZchpGg5nhbtiqwkKYC7MLWRUF7s+r4Yuin5ceCZ/cz7Y1Fv/SbfvkUwWt17rWB9XIPFpvXMlsKu+MV71OcPES7jb8qjQvNLLAv8k3uE+VIfVs5x2+c71RySlYokumtP2j7JNuDzWPZKnNYIo/jb3bYsw3KcxP~4600118~4342840; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:27 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d109"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573691,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:27 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-27 18:28:27 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-27 18:28:27 SUCCESS
AddBasicAuthClientSecretAuthenticationParameters
Added basic authorization header
Authorization
Basic YjIxZDIzNDQtMWUzZC00NmVhLTk5NDAtZWY0NWM4YTdlNzNkOmtZbmtiNGg3Qjc=
2022-11-27 18:28:27
CallTokenEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "authorization": "Basic YjIxZDIzNDQtMWUzZC00NmVhLTk5NDAtZWY0NWM4YTdlNzNkOmtZbmtiNGg3Qjc\u003d",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "267"
}
request_body
grant_type=authorization_code&code=SpYH4sT0-gQU8UBrPbqI6C0OzoW7vFXF4L1wCYdu67s.dq9rphoDCi6z0C2br1lg3x2oWIC_nlOCSlAIi4QRkBH-vLyvw42-gXdR5fcem1xaWvwNt-Hcv8oats_u5yjEIA&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fisv_op_oidc_core_test%2Fcallback
2022-11-27 18:28:28 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK11843a36-329f-42e7-bcd3-651822d7c6c4",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383ac4b354d5091",
  "content-length": "1281",
  "date": "Sun, 27 Nov 2022 18:28:28 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:v/4luMBLf/WMhdPAyRqFj44Ke/PIxuyWrsSUJio/HOU\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d6821ABEC274060A4D408A6DEBD504751~-1~YAAQLdoHYMVkzraEAQAAUQlZughyqoIiMig9UvT3gHxMhS8Whn2JvqsvCQ0RdrHq0d3dMDYroX4LvWn8Ro+e/TchRPpJIAN9JZA5ey3gfBhlZWwIk4SigEeQw/WWWzIt+nWnnNTDN40Fa4m7ljZCj5DIGef6A8N5cBo0QQGUTzDeOHCCfu5QDMOZvJseJiSIN1CIRzzwKUnWp1vQlNYtwtmpVwlzJzU1+d169mpH1p4KKrLFkD9dnELo5z2Yf9B3NG8F0t6JCtbvEEUvsW/wliNjBoyrkwbAyy2cRXaKhwyoiu9fRsP6ZBkwEXQwv77QXDxCfyC2GnXOGlZFCnGvYHiJ0CFaDwkTgFmhum2T5zcn4QHGnx/J4hLjsF4FN7nNJQV2WGE\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:28 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d50FA5B95227A0BADE65172D2EBD436A8~YAAQLdoHYMZkzraEAQAAUQlZuhGiUUu0jXQx2Qcxcyf4CA711Xw78yrHqW/DbFSBfk30ii/U//JoHBkzkNkpDPhIcJ9owYKdmjJnfMSMwT9XmmPOtNOMKMCfbYaQrgAFuU4oo4uY+FkBdW6lZZu/gl/Yeg7DrG/ni/emh420A60ppqlIWBDeaJUbqOFQk60KO6L1tUIBYsGC7c0WlqxDb5Nkfj4LFRKSvM/EaNQDQFrZFnDIdHoCVbD3eEiR5/u5EYdad5T4B9WbhagQ4pT+bOHitJ2/FPwGzCe2VJn/fd0cIUOkxGMYbCcHgUqH~4600118~4342840; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:27 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d95",
    "origin; dur\u003d170"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"access_token":"BER_ZWrLq2mN8QRFucUVRCkeAOxWPlclJeRJ4LoQjEI.1YxyJ_PfDvSimwaXBZFSIBCDyCHVIzumRumF3tFQsAmmUXHw8eDFiGKpE2tj6h4qK0IYAjXPAx1amZVSsrNGLA.M18xNjY5NTczNzA3XzE4","expires_in":7199,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg","scope":"openid","token_type":"bearer"}
2022-11-27 18:28:28 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
BER_ZWrLq2mN8QRFucUVRCkeAOxWPlclJeRJ4LoQjEI.1YxyJ_PfDvSimwaXBZFSIBCDyCHVIzumRumF3tFQsAmmUXHw8eDFiGKpE2tj6h4qK0IYAjXPAx1amZVSsrNGLA.M18xNjY5NTczNzA3XzE4
expires_in
7199
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
scope
openid
token_type
bearer
2022-11-27 18:28:28 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-11-27 18:28:28 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
BER_ZWrLq2mN8QRFucUVRCkeAOxWPlclJeRJ4LoQjEI.1YxyJ_PfDvSimwaXBZFSIBCDyCHVIzumRumF3tFQsAmmUXHw8eDFiGKpE2tj6h4qK0IYAjXPAx1amZVSsrNGLA.M18xNjY5NTczNzA3XzE4
2022-11-27 18:28:28 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
BER_ZWrLq2mN8QRFucUVRCkeAOxWPlclJeRJ4LoQjEI.1YxyJ_PfDvSimwaXBZFSIBCDyCHVIzumRumF3tFQsAmmUXHw8eDFiGKpE2tj6h4qK0IYAjXPAx1amZVSsrNGLA.M18xNjY5NTczNzA3XzE4
type
bearer
2022-11-27 18:28:28 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7199
2022-11-27 18:28:28 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7199
2022-11-27 18:28:28 INFO
CheckForRefreshTokenValue
Couldn't find refresh token
2022-11-27 18:28:28 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "at_hash": "V9y4Ild6LagEt0om7eXo0A",
  "sub": "6160017N67",
  "rat": 1669573691,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "VHZZ1bBLKV",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "AuU_vvkmMoHD2IRnuHdxYQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580908,
  "iat": 1669573708,
  "jti": "2c7137fb-2a89-46ac-a8c0-77bf906ab102"
}
2022-11-27 18:28:28 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 18:28:28
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 18:28:28
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 18:28:28
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 18:28:28
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 18:28:28
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 18:28:28 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 18:28:28 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
VHZZ1bBLKV
2022-11-27 18:28:28 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 18:28:28 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
2022-11-27 18:28:28 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
2022-11-27 18:28:28 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 18:28:28
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 18:28:28 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-11-27 18:28:28 SUCCESS
VerifyIdTokenSubConsistentHybridFlow
authorization endpoint and token endpoint id_token have same sub
sub_auth_endpoint
6160017N67
sub_token_endpoint
6160017N67
Userinfo endpoint tests
2022-11-27 18:28:28
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer BER_ZWrLq2mN8QRFucUVRCkeAOxWPlclJeRJ4LoQjEI.1YxyJ_PfDvSimwaXBZFSIBCDyCHVIzumRumF3tFQsAmmUXHw8eDFiGKpE2tj6h4qK0IYAjXPAx1amZVSsrNGLA.M18xNjY5NTczNzA3XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:28 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK4b74eda6-f444-4803-80a1-fc10706ac8f0",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac4c10e61af9",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:28 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:ZOSRHC8ohDdBo4i8O7z97tCOdisT1kLuXSe2Auus9Ko\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d714699D5A2149B7AE6E623F2E70422EA~-1~YAAQLdoHYN5kzraEAQAAWwtZughWDbP1RKOa82QafU/8FL7OwAiryUp6B32OTGk/E7DYlmLWoamifz8+6xGEynCF+nQuzNcaTC1kdJuqiDOMgXfMzyGeF7/fGPJaf0PaE1tFzdCVQRfUbrkMDclherBID9wVNLNY0cgme/dAwWPt7uJZbFRAsxZy6d8A1nL3Sl4JujpUGCYQEfB8XDUkoEWwfhwCoHlJtbdnvsNxDbXOAMCoyv+z9KeKNik+ojMIEkuFqBWhTdBC80tjOrEKvztra/qnK5vulhKLFU9h7bFjVOZeEbcDJ1MheXqohoc12yrCJVPCrG92Inb84jt0DdTnd86H6r8x8FbyZGeGVXdAfNwSNoR2CvEZng4J8eZeCZe6FEk\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:28 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF5FFB8EC3432BB2A68AE10942C981F89~YAAQLdoHYN9kzraEAQAAWwtZuhFzRsybGN2MAKQ/bOz56mDvKeDZ0hZUkzMMukTtuEoJlKZenQKB6Xl6bQjmfflBPtTLyIS4p1gN327MqGikrHYEbUUUrKFWvx2I+faFi4E61ohjZwbWYyAVUIfY+HvlFeSeC+Lk+m3L3d47V2p0/AlppY+OtIxp+xgSGzxGf1lhnigHFd0dnx72iUlbElpQQyMV99RxWVdkaeqDv7TNg/L3o61hlzZ59hrJ7OsgajhqMkvUJBghZKrO61d99nxR2WYWuvLGfmqHfNchyH/LsL5dySHshRuM7TGy~3354674~3490114; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:28 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d90",
    "origin; dur\u003d338"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573691,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:28 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK4b74eda6-f444-4803-80a1-fc10706ac8f0",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac4c10e61af9",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:28 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:ZOSRHC8ohDdBo4i8O7z97tCOdisT1kLuXSe2Auus9Ko\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d714699D5A2149B7AE6E623F2E70422EA~-1~YAAQLdoHYN5kzraEAQAAWwtZughWDbP1RKOa82QafU/8FL7OwAiryUp6B32OTGk/E7DYlmLWoamifz8+6xGEynCF+nQuzNcaTC1kdJuqiDOMgXfMzyGeF7/fGPJaf0PaE1tFzdCVQRfUbrkMDclherBID9wVNLNY0cgme/dAwWPt7uJZbFRAsxZy6d8A1nL3Sl4JujpUGCYQEfB8XDUkoEWwfhwCoHlJtbdnvsNxDbXOAMCoyv+z9KeKNik+ojMIEkuFqBWhTdBC80tjOrEKvztra/qnK5vulhKLFU9h7bFjVOZeEbcDJ1MheXqohoc12yrCJVPCrG92Inb84jt0DdTnd86H6r8x8FbyZGeGVXdAfNwSNoR2CvEZng4J8eZeCZe6FEk\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:28 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF5FFB8EC3432BB2A68AE10942C981F89~YAAQLdoHYN9kzraEAQAAWwtZuhFzRsybGN2MAKQ/bOz56mDvKeDZ0hZUkzMMukTtuEoJlKZenQKB6Xl6bQjmfflBPtTLyIS4p1gN327MqGikrHYEbUUUrKFWvx2I+faFi4E61ohjZwbWYyAVUIfY+HvlFeSeC+Lk+m3L3d47V2p0/AlppY+OtIxp+xgSGzxGf1lhnigHFd0dnx72iUlbElpQQyMV99RxWVdkaeqDv7TNg/L3o61hlzZ59hrJ7OsgajhqMkvUJBghZKrO61d99nxR2WYWuvLGfmqHfNchyH/LsL5dySHshRuM7TGy~3354674~3490114; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:28 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d90",
    "origin; dur\u003d338"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573691,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:28 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
Second authorization: Make request to authorization endpoint
2022-11-27 18:28:28 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
2022-11-27 18:28:28
CreateRandomStateValue
Created state value
requested_state_length
10
state
HT0CMYStNq
2022-11-27 18:28:28 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
HT0CMYStNq
2022-11-27 18:28:28
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
8EWkApN8gD
2022-11-27 18:28:28 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
HT0CMYStNq
nonce
8EWkApN8gD
2022-11-27 18:28:28 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
HT0CMYStNq
nonce
8EWkApN8gD
response_type
code id_token token
2022-11-27 18:28:28 SUCCESS
AddPromptNoneToAuthorizationEndpointRequest
Added prompt=none to authorization endpoint request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
HT0CMYStNq
nonce
8EWkApN8gD
response_type
code id_token token
prompt
none
2022-11-27 18:28:28 SUCCESS
AddIdTokenHintFromFirstLoginToAuthorizationEndpointRequest
Added id_token_hint to authorization endpoint request
client_id
b21d2344-1e3d-46ea-9940-ef45c8a7e73d
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
HT0CMYStNq
nonce
8EWkApN8gD
response_type
code id_token token
prompt
none
id_token_hint
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
2022-11-27 18:28:28 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "redirect_uri": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "scope": "openid",
  "state": "HT0CMYStNq",
  "nonce": "8EWkApN8gD",
  "response_type": "code id_token token",
  "prompt": "none",
  "id_token_hint": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg"
}
redirect_to_authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b21d2344-1e3d-46ea-9940-ef45c8a7e73d&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=HT0CMYStNq&nonce=8EWkApN8gD&response_type=code%20id_token%20token&prompt=none&id_token_hint=eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
2022-11-27 18:28:28 REDIRECT
oidcc-id-token-hint
Redirecting to authorization endpoint
redirect_to
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b21d2344-1e3d-46ea-9940-ef45c8a7e73d&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=HT0CMYStNq&nonce=8EWkApN8gD&response_type=code%20id_token%20token&prompt=none&id_token_hint=eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJWOXk0SWxkNkxhZ0V0MG9tN2VYbzBBIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkwOCwiaWF0IjoxNjY5NTczNzA4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyYzcxMzdmYi0yYTg5LTQ2YWMtYThjMC03N2JmOTA2YWIxMDIiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiVkhaWjFiQkxLViIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNjkxLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJBdVVfdnZrbU1vSEQySVJudUhkeFlRIiwic3ViIjoiNjE2MDAxN042NyJ9.UpNQrCXCDbS0xA-4Cz4cIaio-bxooxIb0h2J1Bg66dapnhMfxEBMGbfIph6Ceet5cHQ2pkG3civbLXuViRuNzlm4jUTZOMhAv-tC6vHWrpYLozxdwzv2Pc4NcOjMjRmbrEPJz1_-HWqujJSx2SBpRR-mSCzWpLQdsEmEqoBBEeSfhyHcJb6Ac6rfWuTGIvyuqx2xMalbWfgpnyfEY46nK033Kmz93W0U_cEarsno4X26i6opTdnCa6f7V6LN3tzYu6Zgtxd7tPpC_StXYoyElYLMk_7MAFsYIITw1QEyToukPXNQsiqA2QZYtpUeFEpwgAplVHV8nWYrIjTvOrRSzg
2022-11-27 18:28:33 INCOMING
oidcc-id-token-hint
Incoming HTTP request to /test/a/isv_op_oidc_core_test/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close"
}
incoming_path
/test/a/isv_op_oidc_core_test/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 18:28:33 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/UHH3aNIKk9lPzi0d8IjL",
  "fullUrl": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/UHH3aNIKk9lPzi0d8IjL"
}
2022-11-27 18:28:33 OUTGOING
oidcc-id-token-hint
Response to HTTP request to test instance 61w1ztweyful7WF
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/UHH3aNIKk9lPzi0d8IjL, returnUrl=/log-detail.html?log=61w1ztweyful7WF}]
outgoing_path
callback
2022-11-27 18:28:34 INCOMING
oidcc-id-token-hint
Incoming HTTP request to /test/a/isv_op_oidc_core_test/implicit/UHH3aNIKk9lPzi0d8IjL
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close",
  "content-length": "1537"
}
incoming_path
/test/a/isv_op_oidc_core_test/implicit/UHH3aNIKk9lPzi0d8IjL
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#access_token=NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4&code=CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ&expires_in=7199&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA&iss=https%3A%2F%2Foidc-conformance.rel.verify.ibmcloudsecurity.com%2Foauth2&scope=openid&state=HT0CMYStNq&token_type=bearer
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 18:28:34 OUTGOING
oidcc-id-token-hint
Response to HTTP request to test instance 61w1ztweyful7WF
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/UHH3aNIKk9lPzi0d8IjL
2022-11-27 18:28:34
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "access_token",
    "value": "NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4"
  },
  {
    "name": "code",
    "value": "CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ"
  },
  {
    "name": "expires_in",
    "value": "7199"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA"
  },
  {
    "name": "iss",
    "value": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2"
  },
  {
    "name": "scope",
    "value": "openid"
  },
  {
    "name": "state",
    "value": "HT0CMYStNq"
  },
  {
    "name": "token_type",
    "value": "bearer"
  }
]
2022-11-27 18:28:34 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
access_token
NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4
code
CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ
expires_in
7199
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA
iss
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
scope
openid
state
HT0CMYStNq
token_type
bearer
2022-11-27 18:28:34 REDIRECT-IN
oidcc-id-token-hint
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "access_token": "NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4",
  "code": "CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ",
  "expires_in": "7199",
  "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA",
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "scope": "openid",
  "state": "HT0CMYStNq",
  "token_type": "bearer"
}
post_body
Second authorization: Verify authorization endpoint response
2022-11-27 18:28:34 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-11-27 18:28:34 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-11-27 18:28:34 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-11-27 18:28:34 SUCCESS
ValidateIssInAuthorizationResponse
'iss' parameter in authorization response matches server's issuer value.
2022-11-27 18:28:34 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-11-27 18:28:34 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
HT0CMYStNq
2022-11-27 18:28:34 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ
2022-11-27 18:28:34 SUCCESS
ExtractAccessTokenFromAuthorizationResponse
Extracted the access token
value
NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4
type
bearer
2022-11-27 18:28:34 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "at_hash": "rHTMEK4eZVJKNgLJTYHSog",
  "sub": "6160017N67",
  "rat": 1669573712,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "8EWkApN8gD",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "c_hash": "-AIM_dmrCwmkpJnels2l8g",
  "s_hash": "QK4QVpnew9PMwRh-ohw5qQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580913,
  "iat": 1669573713,
  "jti": "a33cff45-6adc-4a1f-9370-5d8e0f3b33cd"
}
2022-11-27 18:28:34 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
8EWkApN8gD
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJySFRNRUs0ZVpWSktOZ0xKVFlIU29nIiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImNfaGFzaCI6Ii1BSU1fZG1yQ3dta3BKbmVsczJsOGciLCJleHAiOjE2Njk1ODA5MTMsImlhdCI6MTY2OTU3MzcxMywiaXNzIjoiaHR0cHM6Ly9vaWRjLWNvbmZvcm1hbmNlLnJlbC52ZXJpZnkuaWJtY2xvdWRzZWN1cml0eS5jb20vb2F1dGgyIiwianRpIjoiYTMzY2ZmNDUtNmFkYy00YTFmLTkzNzAtNWQ4ZTBmM2IzM2NkIiwibmFtZSI6IklTViBEZXYiLCJub25jZSI6IjhFV2tBcE44Z0QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpc3ZkZXZAaWJtLmNvbSIsInJhdCI6MTY2OTU3MzcxMiwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwic19oYXNoIjoiUUs0UVZwbmV3OVBNd1JoLW9odzVxUSIsInN1YiI6IjYxNjAwMTdONjcifQ.MGHum8HfIbqpvgBjuTjqV9F7t6Btx99dxVIQK-1pys2Bv1t8YpVYzGb26bRTLim85znFfip-c9qUvaoP7aPTnAxXBSbNvuw1tn7YNwPkWWNvNhvS-xiLaQph2x89gmDTKtPASOSuDTY8zHO6q2K3H7yIUsczbpH9dj3RArrGF0UB_t9n7b9zoJ_I3yLHSILg5Ligi2i7G4PM8z8vFXuLSDAY93wR3qw5snEmie6wow4nKQxQJ6PfVeLZ14n9FduOSTXRBRbdwO-zeOx0HaBh2y5ghPixsFuNBvAeIAAcjCcRg2zrlb6BiIJ78Ia42tEpEcBZv7j4VJQw-Fw5b1l_tA
2022-11-27 18:28:34 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 18:28:34
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 18:28:34 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
Second authorization: Userinfo endpoint tests
2022-11-27 18:28:34
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer NiCpHH5qb9ozfm-DGUf9Bmeq9wWrxzqr2dKwN19ZpkE.zA0pmyq4g-8Z0BlfN_wt6kmuwrY-lk2f-sImBmUysFAnZ_oxmI2HLMcX29FTolJzfcVeXfmneXkbEbxgKvmXBw.M18xNjY5NTczNzEzXzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:34 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK0d1eeab6-d22e-4fe3-9422-81823d3a2564",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac52354d6191",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:34 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:gyDde8vu0kjbu3+LnfMXEF9ZAaJEgSefPDbvHx4NrnU\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dA57A4510519018286E6767F837E209DD~-1~YAAQLdoHYBNmzraEAQAAZSJZugjFOkJxGRW9G8+4YnOkVn9p3qgFUesDBySSRvJnb9BkuvZnQ0M7GobXQ7RwazePvyrH0eINJRMlCdplqIbgTJVaVXoSrcGMGz/fXfEFxbhPwo+S4Swp6vJDorBOECL3ah6xQMCg5dGlmNIVoa20TGFc+8DJvPZapp8zVfNkub4h196ou3tFHW55x10J/H1GjnJoVsDlj1VicAomC+z8teowuOLbvuDzEKhe57PRYbmv1esFLjOgFzBFLhLm1L701tlqWkSjCEKOAvenojtq7V2dWI1YfwCV/yrVSS40G1IUcGmEZzisFuAGgXqqjledEp/tmhL62mdAmzQoS5Zw+ENPQezq5fCQDetw0gL370dyaOg\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:34 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF648C554DE82D56972B80C1A34CDA793~YAAQLdoHYBRmzraEAQAAZSJZuhEfa+juVkHg5kPN3ciA8oJlqKnlOmeTpCESHZFax7bGQuqCkE3jSu02mUa0qO7b+NZRRuaOVuHtFjBrrEgTHxCDjHbCpWJne7fjk7kl5KRji8gixZfygLQwrK/UmNtMzUegwtPKGz83Dtz7uA5rrIuCVOBzgUTYkQni8uiINcs3zdZBbfy8ti6JUXo1FjvP6T8DbkWL2wWZMhnctxU1+1zkmR6w9VCaZ2M3SrIxo3HlhUOOfjvVyxMckbScwUp92/NmOfPWmZtVwRROPggodxO/PiFmTr6xm3MA~3223865~4405561; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:34 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d98"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573712,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:34 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK0d1eeab6-d22e-4fe3-9422-81823d3a2564",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac52354d6191",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:34 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:gyDde8vu0kjbu3+LnfMXEF9ZAaJEgSefPDbvHx4NrnU\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dA57A4510519018286E6767F837E209DD~-1~YAAQLdoHYBNmzraEAQAAZSJZugjFOkJxGRW9G8+4YnOkVn9p3qgFUesDBySSRvJnb9BkuvZnQ0M7GobXQ7RwazePvyrH0eINJRMlCdplqIbgTJVaVXoSrcGMGz/fXfEFxbhPwo+S4Swp6vJDorBOECL3ah6xQMCg5dGlmNIVoa20TGFc+8DJvPZapp8zVfNkub4h196ou3tFHW55x10J/H1GjnJoVsDlj1VicAomC+z8teowuOLbvuDzEKhe57PRYbmv1esFLjOgFzBFLhLm1L701tlqWkSjCEKOAvenojtq7V2dWI1YfwCV/yrVSS40G1IUcGmEZzisFuAGgXqqjledEp/tmhL62mdAmzQoS5Zw+ENPQezq5fCQDetw0gL370dyaOg\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:34 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF648C554DE82D56972B80C1A34CDA793~YAAQLdoHYBRmzraEAQAAZSJZuhEfa+juVkHg5kPN3ciA8oJlqKnlOmeTpCESHZFax7bGQuqCkE3jSu02mUa0qO7b+NZRRuaOVuHtFjBrrEgTHxCDjHbCpWJne7fjk7kl5KRji8gixZfygLQwrK/UmNtMzUegwtPKGz83Dtz7uA5rrIuCVOBzgUTYkQni8uiINcs3zdZBbfy8ti6JUXo1FjvP6T8DbkWL2wWZMhnctxU1+1zkmR6w9VCaZ2M3SrIxo3HlhUOOfjvVyxMckbScwUp92/NmOfPWmZtVwRROPggodxO/PiFmTr6xm3MA~3223865~4405561; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:34 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d98"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573712,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:34 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-27 18:28:34 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-27 18:28:34 SUCCESS
AddBasicAuthClientSecretAuthenticationParameters
Added basic authorization header
Authorization
Basic YjIxZDIzNDQtMWUzZC00NmVhLTk5NDAtZWY0NWM4YTdlNzNkOmtZbmtiNGg3Qjc=
2022-11-27 18:28:34
CallTokenEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "authorization": "Basic YjIxZDIzNDQtMWUzZC00NmVhLTk5NDAtZWY0NWM4YTdlNzNkOmtZbmtiNGg3Qjc\u003d",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "267"
}
request_body
grant_type=authorization_code&code=CX9WqR1k4v8ror5fHEJZWb8ssjendn1NxyfWnwlbXvc.5TAcPDAD1dN6_bfvGshumAxIP7xCyvQhKbz_9zAVZF52WqkNJ-VTBgk3khZ2lP_uGECsuUBpqR6L4BA_aO06UQ&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fisv_op_oidc_core_test%2Fcallback
2022-11-27 18:28:34 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKa54934c6-f0dc-4ee4-bbfa-1b9e59f76472",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383ac5207b31703",
  "content-length": "1281",
  "date": "Sun, 27 Nov 2022 18:28:34 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:h9TbVLdilChO2I4JddEA4bbrkJ+4+XFGgRUh7xSi9Uk\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dF0900F861AF2B33396EBDF509BAFDD6B~-1~YAAQLdoHYCFmzraEAQAAjCNZugiGP/xT32Cub+GiTdyE0o6Djb4E4cgxB0dKmYqL6llLF4dMstcJmzyum1qddqixA74amawhV6qavlrr/zzZXAEk9yNPtDovHBcpGndIrZ0ejv7BkjTTGvdlAZQiV5gOy+Oq/5/WxuSCBFpHISs1A5hhrX2PNNzb+hEltIXOxHK/hUOqcuc7jRNZ54+QpltaBOWjYRDaMjth9YypBH6lTdfmdqbSm8UduqBdUWuUxQX2ZOxx5ReNA3hTmZfpG1PqDpR4eXnWLqmASLyqhdXtaodFJxs8QwZz0gnAid8uWnv5G8Ng9xaQEvBvB2MUurdFV9RWg12RzNewFTCY+50cVl4CSuPlSwJEl1uRk+1dMLXVmg4\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:34 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d176EAF43F4AF3D2012BBB91ABF2D19A5~YAAQLdoHYCJmzraEAQAAjCNZuhHBUwhR7TemGQRwuxfUMutw2blnodhsvAeEdmN6N/4AvSEXyoEYx8L9rRQIMZ8vJD+9ne729rPJy78kkqP0hVMEpgoWJ1fF6a/O4ZM0NUYGti99ElwDSDyP3PaWG3y+qjoUd+uS5eND+6oMFkrrpjuLdvpe3mWoGR/AINl794zCzn9FfJ26CXE+alOfSTdk6Sj0N8fhKnKB85U4xTAmmtJXPBg+boWD8/Zyr4BfZAIxRjqdka9c963PS/LXw209tP34Px9LF0Pec05SqVyc1/ahJvkUV+eHRQjh~3223865~4405561; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:34 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d95",
    "origin; dur\u003d133"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"access_token":"6Dern4U38YbitbPbp3cwoS4jj6Bvn_HLErN-rsSZE9c.tZ-B3LWS7Iz_X2LVwU--2yezrFhN9g7QFT-S1KC8bz04fTWaPIZhAAWtCxDFuU-ZYOaVm4Hf5c9GgsFt7eL32A.M18xNjY5NTczNzE0XzE4","expires_in":7200,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiI5OTFyd09kNXk2NTlVX19ISUQ3VS13IiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkxNCwiaWF0IjoxNjY5NTczNzE0LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiJjZGJkNjQzNS01ZmI4LTQ5ZTktODJhMS0yNmJkMmRjZmUzZjYiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiOEVXa0FwTjhnRCIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNzEyLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJRSzRRVnBuZXc5UE13Umgtb2h3NXFRIiwic3ViIjoiNjE2MDAxN042NyJ9.lsI-np3zAZAftRzijKdyxnjlcMtwtp1AjChIa6WibU79N4-IJZRRYcAcywHw7YHg2PuFaCWXGxynOITQMQW_pu7IAARgZ9yI7oEuXFBXWpP_w-JaT7wYdlin9yOnp39HgzxCswgo6o5_doBZIYiPAsBrWl6G1zW3gwin06AJmZidedaCK55M7jG52nN40-kZMb2Ppn2dROWZJBBVTj9YO6R9Aa9fr9h7oIWEjtBZByO2T69XPkNLWf0pezWv5CoIAwdBYbbOcq5YcojOpw_rrZBuuaHyTnow2EU0VejzJPqcSLoDd-MnxThTlCkhDs7EYkr8FJUoE9w7JM4PIHUD-w","scope":"openid","token_type":"bearer"}
2022-11-27 18:28:34 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
6Dern4U38YbitbPbp3cwoS4jj6Bvn_HLErN-rsSZE9c.tZ-B3LWS7Iz_X2LVwU--2yezrFhN9g7QFT-S1KC8bz04fTWaPIZhAAWtCxDFuU-ZYOaVm4Hf5c9GgsFt7eL32A.M18xNjY5NTczNzE0XzE4
expires_in
7200
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiI5OTFyd09kNXk2NTlVX19ISUQ3VS13IiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkxNCwiaWF0IjoxNjY5NTczNzE0LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiJjZGJkNjQzNS01ZmI4LTQ5ZTktODJhMS0yNmJkMmRjZmUzZjYiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiOEVXa0FwTjhnRCIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNzEyLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJRSzRRVnBuZXc5UE13Umgtb2h3NXFRIiwic3ViIjoiNjE2MDAxN042NyJ9.lsI-np3zAZAftRzijKdyxnjlcMtwtp1AjChIa6WibU79N4-IJZRRYcAcywHw7YHg2PuFaCWXGxynOITQMQW_pu7IAARgZ9yI7oEuXFBXWpP_w-JaT7wYdlin9yOnp39HgzxCswgo6o5_doBZIYiPAsBrWl6G1zW3gwin06AJmZidedaCK55M7jG52nN40-kZMb2Ppn2dROWZJBBVTj9YO6R9Aa9fr9h7oIWEjtBZByO2T69XPkNLWf0pezWv5CoIAwdBYbbOcq5YcojOpw_rrZBuuaHyTnow2EU0VejzJPqcSLoDd-MnxThTlCkhDs7EYkr8FJUoE9w7JM4PIHUD-w
scope
openid
token_type
bearer
2022-11-27 18:28:34 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-11-27 18:28:34 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
6Dern4U38YbitbPbp3cwoS4jj6Bvn_HLErN-rsSZE9c.tZ-B3LWS7Iz_X2LVwU--2yezrFhN9g7QFT-S1KC8bz04fTWaPIZhAAWtCxDFuU-ZYOaVm4Hf5c9GgsFt7eL32A.M18xNjY5NTczNzE0XzE4
2022-11-27 18:28:34 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
6Dern4U38YbitbPbp3cwoS4jj6Bvn_HLErN-rsSZE9c.tZ-B3LWS7Iz_X2LVwU--2yezrFhN9g7QFT-S1KC8bz04fTWaPIZhAAWtCxDFuU-ZYOaVm4Hf5c9GgsFt7eL32A.M18xNjY5NTczNzE0XzE4
type
bearer
2022-11-27 18:28:34 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7200
2022-11-27 18:28:34 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7200
2022-11-27 18:28:34 INFO
CheckForRefreshTokenValue
Couldn't find refresh token
2022-11-27 18:28:34 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiI5OTFyd09kNXk2NTlVX19ISUQ3VS13IiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkxNCwiaWF0IjoxNjY5NTczNzE0LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiJjZGJkNjQzNS01ZmI4LTQ5ZTktODJhMS0yNmJkMmRjZmUzZjYiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiOEVXa0FwTjhnRCIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNzEyLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJRSzRRVnBuZXc5UE13Umgtb2h3NXFRIiwic3ViIjoiNjE2MDAxN042NyJ9.lsI-np3zAZAftRzijKdyxnjlcMtwtp1AjChIa6WibU79N4-IJZRRYcAcywHw7YHg2PuFaCWXGxynOITQMQW_pu7IAARgZ9yI7oEuXFBXWpP_w-JaT7wYdlin9yOnp39HgzxCswgo6o5_doBZIYiPAsBrWl6G1zW3gwin06AJmZidedaCK55M7jG52nN40-kZMb2Ppn2dROWZJBBVTj9YO6R9Aa9fr9h7oIWEjtBZByO2T69XPkNLWf0pezWv5CoIAwdBYbbOcq5YcojOpw_rrZBuuaHyTnow2EU0VejzJPqcSLoDd-MnxThTlCkhDs7EYkr8FJUoE9w7JM4PIHUD-w
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "at_hash": "991rwOd5y659U__HID7U-w",
  "sub": "6160017N67",
  "rat": 1669573712,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "8EWkApN8gD",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "QK4QVpnew9PMwRh-ohw5qQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580914,
  "iat": 1669573714,
  "jti": "cdbd6435-5fb8-49e9-82a1-26bd2dcfe3f6"
}
2022-11-27 18:28:34 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 18:28:34
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
8EWkApN8gD
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiI5OTFyd09kNXk2NTlVX19ISUQ3VS13IiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkxNCwiaWF0IjoxNjY5NTczNzE0LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiJjZGJkNjQzNS01ZmI4LTQ5ZTktODJhMS0yNmJkMmRjZmUzZjYiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiOEVXa0FwTjhnRCIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNzEyLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJRSzRRVnBuZXc5UE13Umgtb2h3NXFRIiwic3ViIjoiNjE2MDAxN042NyJ9.lsI-np3zAZAftRzijKdyxnjlcMtwtp1AjChIa6WibU79N4-IJZRRYcAcywHw7YHg2PuFaCWXGxynOITQMQW_pu7IAARgZ9yI7oEuXFBXWpP_w-JaT7wYdlin9yOnp39HgzxCswgo6o5_doBZIYiPAsBrWl6G1zW3gwin06AJmZidedaCK55M7jG52nN40-kZMb2Ppn2dROWZJBBVTj9YO6R9Aa9fr9h7oIWEjtBZByO2T69XPkNLWf0pezWv5CoIAwdBYbbOcq5YcojOpw_rrZBuuaHyTnow2EU0VejzJPqcSLoDd-MnxThTlCkhDs7EYkr8FJUoE9w7JM4PIHUD-w
2022-11-27 18:28:34 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiI5OTFyd09kNXk2NTlVX19ISUQ3VS13IiwiYXVkIjpbImIyMWQyMzQ0LTFlM2QtNDZlYS05OTQwLWVmNDVjOGE3ZTczZCJdLCJhdXRoX3RpbWUiOjE2Njk1NzM2MDYsImV4cCI6MTY2OTU4MDkxNCwiaWF0IjoxNjY5NTczNzE0LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiJjZGJkNjQzNS01ZmI4LTQ5ZTktODJhMS0yNmJkMmRjZmUzZjYiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoiOEVXa0FwTjhnRCIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTczNzEyLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiJRSzRRVnBuZXc5UE13Umgtb2h3NXFRIiwic3ViIjoiNjE2MDAxN042NyJ9.lsI-np3zAZAftRzijKdyxnjlcMtwtp1AjChIa6WibU79N4-IJZRRYcAcywHw7YHg2PuFaCWXGxynOITQMQW_pu7IAARgZ9yI7oEuXFBXWpP_w-JaT7wYdlin9yOnp39HgzxCswgo6o5_doBZIYiPAsBrWl6G1zW3gwin06AJmZidedaCK55M7jG52nN40-kZMb2Ppn2dROWZJBBVTj9YO6R9Aa9fr9h7oIWEjtBZByO2T69XPkNLWf0pezWv5CoIAwdBYbbOcq5YcojOpw_rrZBuuaHyTnow2EU0VejzJPqcSLoDd-MnxThTlCkhDs7EYkr8FJUoE9w7JM4PIHUD-w
2022-11-27 18:28:34 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 18:28:34
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 18:28:34 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-11-27 18:28:34 SUCCESS
VerifyIdTokenSubConsistentHybridFlow
authorization endpoint and token endpoint id_token have same sub
sub_auth_endpoint
6160017N67
sub_token_endpoint
6160017N67
Second authorization: Userinfo endpoint tests
2022-11-27 18:28:34
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer 6Dern4U38YbitbPbp3cwoS4jj6Bvn_HLErN-rsSZE9c.tZ-B3LWS7Iz_X2LVwU--2yezrFhN9g7QFT-S1KC8bz04fTWaPIZhAAWtCxDFuU-ZYOaVm4Hf5c9GgsFt7eL32A.M18xNjY5NTczNzE0XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:35 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK282f7e42-d6b4-44ae-a2db-a2ea97fc5344",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac52354d6351",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:35 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:RaDp+aZOz62zGfh2L9aB9CBKDHyvk4naYkckTdxQBv8\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dA7DBC43F318F45D2525C747ACCFE143C~-1~YAAQLdoHYDBmzraEAQAAoiRZugioRe+n0Buj80Biawea7Xhi/8VXhrtylCKMPcxrtjWb9la0qN/yt4SvPjm4bhxYt94qrBu6fuCFaMA+2kU3SalED2S4/21AdwsCvnXKrm5v1cdq/qD1oW9tSCkv51YC6FCvzkMyCS+bdDnVhbUbPKX80tAbdNIJ1tixFNVfyZDdvANRNISLie7HahfRfOr/LuwEe7YFTKONFO0w418OYsvFhD2nALbmsMOf95nOSV9BIITlRZ6V5hkslCnhMi3SSothu+ROi8+YL8nfJJoZFLgOXCyWFUM2re640cUUmmj5U25cIwerbKy5TRZM/kNmVTwubTCGBd26RvtMJCzRFRd51Cllt+L/XzqbTuEd4HdXdtc\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:35 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d22EFDE7533BE12C1E18742862C8547AC~YAAQLdoHYDFmzraEAQAAoiRZuhFQMCji8/8/xiLo29ZVQWy8p95zbgFeAxr4PQdDRjjkLfXzPjPmPID00vyLYaybHoZEmwP8st1Np87GbfJ3WjrpjltX8gT15YZi+tTW6DBjBCO4e3d1WLqc92IE728yzKrNeCVHPI80n8EiAxKKRM11SyI/iUO+akq+482A5QlqZ38yR2ivsrYMz9jKVLxAc9Y5HqQvzFukGOwUw3mMhi3nzm82aa1WkPUT6oOm6zjM9USRBlTQfxg95GNG2vALs2u6Svok9eoX5G5V7AgxhIlIU6ISZr8ios99~3223865~4405561; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:34 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d111"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573712,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:35 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK282f7e42-d6b4-44ae-a2db-a2ea97fc5344",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383ac52354d6351",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 18:28:35 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:RaDp+aZOz62zGfh2L9aB9CBKDHyvk4naYkckTdxQBv8\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dA7DBC43F318F45D2525C747ACCFE143C~-1~YAAQLdoHYDBmzraEAQAAoiRZugioRe+n0Buj80Biawea7Xhi/8VXhrtylCKMPcxrtjWb9la0qN/yt4SvPjm4bhxYt94qrBu6fuCFaMA+2kU3SalED2S4/21AdwsCvnXKrm5v1cdq/qD1oW9tSCkv51YC6FCvzkMyCS+bdDnVhbUbPKX80tAbdNIJ1tixFNVfyZDdvANRNISLie7HahfRfOr/LuwEe7YFTKONFO0w418OYsvFhD2nALbmsMOf95nOSV9BIITlRZ6V5hkslCnhMi3SSothu+ROi8+YL8nfJJoZFLgOXCyWFUM2re640cUUmmj5U25cIwerbKy5TRZM/kNmVTwubTCGBd26RvtMJCzRFRd51Cllt+L/XzqbTuEd4HdXdtc\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:35 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d22EFDE7533BE12C1E18742862C8547AC~YAAQLdoHYDFmzraEAQAAoiRZuhFQMCji8/8/xiLo29ZVQWy8p95zbgFeAxr4PQdDRjjkLfXzPjPmPID00vyLYaybHoZEmwP8st1Np87GbfJ3WjrpjltX8gT15YZi+tTW6DBjBCO4e3d1WLqc92IE728yzKrNeCVHPI80n8EiAxKKRM11SyI/iUO+akq+482A5QlqZ38yR2ivsrYMz9jKVLxAc9Y5HqQvzFukGOwUw3mMhi3nzm82aa1WkPUT6oOm6zjM9USRBlTQfxg95GNG2vALs2u6Svok9eoX5G5V7AgxhIlIU6ISZr8ios99~3223865~4405561; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:34 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d111"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b21d2344-1e3d-46ea-9940-ef45c8a7e73d"],"auth_time":1669573606,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669573712,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 18:28:35 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-27 18:28:35 SUCCESS
CheckIdTokenAuthTimeClaimsSameIfPresent
auth_time is the same in the second id_token
first_id_token
{
  "at_hash": "V9y4Ild6LagEt0om7eXo0A",
  "sub": "6160017N67",
  "rat": 1669573691,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "VHZZ1bBLKV",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "AuU_vvkmMoHD2IRnuHdxYQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580908,
  "iat": 1669573708,
  "jti": "2c7137fb-2a89-46ac-a8c0-77bf906ab102"
}
second_id_token
{
  "at_hash": "991rwOd5y659U__HID7U-w",
  "sub": "6160017N67",
  "rat": 1669573712,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "8EWkApN8gD",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "QK4QVpnew9PMwRh-ohw5qQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580914,
  "iat": 1669573714,
  "jti": "cdbd6435-5fb8-49e9-82a1-26bd2dcfe3f6"
}
2022-11-27 18:28:35 SUCCESS
CheckIdTokenSubConsistentForSecondAuthorization
sub is the same in the second id_token
first_id_token
{
  "at_hash": "V9y4Ild6LagEt0om7eXo0A",
  "sub": "6160017N67",
  "rat": 1669573691,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "VHZZ1bBLKV",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "AuU_vvkmMoHD2IRnuHdxYQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580908,
  "iat": 1669573708,
  "jti": "2c7137fb-2a89-46ac-a8c0-77bf906ab102"
}
second_id_token
{
  "at_hash": "991rwOd5y659U__HID7U-w",
  "sub": "6160017N67",
  "rat": 1669573712,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "8EWkApN8gD",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b21d2344-1e3d-46ea-9940-ef45c8a7e73d",
  "s_hash": "QK4QVpnew9PMwRh-ohw5qQ",
  "auth_time": 1669573606,
  "name": "ISV Dev",
  "exp": 1669580914,
  "iat": 1669573714,
  "jti": "cdbd6435-5fb8-49e9-82a1-26bd2dcfe3f6"
}
2022-11-27 18:28:35 FINISHED
oidcc-id-token-hint
Test has run to completion
testmodule_result
PASSED
Unregister dynamically registered client
2022-11-27 18:28:35
UnregisterDynamicallyRegisteredClient
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b21d2344-1e3d-46ea-9940-ef45c8a7e73d
request_method
DELETE
request_headers
{
  "accept": "application/json",
  "authorization": "Bearer fnQln9fcyea9oFBqbG1mUPJ0V85Zr9p82B_yx_AFu5Y.rbleSLZZ2LI7tczrGk5FO2U_bDTCOnmu0o2fxmdiWwsb5aXhM4SoDAGaHWsm1PEcVZxDABUf14-GXWmMIYT9XQ.M18xNjY5NTczNjgyXzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 18:28:36 RESPONSE
UnregisterDynamicallyRegisteredClient
HTTP response
response_status_code
204 NO_CONTENT
response_status_text
No Content
response_headers
{
  "x-backside-transport": "OK OK",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK4e786e43-c2d1-445e-b0e5-cc518296af85",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383ac532068bfb5",
  "date": "Sun, 27 Nov 2022 18:28:36 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:P8J9UH2nPzbuQBdelD4D5lrhRzPAXRzWGbrCjPJqjwc\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d3095E8C232B7EBA50C0E3676AE56AF62~-1~YAAQLdoHYHFmzraEAQAA+ypZughXihPT107tmmKJVbuzGvMn0Ob21ZrdaIxGDb5zlmI7d1rBy7LRTh0d1ykpzeq9WZFQVnZz7GnPInGHtQSaPP7k863yrNcxNib3kFE/gtWdFppXZatp7cEInF5b1Qn2lMCKdSwo1Z8AV0ab/9NLsywzcxAsKaUal0/Xos3W9bCxLbhgzzm6SL4CD4RMW9ZS/0M9W236RSLedbXixz4wYcmX1A0dNclY5IVreZgR5ndeW9hzDWDx2K3sVGmru2L1AK+StSTNfzI+A9BIFgv7n9EfnQCNtira1C0lAqGHfOUZ+1oHl7d3r9Xawvk1a1PRYb174LPRwN70dVlfLKUceeY/oaJv2ztqiyLTW4JaqN5m7S4\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 18:28:36 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d7C820A3392454276F230D8E09CB993AF~YAAQLdoHYHJmzraEAQAA+ypZuhHEtw5TqSj/gr5aujh9l5NT7sVSzotFTZIX3Qsz6w67KWuyDrf/qqqqv9tS28Mo8ILdLbuHHf1R1tWY83jYw5o4zd6iny0DGePzVyLFRyqbe94TJXkz/fwNsTxiyYkpTVCt8u8AHVg/WKiPB5tA9bFZXg4lakq9NXJdJ17wFDpJHO5QrmotRlMAEkMpfrcTcvc8qOgvE67Zb4FGi6N7eqUumuR5QCfakgGcJFN7Xbe7d2U3DijEZi9mf5e2VnDJ8HKR3odxrYWT++NTzWicYUHAfEC0ip5BqHf1~4605238~4536388; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 22:28:35 GMT; Max-Age\u003d14399; Secure"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body

                                
2022-11-27 18:28:36 SUCCESS
UnregisterDynamicallyRegisteredClient
Client successfully unregistered
2022-11-27 18:28:40
TEST-RUNNER
Alias has now been claimed by another test
alias
isv_op_oidc_core_test
new_test_id
A4xaIvu4XStGkd3
Test Results