Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-11-27 17:08:23 INFO
TEST-RUNNER
Test instance Rf05ZXRkzdhvTtx created
baseUrl
https://www.certification.openid.net/test/a/isv_op_oidc_core_test
variant
{
  "client_auth_type": "client_secret_basic",
  "response_type": "code id_token",
  "server_metadata": "discovery",
  "response_mode": "default",
  "client_registration": "dynamic_client"
}
alias
isv_op_oidc_core_test
description
isv_op_oidc_core_test_dynamic_client
planId
rdCLwWmseshp4
config
{
  "server": {
    "discoveryUrl": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration",
    "login_hint": "isvdev@ibm.com"
  },
  "client": {
    "client_name": "Ristretto Core Conformance Test Dynamic Client One"
  },
  "client2": {
    "client_name": "Ristretto Core Conformance Test Dynamic Client Two"
  },
  "consent": {},
  "alias": "isv_op_oidc_core_test",
  "description": "isv_op_oidc_core_test_dynamic_client"
}
testName
oidcc-claims-essential
2022-11-27 17:08:23 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-27 17:08:23
GetDynamicServerConfiguration
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-27 17:08:23 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK7f9696c4-a494-47a6-baab-74747850b9b3",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c2816383998707abc783",
  "vary": "Accept-Encoding",
  "date": "Sun, 27 Nov 2022 17:08:23 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:ZJFvZ8h+UUbxb+caaVPpPAgN0+j3wLkDpv4S7GA93Uk\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d24539E2E54ACE83D074E25BEACFE0D67~-1~YAAQTU5OaK64dqiEAQAAfLoPugh9WDIIwi/UBzvSC4LgoTPD3nAgBsU4AoajZ4U1jKbBFbbKB/kODMDiFy2xKVuzwAksWxxZshC4fuujVig6Jgf+Xo1e091JjYGDzStmERZnWeTYHXJoUSekbk1vRL0eTnVi626c8Bq948BiHtjsTHz7u1xLsKwBKhU3Enc+ZS3k71PeXtjwR04aanw+eOGdo5fCW+rIBaw+/rOS8aS1Z9UK71P+6gdi0DiPrSdbn7eYfIhp2Z8foh5XNoYtdvIIGXtPzhaqMYcJ/TVpxM+K4bSEmTRorZEFC1TyoTJsVEr4DuRaU7rW1jhPxXNB7+74YmCT40xwpGRw5lPvq4MamzRrwHBwsxybATfII5f3mZHXMLE\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:23 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d3181AE2DCC2E8CF71FFD2F5BD1ACD58D~YAAQTU5OaK+4dqiEAQAAfLoPuhFz2yycn4K9hxHYmsMZkCr3mNwNaF5JiZ9LyKSw1xBZ04LMyL7OCK6TxGDgxsIe25T3FM/iOoBf1PKirigVAUGhVZYqrgV9ldqZAqw/t23NrsIPcuE55Ms3LC1e+LSNJAyEN7WkfduVTEINnu7xEjnkHoDHluSKtSLspKRWKd8zncAqNw+O8kETCIdg68lC51JwBByYAEp8KC/UnKuWwpRpfqqqnDeLvWzLbKc9pxoqnF5zOK/psZRRTpVPo0NS4KcFHdzfF6M+YZ5d83gLk34XRC9ab9aS6K86~3486775~3491125; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:23 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d227",
    "origin; dur\u003d120"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"issuer":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","authorization_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize","token_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token","introspection_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect","userinfo_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo","revocation_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke","pushed_authorization_request_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par","registration_endpoint":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register","jwks_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks","response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"response_modes_supported":["query","fragment","form_post","jwt","query.jwt","fragment.jwt","form_post.jwt"],"grant_types_supported":["authorization_code","implicit","password","refresh_token","client_credentials"],"token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"authorization_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"authorization_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"authorization_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"id_token_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"id_token_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"id_token_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"userinfo_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"userinfo_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"subject_types_supported":["public"],"scopes_supported":["openid","profile","email","phone","address"],"claims_supported":["realmName","email","given_name","tenantId","employee_id","department","job_title","preferred_username","groupIds","upn","uid","family_name","name","mobile_number","iss","acr"],"claim_types_supported":["normal"],"claims_parameter_supported":true,"request_parameter_supported":true,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"tls_client_certificate_bound_access_tokens":true,"mtls_endpoint_aliases":{"introspection_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect","pushed_authorization_request_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par","revocation_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke","token_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"},"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"]}
2022-11-27 17:08:23 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
issuer
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize
token_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
introspection_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/introspect
userinfo_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
revocation_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/revoke
pushed_authorization_request_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/par
registration_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
response_modes_supported
[
  "query",
  "fragment",
  "form_post",
  "jwt",
  "query.jwt",
  "fragment.jwt",
  "form_post.jwt"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "refresh_token",
  "client_credentials"
]
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
authorization_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
authorization_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
authorization_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
id_token_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
id_token_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
id_token_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
userinfo_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
userinfo_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
subject_types_supported
[
  "public"
]
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address"
]
claims_supported
[
  "realmName",
  "email",
  "given_name",
  "tenantId",
  "employee_id",
  "department",
  "job_title",
  "preferred_username",
  "groupIds",
  "upn",
  "uid",
  "family_name",
  "name",
  "mobile_number",
  "iss",
  "acr"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
request_parameter_supported
true
request_uri_parameter_supported
true
require_request_uri_registration
true
tls_client_certificate_bound_access_tokens
true
mtls_endpoint_aliases
{
  "introspection_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par",
  "revocation_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke",
  "token_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"
}
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
2022-11-27 17:08:23 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-11-27 17:08:23 SUCCESS
ExtractTLSTestValuesFromServerConfiguration
Extracted TLS information from authorization server configuration
registration_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
authorization_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
token_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
userinfo_endpoint
{
  "testHost": "oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "testPort": 443
}
2022-11-27 17:08:23
FetchServerKeys
Fetching server key
jwks_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
2022-11-27 17:08:23
FetchServerKeys
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-11-27 17:08:24 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK8b021624-1f7b-479f-9182-c3917a944c8f",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281638399872042f015",
  "vary": "Accept-Encoding",
  "date": "Sun, 27 Nov 2022 17:08:24 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:QB6p9ILgKoewAMJaK49FyBUX+3OyLd/3m+1XlCrdg6I\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d861D5BB5141924D237E126AC5AABFD74~-1~YAAQTU5OaOq4dqiEAQAAPbwPuggH8twnl/zAwXxhR++JNfIoyZprev916T8jlsuWTO13wj22u3fp3l5vezHcFUgCmJB6CnRSqOcD0tKbDShI/WuaLNjMY1j4yYQwU9jzSXxP99tVBd0M9nvmFdRDCGAeygYhnXSxh7zg0j5B1tLEsXq1J/Kws4TgB9yMQMaFYFlxgd0SRkGWunwp0uAa+JfSdsTWO2faUYnB/4iwncr+tCO/fgvMbOuINVgkWB4bqAgKkpB/c5KTEz+T7/JRvJsT7uazsZ08CfwiukODS/IKcrqSXgV2XcMoAopZ+YJSsCCv4OLwzhQ474pJZccE68u5+rFKzMjXQ7xm4oNZnGhgov4z3GPqGs3fv0HDKijK0f3hQTo\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:24 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d42BF0365BD5955F53A6131FACEEE7186~YAAQTU5OaOu4dqiEAQAAPbwPuhGjrcRpCfH5It/QaKq1ZhUVCtPYphRERijk5XE5/sqacu/hN8tVxD556Hul5Idjb9M4RkPbO9eaRmSg3seFIkq1ObU04eH8Lo824vAs1uiiFAxxFCvJYNKxk9XM2nwRoGg7d7X1UQG3RYO5zDFb2fN0JusmP8hBsPd8jrXA1cg8Dxk4qSDaJvgaGePwCwAOIKWu67XqvWMNBybnPWJq/c8zcYl33ZB9FPNRY32zgW6VXSaWHlPu5xdsu3iHo2llIkDf3du9QmizBWAyUFoF53UKnopPJQPkFoqX~3486775~3491125; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:23 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d78",
    "origin; dur\u003d271"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-27 17:08:24
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-11-27 17:08:24 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-27 17:08:24 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-11-27 17:08:24 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-11-27 17:08:24 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-11-27 17:08:24 SUCCESS
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-11-27 17:08:24 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-11-27 17:08:24
StoreOriginalClientConfiguration
Created original_client_config object from the client configuration.
client_name
Ristretto Core Conformance Test Dynamic Client One
2022-11-27 17:08:24
ExtractClientNameFromStoredConfig
Extracted client_name from stored client configuration.
client_name
Ristretto Core Conformance Test Dynamic Client One
2022-11-27 17:08:24 SUCCESS
GenerateRS256ClientJWKs
Generated client JWKs
client_jwks
{
  "keys": [
    {
      "p": "57Ss4OoiPz5XTdH2tGdDC9eYPCypAF0XMQPPNUgU3ouaf23ximGpiuLxU-LmwJxwzqDszQ2mR7ruJpchRKBrg4iFPZeF2Le2gd0YjDl5xrV4yyE83OVaiDl2JXLaRo-0r2Qn-xxFFzxjqU7QwcSSrUCCQCxT1XAJ7h3qBAMsf3E",
      "kty": "RSA",
      "q": "k-_GOhEIwrjOdMGtKD1_JuQx_5U27gSporEDEzDjuavAB6LHRM2wTN0H4alT_o35TROlvF2YWsw1iWW18-VLQmiDGP4epng8EDfHHy6TXk9UubUfOeoyBMxY4Le-MjdBoJASbMVkagEXW-0_pnHWpxgCWEQYovGzQGdH33w_ddc",
      "d": "P0tyG4GqoQCdq0-0ridoaFtwKgh1D3OIudVLevvHoYOwU9fUeP132hIj6JHzkgLPlqCSS-oATtBlFzis83u3Tqr-IOKBJPJ8NSXY6abBaFKPG6kYjmI9iQWLDcIsQlie41Qr0b1Qr1ZSAkcWkQryavlsj9-jVN1gUAEofYfkmQTj197RkgV6gBLHT5ofeMIpkty9H1AB2_xTxT1gvCnn4laGh_s61Usibk-9Lhfh3n6U9NSnSulaxvZNM4ot8sG-pbuwZalk7bYjutyj-ugkYD3N3f9Fx9mf1AUFZBQ1jRu62_kvbRd7Dhq5wlFAq5H8l98IdS-bUqG5aa-sQEx-gQ",
      "e": "AQAB",
      "use": "sig",
      "qi": "DFhFxRFaKj6AbvHXJuPDZSi7IB9fWldvpxTUH5D2KqtsAtYI2mH0ksnsE5qekExXzWYNE7UWi6LZuObJuV31oDTNfXaH5cE1y8PA8YAmJUnQTlMdnyYTCYssz1v163ZfgpvAwjGWZpa8_kzlnWCb6yubHEhvvzZIztxFe3RDTHw",
      "dp": "cT3uWCZWAo7XYGNDrbviGsGN16sEFfdpRD1WYfYOrQ2RvsHfEQDWOdjclWEJ4g0TXQltcnI_WENV7WpjigTVRv3MEOQjOF3hRurl-nKEv8cleDGQa210p6tdwMO3RlEpv6a1m5afddG_65lnkawe-6nRfserWV9emw_ntXpPnyE",
      "alg": "RS256",
      "dq": "UgaW0Md1JhK2VsK0siU3BWdt2ZrwtBTdwhmH7PIksmRqu1EkUCAEavn7TsJGklRCMNx9_u2edmnYHXDJ7IvsqMuuNQNiF0d_djaXL9DxYU93WOj2gXQ7e7Gabi8zRECjINYBgVIJlUU5oHzx1-Yy8L89PZe0WVTO4RzjGyWXQk0",
      "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "alg": "RS256",
      "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
    }
  ]
}
2022-11-27 17:08:24 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-11-27 17:08:24
CreateEmptyDynamicRegistrationRequest
Created empty dynamic registration request
2022-11-27 17:08:24
AddClientNameToDynamicRegistrationRequest
Added client_name to registration request
client_name
Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx
2022-11-27 17:08:24
AddAuthorizationCodeGrantTypeToDynamicRegistrationRequest
Added 'authorization_code' to 'grant_types'
grant_types
[
  "authorization_code"
]
2022-11-27 17:08:24
AddImplicitGrantTypeToDynamicRegistrationRequest
Added 'implicit' to 'grant_types'
grant_types
[
  "authorization_code",
  "implicit"
]
2022-11-27 17:08:24
AddPublicJwksToDynamicRegistrationRequest
Added client public JWKS to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
      }
    ]
  }
}
2022-11-27 17:08:24
AddTokenEndpointAuthMethodToDynamicRegistrationRequestFromEnvironment
Added token endpoint auth method to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic"
}
2022-11-27 17:08:24
AddResponseTypesArrayToDynamicRegistrationRequestFromEnvironment
Added response_types array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token"
  ]
}
2022-11-27 17:08:24
AddRedirectUriToDynamicRegistrationRequest
Added redirect_uris array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ]
}
2022-11-27 17:08:24
AddContactsToDynamicRegistrationRequest
Added contacts array to dynamic registration request
dynamic_registration_request
{
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "jwks": {
    "keys": [
      {
        "kty": "RSA",
        "e": "AQAB",
        "use": "sig",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"
      }
    ]
  },
  "token_endpoint_auth_method": "client_secret_basic",
  "response_types": [
    "code id_token"
  ],
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ],
  "contacts": [
    "certification@oidf.org"
  ]
}
2022-11-27 17:08:24
CallDynamicRegistrationEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register
request_method
POST
request_headers
{
  "accept": "application/json",
  "accept-charset": "utf-8",
  "content-type": "application/json",
  "content-length": "769"
}
request_body
{"client_name":"Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx","grant_types":["authorization_code","implicit"],"jwks":{"keys":[{"kty":"RSA","e":"AQAB","use":"sig","alg":"RS256","n":"heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w"}]},"token_endpoint_auth_method":"client_secret_basic","response_types":["code id_token"],"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"contacts":["certification@oidf.org"]}
2022-11-27 17:08:26 RESPONSE
CallDynamicRegistrationEndpoint
HTTP response
response_status_code
201 CREATED
response_status_text
Created
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK53d58fbb-e99b-4809-bf61-151422235345",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383998810cfed39",
  "content-length": "1437",
  "date": "Sun, 27 Nov 2022 17:08:26 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:3pyctelSclY50RtMv42ToRW1Zoj2TunIEQdWTPZpmHI\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d8232108CD30C75F1729199555AC08B3D~-1~YAAQTU5OaJi5dqiEAQAAYcMPugilhp8MpBBb/Ivk0Cats37L7mNAm54fgN/UCtuZN3mnwzVL1un+hgsAH69UoNNeBXXGfywgYS+pMupvjK3u+bCeMkX9ZaefVMYTamet6Fr72MorqEEE01RSP64BGEEkOS3qQdspqY3A03wX51Bto7Szp2ROLjD3VQDGKVg891jsxcP3DVYtULx64Ng45Vbv51xiiHKeZK9clyhzchpilB1jVXlR8X1lotbvT0w8LhQJecR+1NVU/pfzeAjBuowXcORz3sNxkOLEhc+o8FiRpHHQRYuVfq7/95OMe9h1o6jXCFZLdU0a9fzbHa5/7dlMMPvS/4Vl1qsoKZUZ27tmge8jGhPVNi/cAxfropW3Q/V+BtU\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:26 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dB19A30B06EBB4E80EEFE4010627776BA~YAAQTU5OaJm5dqiEAQAAYcMPuhHzI+DhGDSncq8VBtPZW0twgtkDpIvtOIC0Gjdx3H/eIt5tp4byJbU8/ZPuFfTX5yxPwF42tG+wLDz5vcmIYFK+D/QlI4YO94ppFRvVuN+Aq/vjAgci2cPpwQsW5StvSqG7sEuT+W0STxmQbfpX2qAOoJU1EYiFBBOYwkyOG+4RrrkV51EHZJavY24XV/OmHe/5BiGOB0XtxiRvrmon+bJ6ACynD065VxCQDoEjs7CcY3E6wR8JY9zV1EdSMuIrFaU6sHmTZtTrj8MugAYH2kr+ACvqqFAhOsX6~4404292~4403777; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:24 GMT; Max-Age\u003d14398; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d164",
    "origin; dur\u003d1472"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"all_users_entitled":true,"client_id":"b2aa8d37-62b5-4332-aaec-614964a0e00e","client_id_issued_at":"2022-11-27T17:08:24Z","client_name":"Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx","client_secret":"ubjoioHiMs","client_secret_expires_at":0,"consent_action":"always_prompt","enforce_pkce":false,"grant_types":["authorization_code","implicit"],"id_token_map":[],"id_token_signed_response_alg":"RS256","initiate_login_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","jwks":{"keys":[{"use":"sig","kty":"RSA","alg":"RS256","n":"heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w","e":"AQAB"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"registration_access_token":"QscanXFgQ-FNcPFAiWXnkzzXHxxXzynBJcCcdkR2Rg4.VSXR89pAqcDJu2ypA51D6BkMwi6Cw8_6jaXZ_czMYQTx8b5z7qCZb11Y_0C0GYV5pEuxrXn0AvlkElFJbHBI1w.M18xNjY5NTY4OTA1XzE4","registration_client_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b2aa8d37-62b5-4332-aaec-614964a0e00e","response_types":["code id_token"],"token_endpoint_auth_method":"client_secret_basic","token_map":[]}
2022-11-27 17:08:26
CallDynamicRegistrationEndpoint
Parsed registration endpoint response
status
201
endpoint_name
dynamic registration
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK53d58fbb-e99b-4809-bf61-151422235345",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c2816383998810cfed39",
  "content-length": "1437",
  "date": "Sun, 27 Nov 2022 17:08:26 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:3pyctelSclY50RtMv42ToRW1Zoj2TunIEQdWTPZpmHI\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d8232108CD30C75F1729199555AC08B3D~-1~YAAQTU5OaJi5dqiEAQAAYcMPugilhp8MpBBb/Ivk0Cats37L7mNAm54fgN/UCtuZN3mnwzVL1un+hgsAH69UoNNeBXXGfywgYS+pMupvjK3u+bCeMkX9ZaefVMYTamet6Fr72MorqEEE01RSP64BGEEkOS3qQdspqY3A03wX51Bto7Szp2ROLjD3VQDGKVg891jsxcP3DVYtULx64Ng45Vbv51xiiHKeZK9clyhzchpilB1jVXlR8X1lotbvT0w8LhQJecR+1NVU/pfzeAjBuowXcORz3sNxkOLEhc+o8FiRpHHQRYuVfq7/95OMe9h1o6jXCFZLdU0a9fzbHa5/7dlMMPvS/4Vl1qsoKZUZ27tmge8jGhPVNi/cAxfropW3Q/V+BtU\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:26 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dB19A30B06EBB4E80EEFE4010627776BA~YAAQTU5OaJm5dqiEAQAAYcMPuhHzI+DhGDSncq8VBtPZW0twgtkDpIvtOIC0Gjdx3H/eIt5tp4byJbU8/ZPuFfTX5yxPwF42tG+wLDz5vcmIYFK+D/QlI4YO94ppFRvVuN+Aq/vjAgci2cPpwQsW5StvSqG7sEuT+W0STxmQbfpX2qAOoJU1EYiFBBOYwkyOG+4RrrkV51EHZJavY24XV/OmHe/5BiGOB0XtxiRvrmon+bJ6ACynD065VxCQDoEjs7CcY3E6wR8JY9zV1EdSMuIrFaU6sHmTZtTrj8MugAYH2kr+ACvqqFAhOsX6~4404292~4403777; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:24 GMT; Max-Age\u003d14398; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d164",
    "origin; dur\u003d1472"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"all_users_entitled":true,"client_id":"b2aa8d37-62b5-4332-aaec-614964a0e00e","client_id_issued_at":"2022-11-27T17:08:24Z","client_name":"Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx","client_secret":"ubjoioHiMs","client_secret_expires_at":0,"consent_action":"always_prompt","enforce_pkce":false,"grant_types":["authorization_code","implicit"],"id_token_map":[],"id_token_signed_response_alg":"RS256","initiate_login_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com","jwks":{"keys":[{"use":"sig","kty":"RSA","alg":"RS256","n":"heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w","e":"AQAB"}]},"redirect_uris":["https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"],"registration_access_token":"QscanXFgQ-FNcPFAiWXnkzzXHxxXzynBJcCcdkR2Rg4.VSXR89pAqcDJu2ypA51D6BkMwi6Cw8_6jaXZ_czMYQTx8b5z7qCZb11Y_0C0GYV5pEuxrXn0AvlkElFJbHBI1w.M18xNjY5NTY4OTA1XzE4","registration_client_uri":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b2aa8d37-62b5-4332-aaec-614964a0e00e","response_types":["code id_token"],"token_endpoint_auth_method":"client_secret_basic","token_map":[]}
body_json
{
  "all_users_entitled": true,
  "client_id": "b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "client_id_issued_at": "2022-11-27T17:08:24Z",
  "client_name": "Ristretto Core Conformance Test Dynamic Client One Rf05ZXRkzdhvTtx",
  "client_secret": "ubjoioHiMs",
  "client_secret_expires_at": 0,
  "consent_action": "always_prompt",
  "enforce_pkce": false,
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "id_token_map": [],
  "id_token_signed_response_alg": "RS256",
  "initiate_login_uri": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com",
  "jwks": {
    "keys": [
      {
        "use": "sig",
        "kty": "RSA",
        "alg": "RS256",
        "n": "heXEXNh8TbPmUReAQ2WgvNV233KF7q9RUrd9xWxFp5N3nfbhO-BGiFRWBx80KIKkFwGxgHLc79e09xcSpL6cKjIEQ01lLCgSC1JBHIXClC3OvEZfdFay6bbaYRaoi2TsO8lBmBbCykea7VVzUzVYEhQ5lw54jPJCaoLDmatVlVI0-ugggg1DhgQB3GcignZkfNeNy_ck_H7AN7kc0k29s3TpWrXblZoYvsS3Q-JLh-TMcCG51r2CK8nIdmgbYHXEttgyXnU38w4dvb9d2-e41mnhOHBqS_2oVqouVei00DpNo0fBJR2Oo9RDlRG4iiAEmlMVe5A0kwfRLA7vGWys5w",
        "e": "AQAB"
      }
    ]
  },
  "redirect_uris": [
    "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback"
  ],
  "registration_access_token": "QscanXFgQ-FNcPFAiWXnkzzXHxxXzynBJcCcdkR2Rg4.VSXR89pAqcDJu2ypA51D6BkMwi6Cw8_6jaXZ_czMYQTx8b5z7qCZb11Y_0C0GYV5pEuxrXn0AvlkElFJbHBI1w.M18xNjY5NTY4OTA1XzE4",
  "registration_client_uri": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "response_types": [
    "code id_token"
  ],
  "token_endpoint_auth_method": "client_secret_basic",
  "token_map": []
}
2022-11-27 17:08:26 SUCCESS
EnsureContentTypeJson
endpoint_response Content-Type: header is application/json
2022-11-27 17:08:26 SUCCESS
EnsureHttpStatusCodeIs201
dynamic registration endpoint returned the expected http status
expected_status
201
http_status
201
2022-11-27 17:08:26 SUCCESS
CheckNoErrorFromDynamicRegistrationEndpoint
Dynamic registration endpoint did not return an error.
2022-11-27 17:08:26 SUCCESS
ExtractDynamicRegistrationResponse
Extracted client from dynamic registration response
client_id
b2aa8d37-62b5-4332-aaec-614964a0e00e
2022-11-27 17:08:26 SUCCESS
VerifyClientManagementCredentials
Verified dynamic registration management credentials
registration_client_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b2aa8d37-62b5-4332-aaec-614964a0e00e
registration_access_token
QscanXFgQ-FNcPFAiWXnkzzXHxxXzynBJcCcdkR2Rg4.VSXR89pAqcDJu2ypA51D6BkMwi6Cw8_6jaXZ_czMYQTx8b5z7qCZb11Y_0C0GYV5pEuxrXn0AvlkElFJbHBI1w.M18xNjY5NTY4OTA1XzE4
2022-11-27 17:08:26
SetScopeInClientConfigurationToOpenId
Set scope in client configuration to "openid"
scope
openid
2022-11-27 17:08:26 SUCCESS
EnsureServerConfigurationSupportsClientSecretBasic
Contents of 'token_endpoint_auth_methods_supported' in discovery document matches expectations.
actual
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
expected
[
  "client_secret_basic"
]
minimum_matches_required
1
2022-11-27 17:08:26 SUCCESS
SetProtectedResourceUrlToUserInfoEndpoint
userinfo_endpoint will be used to test access token. The user info is not a mandatory to implement feature in the OpenID Connect specification, but is mandatory for certification.
protected_resource_url
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
2022-11-27 17:08:26
oidcc-claims-essential
Setup Done
Make request to authorization endpoint
2022-11-27 17:08:26 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
b2aa8d37-62b5-4332-aaec-614964a0e00e
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
2022-11-27 17:08:26
CreateRandomStateValue
Created state value
requested_state_length
10
state
Pl6wqtsaCf
2022-11-27 17:08:26 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
b2aa8d37-62b5-4332-aaec-614964a0e00e
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
Pl6wqtsaCf
2022-11-27 17:08:26
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
qSh9rTROaO
2022-11-27 17:08:26 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
b2aa8d37-62b5-4332-aaec-614964a0e00e
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
Pl6wqtsaCf
nonce
qSh9rTROaO
2022-11-27 17:08:26 SUCCESS
SetAuthorizationEndpointRequestResponseTypeFromEnvironment
Added response_type parameter to request
client_id
b2aa8d37-62b5-4332-aaec-614964a0e00e
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
scope
openid
state
Pl6wqtsaCf
nonce
qSh9rTROaO
response_type
code id_token
2022-11-27 17:08:26 SUCCESS
AddUserInfoEssentialNameClaimToAuthorizationEndpointRequest
Added name claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "redirect_uri": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "scope": "openid",
  "state": "Pl6wqtsaCf",
  "nonce": "qSh9rTROaO",
  "response_type": "code id_token",
  "claims": {
    "userinfo": {
      "name": {
        "essential": true
      }
    }
  }
}
2022-11-27 17:08:26 SUCCESS
BuildPlainRedirectToAuthorizationEndpoint
Sending to authorization endpoint
auth_request
{
  "client_id": "b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "redirect_uri": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "scope": "openid",
  "state": "Pl6wqtsaCf",
  "nonce": "qSh9rTROaO",
  "response_type": "code id_token",
  "claims": {
    "userinfo": {
      "name": {
        "essential": true
      }
    }
  }
}
redirect_to_authorization_endpoint
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b2aa8d37-62b5-4332-aaec-614964a0e00e&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=Pl6wqtsaCf&nonce=qSh9rTROaO&response_type=code%20id_token&claims=%7B%22userinfo%22:%7B%22name%22:%7B%22essential%22:true%7D%7D%7D
2022-11-27 17:08:26 REDIRECT
oidcc-claims-essential
Redirecting to authorization endpoint
redirect_to
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/authorize?client_id=b2aa8d37-62b5-4332-aaec-614964a0e00e&redirect_uri=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback&scope=openid&state=Pl6wqtsaCf&nonce=qSh9rTROaO&response_type=code%20id_token&claims=%7B%22userinfo%22:%7B%22name%22:%7B%22essential%22:true%7D%7D%7D
2022-11-27 17:08:37 INCOMING
oidcc-claims-essential
Incoming HTTP request to /test/a/isv_op_oidc_core_test/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close"
}
incoming_path
/test/a/isv_op_oidc_core_test/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 17:08:37 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/08Wg9Y3WC02LXaz3vw7B",
  "fullUrl": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/08Wg9Y3WC02LXaz3vw7B"
}
2022-11-27 17:08:37 OUTGOING
oidcc-claims-essential
Response to HTTP request to test instance Rf05ZXRkzdhvTtx
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/isv_op_oidc_core_test/implicit/08Wg9Y3WC02LXaz3vw7B, returnUrl=/log-detail.html?log=Rf05ZXRkzdhvTtx}]
outgoing_path
callback
2022-11-27 17:08:48 INCOMING
oidcc-claims-essential
Incoming HTTP request to /test/a/isv_op_oidc_core_test/implicit/08Wg9Y3WC02LXaz3vw7B
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "accept": "*/*",
  "content-type": "text/plain",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "connection": "close",
  "content-length": "1278"
}
incoming_path
/test/a/isv_op_oidc_core_test/implicit/08Wg9Y3WC02LXaz3vw7B
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
#code=ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw&iss=https%3A%2F%2Foidc-conformance.rel.verify.ibmcloudsecurity.com%2Foauth2&state=Pl6wqtsaCf
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-11-27 17:08:48 OUTGOING
oidcc-claims-essential
Response to HTTP request to test instance Rf05ZXRkzdhvTtx
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/08Wg9Y3WC02LXaz3vw7B
2022-11-27 17:08:48
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
parameters
[
  {
    "name": "code",
    "value": "ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q"
  },
  {
    "name": "id_token",
    "value": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw"
  },
  {
    "name": "iss",
    "value": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2"
  },
  {
    "name": "state",
    "value": "Pl6wqtsaCf"
  }
]
2022-11-27 17:08:48 SUCCESS
ExtractImplicitHashToCallbackResponse
Extracted the hash values
code
ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw
iss
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2
state
Pl6wqtsaCf
2022-11-27 17:08:48 REDIRECT-IN
oidcc-claims-essential
Authorization endpoint response captured
url_query
{}
headers
{
  "host": "www.certification.openid.net",
  "cache-control": "max-age\u003d0",
  "upgrade-insecure-requests": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Google Chrome\";v\u003d\"107\", \"Chromium\";v\u003d\"107\", \"Not\u003dA?Brand\";v\u003d\"24\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9,zh-CN;q\u003d0.8,zh;q\u003d0.7",
  "cookie": "__utmz\u003d201319536.1668662898.14.3.utmcsr\u003dcertification.openid.net|utmccn\u003d(referral)|utmcmd\u003dreferral|utmcct\u003d/; __utmc\u003d201319536; __utma\u003d201319536.1094656506.1667372526.1669169819.1669192421.17; JSESSIONID\u003dA99EA218D2554846F38BDDE459E8C220",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{
  "code": "ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q",
  "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw",
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "state": "Pl6wqtsaCf"
}
post_body
Verify authorization endpoint response
2022-11-27 17:08:48 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-11-27 17:08:48 SUCCESS
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
2022-11-27 17:08:48 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-11-27 17:08:48 SUCCESS
ValidateIssInAuthorizationResponse
'iss' parameter in authorization response matches server's issuer value.
2022-11-27 17:08:48 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-11-27 17:08:48 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
Pl6wqtsaCf
2022-11-27 17:08:48 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q
2022-11-27 17:08:48 SUCCESS
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "sub": "6160017N67",
  "rat": 1669568911,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "qSh9rTROaO",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "c_hash": "a9uTQWcG37AS9DsvgbPFNA",
  "s_hash": "0G-xb2mYb8Su_SMTUEVjWg",
  "auth_time": 1669568408,
  "name": "ISV Dev",
  "exp": 1669576117,
  "iat": 1669568917,
  "jti": "96d1f3cc-1901-443c-a1b0-21a745b53d87"
}
2022-11-27 17:08:48 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 17:08:48
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 17:08:48
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 17:08:48
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 17:08:48
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 17:08:48
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 17:08:48 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 17:08:48 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
qSh9rTROaO
2022-11-27 17:08:48 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 17:08:48 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw
2022-11-27 17:08:48 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF1ZCI6WyJiMmFhOGQzNy02MmI1LTQzMzItYWFlYy02MTQ5NjRhMGUwMGUiXSwiYXV0aF90aW1lIjoxNjY5NTY4NDA4LCJjX2hhc2giOiJhOXVUUVdjRzM3QVM5RHN2Z2JQRk5BIiwiZXhwIjoxNjY5NTc2MTE3LCJpYXQiOjE2Njk1Njg5MTcsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tL29hdXRoMiIsImp0aSI6Ijk2ZDFmM2NjLTE5MDEtNDQzYy1hMWIwLTIxYTc0NWI1M2Q4NyIsIm5hbWUiOiJJU1YgRGV2Iiwibm9uY2UiOiJxU2g5clRST2FPIiwicHJlZmVycmVkX3VzZXJuYW1lIjoiaXN2ZGV2QGlibS5jb20iLCJyYXQiOjE2Njk1Njg5MTEsInJlYWxtTmFtZSI6ImNsb3VkSWRlbnRpdHlSZWFsbSIsInNfaGFzaCI6IjBHLXhiMm1ZYjhTdV9TTVRVRVZqV2ciLCJzdWIiOiI2MTYwMDE3TjY3In0.GNpUkd7CWE34pEspTnem1K5OWjqYC8eLQO5ff9kHeu198MMyHI-FaEvfCGV6buvHPjbeiGtLSjaqqVQkSnFJTg4uMIuKadamI8-caT0BF8FQgeNO9fluKgCwGwAdjeljxloQgwOSIwxugvZ0QRWjGLMtg0TAslA7TXdfP8i7yQHn_jvjU10OyoRCUJj7geGp1GLmmNRRxICfGWO6YzDwyFWM8AwKLCprcBlsbtB0aaD5oZ_lcJhCUSpYTvSkKnY29VGuioSUTFn268v_gUy_a0SeVzTZy1Do07lKkl_ryJbLUfgC_vYa2NbZlZ7yxFz5MiHubCoRRif_zM6xmfz0Tw
2022-11-27 17:08:48 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 17:08:48
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 17:08:48 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-11-27 17:08:48 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q
redirect_uri
https://www.certification.openid.net/test/a/isv_op_oidc_core_test/callback
2022-11-27 17:08:48 SUCCESS
AddBasicAuthClientSecretAuthenticationParameters
Added basic authorization header
Authorization
Basic YjJhYThkMzctNjJiNS00MzMyLWFhZWMtNjE0OTY0YTBlMDBlOnViam9pb0hpTXM=
2022-11-27 17:08:48
CallTokenEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "authorization": "Basic YjJhYThkMzctNjJiNS00MzMyLWFhZWMtNjE0OTY0YTBlMDBlOnViam9pb0hpTXM\u003d",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "267"
}
request_body
grant_type=authorization_code&code=ZWhJWGq4f2pfbrMpuFc0yLKqANiQzZnemBjCrggucRc.elVUPSSN96QWPcVTiFqGPaV4xP28WGwx4ShaorIiBXO2TREDBxbeQPdJxf4qxoEG4c2hz5qQ-NY7kzRhDHZg0Q&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Fisv_op_oidc_core_test%2Fcallback
2022-11-27 17:08:49 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKc29d47f8-e2cf-4391-89a9-a61569444133",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c281638399a007aba6f3",
  "content-length": "1281",
  "date": "Sun, 27 Nov 2022 17:08:48 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:t/sp78cx2ZedbOarYsQwhC2CluvivjDX6o192Rh3jm0\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:54725591; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dD7BDD9320F477DD9F87853F3E94B64C6~-1~YAAQXXYGF6WzxYSEAQAA4RwQugiWGmyBxvbrnjDBaz+9PKNqS1W7GNWq+F+x8Er9dXur7DYArvlP3Dil3fCKLQkCmxMIaor6FojJpzEHArD7PbuQ63Q0NHKrQkY29dJok657mzpMhCr/2zpmxkgHaa2aBIgx16l1cDaEr+Mws3Lj0XLXxhDeyMLnQCJArZlVN8Vz7BNYVjyOONoh6Z8JFTE+5dk9qQnQqHaYD3iCuE9q1GSBO2I6LcPSAti65f4Mp8MmcwWqHdbDGteOnNv6ZOSrclzMlwLXs2SRRNygj67H2WG79g6VU7lpBjBOYFtP6HfhA5fJRmbjk740m+4xifKKkC4Chcnc79iPaH8j6jMkqX7mTplDxpzJobhS1SUv3yuIZpY\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:48 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dD1201CBBEB8D2573AC037EA5A61F35C2~YAAQXXYGF6azxYSEAQAA4RwQuhGTro2In5m8p0jSeMD9Uf6wNs1Sx4JeERBdU1BkqU8fJMtIgZ3NX6UkL+EXGR2BmxRb1hVORBAyu0J/Aiq4cRV7qRz2NBHgwHkGeyVRs0X/I4cWCgwovxQfz6UQwHKWfs4PW0gCEh1cUMkJcTbXt0GW/IWRzmA++n0J+t0Ivv8jecRd5viI2eAsTIAdkEQLSfoTs52n8C8g40RNrWPe3qilT4VuFWKXsfzFcHHlzO8fdqZv67Pz1LbV8nBh26CiBatjwLkpyCKaQ8FanPMyqKmtpQgKBW4lrGh6~3294785~3619128; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:48 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d448",
    "origin; dur\u003d242"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"access_token":"BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4","expires_in":7200,"id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJUWE9ob2hjcDVmWVBZNExxZ1oybUpRIiwiYXVkIjpbImIyYWE4ZDM3LTYyYjUtNDMzMi1hYWVjLTYxNDk2NGEwZTAwZSJdLCJhdXRoX3RpbWUiOjE2Njk1Njg0MDgsImV4cCI6MTY2OTU3NjEyOCwiaWF0IjoxNjY5NTY4OTI4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyM2RkNDVkZC1kNjdmLTQyZTItYTk1Ni01MGI0ZmEyNjAzMjAiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoicVNoOXJUUk9hTyIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTY4OTExLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiIwRy14YjJtWWI4U3VfU01UVUVWaldnIiwic3ViIjoiNjE2MDAxN042NyJ9.BiKKuaUnv2zXw7pgauZFjyJR4L25zT3YxFCFVhnP9RXdYZyroZK0OkmFyPvnP27Yw3iU4XplfNuZtrrih68pOHR6UyS0NqdGBJ4ENAdUT46u3DrEAkNFtmhlz4O-mAZl_nRjwWcHTR2UmqBDEdfGa6EUMEBfGs-deyvB1LGXemMZuW74LdNYDNCresLr31hnFb9PkAGALT_yZ4lno8HwL8aFMrOIr1lV-whZwr99yp9JrYsLSt7AjhZwu5CdXAsuBYO5RkZUgdoCToXYxez6bfuixdmHH6y7oWKeiglFrIwWKAJZvN0I9d6uIfEYfU6Dkp5HZOKPgBg0eb3_bX5ZrA","scope":"openid","token_type":"bearer"}
2022-11-27 17:08:49 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4
expires_in
7200
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJUWE9ob2hjcDVmWVBZNExxZ1oybUpRIiwiYXVkIjpbImIyYWE4ZDM3LTYyYjUtNDMzMi1hYWVjLTYxNDk2NGEwZTAwZSJdLCJhdXRoX3RpbWUiOjE2Njk1Njg0MDgsImV4cCI6MTY2OTU3NjEyOCwiaWF0IjoxNjY5NTY4OTI4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyM2RkNDVkZC1kNjdmLTQyZTItYTk1Ni01MGI0ZmEyNjAzMjAiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoicVNoOXJUUk9hTyIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTY4OTExLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiIwRy14YjJtWWI4U3VfU01UVUVWaldnIiwic3ViIjoiNjE2MDAxN042NyJ9.BiKKuaUnv2zXw7pgauZFjyJR4L25zT3YxFCFVhnP9RXdYZyroZK0OkmFyPvnP27Yw3iU4XplfNuZtrrih68pOHR6UyS0NqdGBJ4ENAdUT46u3DrEAkNFtmhlz4O-mAZl_nRjwWcHTR2UmqBDEdfGa6EUMEBfGs-deyvB1LGXemMZuW74LdNYDNCresLr31hnFb9PkAGALT_yZ4lno8HwL8aFMrOIr1lV-whZwr99yp9JrYsLSt7AjhZwu5CdXAsuBYO5RkZUgdoCToXYxez6bfuixdmHH6y7oWKeiglFrIwWKAJZvN0I9d6uIfEYfU6Dkp5HZOKPgBg0eb3_bX5ZrA
scope
openid
token_type
bearer
2022-11-27 17:08:49 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-11-27 17:08:49 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4
2022-11-27 17:08:49 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4
type
bearer
2022-11-27 17:08:49 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
7200
2022-11-27 17:08:49 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
7200
2022-11-27 17:08:49 INFO
CheckForRefreshTokenValue
Couldn't find refresh token
2022-11-27 17:08:49 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJUWE9ob2hjcDVmWVBZNExxZ1oybUpRIiwiYXVkIjpbImIyYWE4ZDM3LTYyYjUtNDMzMi1hYWVjLTYxNDk2NGEwZTAwZSJdLCJhdXRoX3RpbWUiOjE2Njk1Njg0MDgsImV4cCI6MTY2OTU3NjEyOCwiaWF0IjoxNjY5NTY4OTI4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyM2RkNDVkZC1kNjdmLTQyZTItYTk1Ni01MGI0ZmEyNjAzMjAiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoicVNoOXJUUk9hTyIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTY4OTExLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiIwRy14YjJtWWI4U3VfU01UVUVWaldnIiwic3ViIjoiNjE2MDAxN042NyJ9.BiKKuaUnv2zXw7pgauZFjyJR4L25zT3YxFCFVhnP9RXdYZyroZK0OkmFyPvnP27Yw3iU4XplfNuZtrrih68pOHR6UyS0NqdGBJ4ENAdUT46u3DrEAkNFtmhlz4O-mAZl_nRjwWcHTR2UmqBDEdfGa6EUMEBfGs-deyvB1LGXemMZuW74LdNYDNCresLr31hnFb9PkAGALT_yZ4lno8HwL8aFMrOIr1lV-whZwr99yp9JrYsLSt7AjhZwu5CdXAsuBYO5RkZUgdoCToXYxez6bfuixdmHH6y7oWKeiglFrIwWKAJZvN0I9d6uIfEYfU6Dkp5HZOKPgBg0eb3_bX5ZrA
header
{
  "kid": "server",
  "alg": "RS256"
}
claims
{
  "at_hash": "TXOhohcp5fYPY4LqgZ2mJQ",
  "sub": "6160017N67",
  "rat": 1669568911,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "preferred_username": "isvdev@ibm.com",
  "nonce": "qSh9rTROaO",
  "acr": "urn:ibm:security:policy:id:1",
  "aud": "b2aa8d37-62b5-4332-aaec-614964a0e00e",
  "s_hash": "0G-xb2mYb8Su_SMTUEVjWg",
  "auth_time": 1669568408,
  "name": "ISV Dev",
  "exp": 1669576128,
  "iat": 1669568928,
  "jti": "23dd45dd-d67f-42e2-a956-50b4fa260320"
}
2022-11-27 17:08:49 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-11-27 17:08:49
ValidateIdTokenStandardClaims
sub is a string with content
2022-11-27 17:08:49
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-11-27 17:08:49
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-11-27 17:08:49
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-11-27 17:08:49
ValidateIdTokenStandardClaims
name is a string with content
2022-11-27 17:08:49 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-11-27 17:08:49 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
qSh9rTROaO
2022-11-27 17:08:49 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
2022-11-27 17:08:49 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJUWE9ob2hjcDVmWVBZNExxZ1oybUpRIiwiYXVkIjpbImIyYWE4ZDM3LTYyYjUtNDMzMi1hYWVjLTYxNDk2NGEwZTAwZSJdLCJhdXRoX3RpbWUiOjE2Njk1Njg0MDgsImV4cCI6MTY2OTU3NjEyOCwiaWF0IjoxNjY5NTY4OTI4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyM2RkNDVkZC1kNjdmLTQyZTItYTk1Ni01MGI0ZmEyNjAzMjAiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoicVNoOXJUUk9hTyIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTY4OTExLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiIwRy14YjJtWWI4U3VfU01UVUVWaldnIiwic3ViIjoiNjE2MDAxN042NyJ9.BiKKuaUnv2zXw7pgauZFjyJR4L25zT3YxFCFVhnP9RXdYZyroZK0OkmFyPvnP27Yw3iU4XplfNuZtrrih68pOHR6UyS0NqdGBJ4ENAdUT46u3DrEAkNFtmhlz4O-mAZl_nRjwWcHTR2UmqBDEdfGa6EUMEBfGs-deyvB1LGXemMZuW74LdNYDNCresLr31hnFb9PkAGALT_yZ4lno8HwL8aFMrOIr1lV-whZwr99yp9JrYsLSt7AjhZwu5CdXAsuBYO5RkZUgdoCToXYxez6bfuixdmHH6y7oWKeiglFrIwWKAJZvN0I9d6uIfEYfU6Dkp5HZOKPgBg0eb3_bX5ZrA
2022-11-27 17:08:49 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJSUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46aWJtOnNlY3VyaXR5OnBvbGljeTppZDoxIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJUWE9ob2hjcDVmWVBZNExxZ1oybUpRIiwiYXVkIjpbImIyYWE4ZDM3LTYyYjUtNDMzMi1hYWVjLTYxNDk2NGEwZTAwZSJdLCJhdXRoX3RpbWUiOjE2Njk1Njg0MDgsImV4cCI6MTY2OTU3NjEyOCwiaWF0IjoxNjY5NTY4OTI4LCJpc3MiOiJodHRwczovL29pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbS9vYXV0aDIiLCJqdGkiOiIyM2RkNDVkZC1kNjdmLTQyZTItYTk1Ni01MGI0ZmEyNjAzMjAiLCJuYW1lIjoiSVNWIERldiIsIm5vbmNlIjoicVNoOXJUUk9hTyIsInByZWZlcnJlZF91c2VybmFtZSI6ImlzdmRldkBpYm0uY29tIiwicmF0IjoxNjY5NTY4OTExLCJyZWFsbU5hbWUiOiJjbG91ZElkZW50aXR5UmVhbG0iLCJzX2hhc2giOiIwRy14YjJtWWI4U3VfU01UVUVWaldnIiwic3ViIjoiNjE2MDAxN042NyJ9.BiKKuaUnv2zXw7pgauZFjyJR4L25zT3YxFCFVhnP9RXdYZyroZK0OkmFyPvnP27Yw3iU4XplfNuZtrrih68pOHR6UyS0NqdGBJ4ENAdUT46u3DrEAkNFtmhlz4O-mAZl_nRjwWcHTR2UmqBDEdfGa6EUMEBfGs-deyvB1LGXemMZuW74LdNYDNCresLr31hnFb9PkAGALT_yZ4lno8HwL8aFMrOIr1lV-whZwr99yp9JrYsLSt7AjhZwu5CdXAsuBYO5RkZUgdoCToXYxez6bfuixdmHH6y7oWKeiglFrIwWKAJZvN0I9d6uIfEYfU6Dkp5HZOKPgBg0eb3_bX5ZrA
2022-11-27 17:08:49 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6160017N67
2022-11-27 17:08:49
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-11-27 17:08:49 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-11-27 17:08:49 SUCCESS
VerifyIdTokenSubConsistentHybridFlow
authorization endpoint and token endpoint id_token have same sub
sub_auth_endpoint
6160017N67
sub_token_endpoint
6160017N67
Userinfo endpoint tests
2022-11-27 17:08:49
CallProtectedResource
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 17:08:49 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK9be116ac-a952-417f-8307-d21a2894f755",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281638399a120431335",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 17:08:49 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:KC79mFae3ETtct5rFwEmHZRguaRYCGseqt1h5JfSp5g\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dC3AD446041EB81DD4DFD4A399AA091DB~-1~YAAQXXYGF7OzxYSEAQAA+R0Quggq0ESBWuhM/2EOH0LTTzAMEsxofdh1J1FLNGGqpMqVbIEORJCqQPjTFGaeJSgAAhMiJDJa6c4dZljNegUOJ4wJExPyiz3pCsPLcWFjaMrWJ59fSDPacpGxTIEcC336tOFKyBTARkWix2KAdxPGIsbjXuDmdqN5a0iBJmW/LhX5SLwp7fmhKYaN9UH57cjCeUfUJ7lbzqZRfVIyiPf7LwQYzs1ZcIrVq+bDiCCvl91iWYAeahlY9di83tQRglzyocZKLomRXCnvtIF0rlAdA18wjep+44QU+CUOpnMkmDJPcgv1aEk0F2R96If2SEN3U5VBc9aFc2K5qzPp3761d6v6HhE4cy0NvPOC7Z7tGLOc8tA\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:49 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF5A6DD737634F3DABB053F06D9455005~YAAQXXYGF7SzxYSEAQAA+R0QuhEVUaQOThhsK4h4jWLXxovbokGW/+tLPtHX/tcAzqAXn2qVx3zY+Z9YoUDBqsPc8P9QE5yGTJV/abmdG1173tS1iefE8jdWdjj4yG9/6n4xNsPIPNNf44GdqH8UHxYeDCUQA96+M/1kUPemYjFIiM4XOygMmxXly1FzzxfICZDOLrV7fe/7UWqWDu1htt18BhAJML0kIeIuAOfKZqKDBu0wjL1r1Nnwl3Z9T8Z+HpcANRCGeDu8xp4/383oHNNC034oikA9heRc/DdjLBAzXKrP/842Fl/D/WSC~3290676~3622214; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:49 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d110"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b2aa8d37-62b5-4332-aaec-614964a0e00e"],"auth_time":1669568408,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669568911,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 17:08:49 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK9be116ac-a952-417f-8307-d21a2894f755",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281638399a120431335",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 17:08:49 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:KC79mFae3ETtct5rFwEmHZRguaRYCGseqt1h5JfSp5g\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003dC3AD446041EB81DD4DFD4A399AA091DB~-1~YAAQXXYGF7OzxYSEAQAA+R0Quggq0ESBWuhM/2EOH0LTTzAMEsxofdh1J1FLNGGqpMqVbIEORJCqQPjTFGaeJSgAAhMiJDJa6c4dZljNegUOJ4wJExPyiz3pCsPLcWFjaMrWJ59fSDPacpGxTIEcC336tOFKyBTARkWix2KAdxPGIsbjXuDmdqN5a0iBJmW/LhX5SLwp7fmhKYaN9UH57cjCeUfUJ7lbzqZRfVIyiPf7LwQYzs1ZcIrVq+bDiCCvl91iWYAeahlY9di83tQRglzyocZKLomRXCnvtIF0rlAdA18wjep+44QU+CUOpnMkmDJPcgv1aEk0F2R96If2SEN3U5VBc9aFc2K5qzPp3761d6v6HhE4cy0NvPOC7Z7tGLOc8tA\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:49 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF5A6DD737634F3DABB053F06D9455005~YAAQXXYGF7SzxYSEAQAA+R0QuhEVUaQOThhsK4h4jWLXxovbokGW/+tLPtHX/tcAzqAXn2qVx3zY+Z9YoUDBqsPc8P9QE5yGTJV/abmdG1173tS1iefE8jdWdjj4yG9/6n4xNsPIPNNf44GdqH8UHxYeDCUQA96+M/1kUPemYjFIiM4XOygMmxXly1FzzxfICZDOLrV7fe/7UWqWDu1htt18BhAJML0kIeIuAOfKZqKDBu0wjL1r1Nnwl3Z9T8Z+HpcANRCGeDu8xp4/383oHNNC034oikA9heRc/DdjLBAzXKrP/842Fl/D/WSC~3290676~3622214; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:49 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d91",
    "origin; dur\u003d110"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b2aa8d37-62b5-4332-aaec-614964a0e00e"],"auth_time":1669568408,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669568911,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 17:08:49 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-27 17:08:49
CallUserInfoEndpoint
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/userinfo
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer BPTqwZa1MLFqnwmedeO-4FoqdxQtOjYKTesnYH1DySE.IfAsWj6TjXtoqMsOkjLnUL_bML6_qJIFVGWemrz_MgpW4AxG298-PvPjGkrmfBGRri3RG4yqFBJVb3eFPzZxtQ.M18xNjY5NTY4OTI4XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 17:08:49 RESPONSE
CallUserInfoEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKa4c43e14-b015-4cb2-8864-3ac95581f6aa",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281638399a120431cf5",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 17:08:49 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:nasc+62mQ0jaS27BOLEOOGItW/VbbNqyMQ9OVD+eDgk\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d1A87E41BF7E5909E19510E544A89CBC4~-1~YAAQXXYGF8KzxYSEAQAADR8QuggwDkKUoD94UY3xXHGUJxicdwGbL+mDPdQ5e4ibCcsdXe9niY0NsGhhlu8QCV1Tw67XsqG9I4bAjcAoFs4gn1xMDQy2gV6QucrED/3SyKnHa5y4jVKT2KsFBqD3AikgH44lYeHo/z0WfwCo6kBWaCYU8F1xALQOvkIqdwpvWkLYb5q8YHk1H8GhwDJ+AOW26Pq7uTiimpltFg9p6CaxjnDkEeeix6rDie91BhnEZ3lnrRb/czSyPdocHMZ+7qhuVuqXrfMJ09IQEi82BDj/Ut6kcepNzRRwlLazmcfk7ESYLqwR8JnV8i2kocxCJ4NUH3XDg0KzTw0CyL+UXH8JrbylhqE2IOZ1Ni+BNyEL3UxbpaA\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:49 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dEB0E2C6881259718BAE3797816DA3529~YAAQXXYGF8OzxYSEAQAADR8QuhF6heNVbtU5jPp+n6hd+4STT6eJk8LzR7CCMQ/ctUvTKpC2SAgQ2bgM9BA/Rpgnf++a0VuobI3fJgliPtdVmyatmZhTlkY6ReYXyX1aLDeTxOAVnCyx6MjlVAN+5Vb0oKXSMR1ECFZNU2pVMb6vqzQf0BRstaTErOqs3osOU6FI7SuTKnG2kAYVqeYALsbWGFOe6M2eo3MyPa/2fVWAMgx/4z77XQIbgEkrhfuzRxkrRkFXJlpzjFoygAbaDWemR+zcZxH7PPRJMWG2VbkhpaLmcmdaIUAEyOee~3290676~3622214; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:49 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d95",
    "origin; dur\u003d113"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b2aa8d37-62b5-4332-aaec-614964a0e00e"],"auth_time":1669568408,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669568911,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 17:08:49 SUCCESS
CallUserInfoEndpoint
Got a response from the userinfo endpoint
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKa4c43e14-b015-4cb2-8864-3ac95581f6aa",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c281638399a120431cf5",
  "content-length": "324",
  "date": "Sun, 27 Nov 2022 17:08:49 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:nasc+62mQ0jaS27BOLEOOGItW/VbbNqyMQ9OVD+eDgk\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d1A87E41BF7E5909E19510E544A89CBC4~-1~YAAQXXYGF8KzxYSEAQAADR8QuggwDkKUoD94UY3xXHGUJxicdwGbL+mDPdQ5e4ibCcsdXe9niY0NsGhhlu8QCV1Tw67XsqG9I4bAjcAoFs4gn1xMDQy2gV6QucrED/3SyKnHa5y4jVKT2KsFBqD3AikgH44lYeHo/z0WfwCo6kBWaCYU8F1xALQOvkIqdwpvWkLYb5q8YHk1H8GhwDJ+AOW26Pq7uTiimpltFg9p6CaxjnDkEeeix6rDie91BhnEZ3lnrRb/czSyPdocHMZ+7qhuVuqXrfMJ09IQEi82BDj/Ut6kcepNzRRwlLazmcfk7ESYLqwR8JnV8i2kocxCJ4NUH3XDg0KzTw0CyL+UXH8JrbylhqE2IOZ1Ni+BNyEL3UxbpaA\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:49 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dEB0E2C6881259718BAE3797816DA3529~YAAQXXYGF8OzxYSEAQAADR8QuhF6heNVbtU5jPp+n6hd+4STT6eJk8LzR7CCMQ/ctUvTKpC2SAgQ2bgM9BA/Rpgnf++a0VuobI3fJgliPtdVmyatmZhTlkY6ReYXyX1aLDeTxOAVnCyx6MjlVAN+5Vb0oKXSMR1ECFZNU2pVMb6vqzQf0BRstaTErOqs3osOU6FI7SuTKnG2kAYVqeYALsbWGFOe6M2eo3MyPa/2fVWAMgx/4z77XQIbgEkrhfuzRxkrRkFXJlpzjFoygAbaDWemR+zcZxH7PPRJMWG2VbkhpaLmcmdaIUAEyOee~3290676~3622214; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:49 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d95",
    "origin; dur\u003d113"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
status_code
{
  "code": 200
}
body
{"acr":"urn:ibm:security:policy:id:1","amr":["password"],"aud":["b2aa8d37-62b5-4332-aaec-614964a0e00e"],"auth_time":1669568408,"iss":"https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2","name":"ISV Dev","preferred_username":"isvdev@ibm.com","rat":1669568911,"realmName":"cloudIdentityRealm","sub":"6160017N67"}
2022-11-27 17:08:49 SUCCESS
EnsureHttpStatusCodeIs200
resource endpoint returned the expected http status
expected_status
200
http_status
200
2022-11-27 17:08:49 SUCCESS
ExtractUserInfoFromUserInfoEndpointResponse
Extracted user info
userinfo
{
  "acr": "urn:ibm:security:policy:id:1",
  "amr": [
    "password"
  ],
  "aud": [
    "b2aa8d37-62b5-4332-aaec-614964a0e00e"
  ],
  "auth_time": 1669568408,
  "iss": "https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2",
  "name": "ISV Dev",
  "preferred_username": "isvdev@ibm.com",
  "rat": 1669568911,
  "realmName": "cloudIdentityRealm",
  "sub": "6160017N67"
}
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: acr
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: amr
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: aud
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: auth_time
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: iss
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
name is a string with content
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
preferred_username is a string with content
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: rat
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
Skipping unknown claim: realmName
2022-11-27 17:08:49
ValidateUserInfoStandardClaims
sub is a string with content
2022-11-27 17:08:49 SUCCESS
ValidateUserInfoStandardClaims
Userinfo is valid
2022-11-27 17:08:49 SUCCESS
EnsureUserInfoContainsSub
Found sub in userinfo
sub
6160017N67
2022-11-27 17:08:49
EnsureUserInfoUpdatedAtValid
userinfo response does not contain 'updated_at'
2022-11-27 17:08:49
EnsureMemberValuesInClaimNameReferenceToMemberNamesInClaimSources
userinfo response does not contain '_claim_names' nor _claim_sources'
2022-11-27 17:08:49 SUCCESS
VerifyUserInfoAndIdTokenInAuthorizationEndpointSameSub
userinfo response and id_token sub are the same
sub_user_info
6160017N67
sub_id_token
6160017N67
2022-11-27 17:08:49 SUCCESS
VerifyUserInfoAndIdTokenInTokenEndpointSameSub
userinfo response and id_token sub are the same
sub_user_info
6160017N67
sub_id_token
6160017N67
2022-11-27 17:08:49 SUCCESS
VerifyScopesReturnedInUserInfoClaims
'claims' in userinfo contains all scope items of scope in authorization request (corresponds to scope standard claims)
actual_scope_items
[
  "acr",
  "amr",
  "aud",
  "auth_time",
  "iss",
  "name",
  "preferred_username",
  "rat",
  "realmName",
  "sub"
]
expected_scope_items
[
  "sub"
]
2022-11-27 17:08:49 SUCCESS
EnsureUserInfoContainsName
Found name in userinfo
name
ISV Dev
2022-11-27 17:08:49 WARNING
EnsureIdTokenDoesNotContainName
Unexpectedly found name in id_token. The conformance suite did not request the 'name' claim is returned in the id_token and hence did not expect the server to include it. Technically this does not violate the specifications but it is likely a bug in the server and may result in user data being exposed in unintended ways.
name
ISV Dev
2022-11-27 17:08:49 FINISHED
oidcc-claims-essential
Test has run to completion
testmodule_result
WARNING
Unregister dynamically registered client
2022-11-27 17:08:49
UnregisterDynamicallyRegisteredClient
HTTP request
request_uri
https://oidc-conformance.rel.verify.ibmcloudsecurity.com/oauth2/register/b2aa8d37-62b5-4332-aaec-614964a0e00e
request_method
DELETE
request_headers
{
  "accept": "application/json",
  "authorization": "Bearer QscanXFgQ-FNcPFAiWXnkzzXHxxXzynBJcCcdkR2Rg4.VSXR89pAqcDJu2ypA51D6BkMwi6Cw8_6jaXZ_czMYQTx8b5z7qCZb11Y_0C0GYV5pEuxrXn0AvlkElFJbHBI1w.M18xNjY5NTY4OTA1XzE4",
  "content-length": "0"
}
request_body

                                
2022-11-27 17:08:51 RESPONSE
UnregisterDynamicallyRegisteredClient
HTTP response
response_status_code
204 NO_CONTENT
response_status_text
No Content
response_headers
{
  "x-backside-transport": "OK OK",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKead50dce-6bff-47b6-b360-2a006e9ce511",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c281638399a110d00409",
  "date": "Sun, 27 Nov 2022 17:08:51 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:EjfZ93493Ea2xFD7WPglIxeWlSxcvQU/rmKge04yVy0\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.verify.ibmcloudsecurity.com; Secure; HttpOnly",
    "_abck\u003d42861D8004C627C2BEF77560537E7183~-1~YAAQXXYGFz20xYSEAQAApCcQuggr6FhsMjtIv8N/qP/d7nEfXG7AEqbPURH+JipKJPv/uHnLAjh9L7qLa50c79lniH2KXoo8UGF0K5l6DqXZj1DIEjNRgGGpNHOZHEIT+xDpp4d+v8O6QWxJXtwnZcrud8Rf2cBV4jfWOnxHul4H46cg6Js9bs4CA4XVXol1GIkAZn2yr4mR5fDXHqa1ZLgqVtVTycg8+8vr670sqC52yhcDE50CsbS6Q1mtBKdsBZUY4gfgxDa/oVdMz/sRve2I3hLW/UylSS0aoZZmPI6pwt4VdLw3F85FCGO1uPHF7vsCMhVW8xJPC1VIePqBmYbzx2TZT2PM/zIq1gc8PDmJeCdR1crbvYFk88UL66UKpJXBnd4\u003d~-1~-1~-1; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dMon, 27 Nov 2023 17:08:51 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d72A21A6F1B23D1684131FBA60B6E9FB3~YAAQXXYGFz60xYSEAQAApCcQuhGj8HPolVMT/V7+XeqdP85xRVozaTiZZ1GHX/ECNDJO/8HuS529sdK21+cpKcXIQXBQrAQxzAvlgSwk2t6x3hcKDBN8L+z4KJYwl6mkhF9gputEVAhN6JdpOdJHtCBDobVXZ22XkkLVwBmitSWLrDy45QFSF2uOdTrBYngKJs8P9xI8oZT3KZNL5yb5/VG2GSKeViq2s0eRml5ieNECKPv8dK2UgvBnFnA2kOuvR7bg5DMGICbPDIa5FvTGDCTbHBOd7sL8iqKBqouMFq3X//tfif6Cu7NhneaS~3290676~3622214; Domain\u003d.ibmcloudsecurity.com; Path\u003d/; Expires\u003dSun, 27 Nov 2022 21:08:49 GMT; Max-Age\u003d14398; Secure"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body

                                
2022-11-27 17:08:51 SUCCESS
UnregisterDynamicallyRegisteredClient
Client successfully unregistered
2022-11-27 17:08:56
TEST-RUNNER
Alias has now been claimed by another test
alias
isv_op_oidc_core_test
new_test_id
ICVzilgn26O7GqW
Test Results