Test Name | oidcc-client-test-idtoken-sig-none |
---|---|
Variant | client_auth_type=client_secret_basic, request_type=plain_http_request, response_type=code, response_mode=default, client_registration=static_client |
Test ID | XzAC0lizZom7Atp https://www.certification.openid.net/log-detail.html?public=true&log=XzAC0lizZom7Atp |
Created | 2025-04-28T07:51:12.841949589Z |
Description | Conformance testing of Arcon Converged Identity as a Relaying Party using the OpenID Connect Core: Basic Certification Profile |
Test Version | 5.1.31 |
Test Owner | 115858928797071758548 https://accounts.google.com |
Plan ID | BFj2iiVzbPPzd https://www.certification.openid.net/plan-detail.html?public=true&plan=BFj2iiVzbPPzd |
Exported From | https://www.certification.openid.net |
Exported By | 115858928797071758548 https://accounts.google.com |
Suite Version | 5.1.31 |
Exported | 2025-04-28 09:40:10 (UTC) |
Status: FINISHED Result: SKIPPED |
SUCCESS 39 FAILURE 0 WARNING 0 REVIEW 0 INFO 18 |
2025-04-28 07:51:12 |
INFO
|
TEST-RUNNER
Test instance XzAC0lizZom7Atp created
|
||||||||||||||||
|
2025-04-28 07:51:12 |
SUCCESS
|
OIDCCGenerateServerConfiguration
Generated default server configuration
|
||
|
2025-04-28 07:51:12 |
|
SetTokenEndpointAuthMethodsSupportedToClientSecretBasicOnly
Changed token_endpoint_auth_methods_supported to client_secret_basic only in server configuration
|
||
|
2025-04-28 07:51:13 |
|
OIDCCGenerateServerJWKs
Generated server public private JWK sets
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2025-04-28 07:51:13 | SUCCESS |
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
|
||
|
2025-04-28 07:51:13 |
SUCCESS
|
OIDCCLoadUserInfo
Added user information
|
||
|
2025-04-28 07:51:13 |
SUCCESS
|
OIDCCGetStaticClientConfigurationForRPTests
Found a static client object
|
||||||||
|
2025-04-28 07:51:13 | SUCCESS |
EnsureClientDoesNotHaveBothJwksAndJwksUri
Client does not have both jwks and jwks_uri set
|
||
|
2025-04-28 07:51:13 | INFO |
FetchClientKeys
Skipped evaluation due to missing required element: client jwks_uri
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientGrantTypes
grant_types match response_types
|
||||
|
2025-04-28 07:51:13 | SUCCESS |
OIDCCValidateClientRedirectUris
Valid redirect_uri(s) provided in registration request
|
||
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientLogoUris
Client does not contain any logo_uri
|
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientUris
Client does not contain any client_uri
|
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientPolicyUris
Client does not contain any policy_uri
|
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientTosUris
Client does not contain any tos_uri
|
|
2025-04-28 07:51:13 | SUCCESS |
ValidateClientSubjectType
A subject_type was not provided
|
|
2025-04-28 07:51:13 | INFO |
ValidateIdTokenSignedResponseAlg
Skipped evaluation due to missing required element: client id_token_signed_response_alg
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
EnsureIdTokenEncryptedResponseAlgIsSetIfEncIsSet
id_token_encrypted_response_enc is not set
|
|
2025-04-28 07:51:13 | INFO |
ValidateUserinfoSignedResponseAlg
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
EnsureUserinfoEncryptedResponseAlgIsSetIfEncIsSet
userinfo_encrypted_response_enc is not set
|
|
2025-04-28 07:51:13 | INFO |
ValidateRequestObjectSigningAlg
Skipped evaluation due to missing required element: client request_object_signing_alg
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
EnsureRequestObjectEncryptionAlgIsSetIfEncIsSet
request_object_encryption_enc is not set
|
|
2025-04-28 07:51:13 | INFO |
ValidateTokenEndpointAuthSigningAlg
Skipped evaluation due to missing required element: client token_endpoint_auth_signing_alg
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
ValidateDefaultMaxAge
default_max_age is not set
|
|
2025-04-28 07:51:13 | INFO |
ValidateRequireAuthTime
Skipped evaluation due to missing required element: client require_auth_time
|
||||||
|
2025-04-28 07:51:13 | INFO |
ValidateDefaultAcrValues
Skipped evaluation due to missing required element: client default_acr_values
|
||||||
|
2025-04-28 07:51:13 | SUCCESS |
ValidateInitiateLoginUri
initiate_login_uri is valid
|
||
|
2025-04-28 07:51:13 | INFO |
ValidateRequestUris
Skipped evaluation due to missing required element: client request_uris
|
||||||
|
2025-04-28 07:51:13 |
|
SetServerSigningAlgToNone
Successfully set signing algorithm to none
|
||
|
2025-04-28 07:51:13 |
|
SetClientIdTokenSignedResponseAlgToServerSigningAlg
Set id_token_signed_response_alg for the registered client
|
||
|
2025-04-28 07:51:13 |
|
oidcc-client-test-idtoken-sig-none
Setup Done
|
|
2025-04-28 07:51:19 |
INCOMING
|
oidcc-client-test-idtoken-sig-none
Incoming HTTP request to /test/a/ArconCI/authorize
|
||||||||||||||||||||||||
|
Authorization endpoint |
2025-04-28 07:51:19 | SUCCESS |
EnsureRequestDoesNotContainRequestObject
Request does not contain a request parameter
|
|
2025-04-28 07:51:19 | SUCCESS |
EnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
|
||||
|
2025-04-28 07:51:19 | SUCCESS |
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
|
||
|
2025-04-28 07:51:19 |
SUCCESS
|
ExtractRequestedScopes
Requested scopes
|
||
|
2025-04-28 07:51:19 | SUCCESS |
ExtractNonceFromAuthorizationRequest
Extracted nonce
|
||
|
2025-04-28 07:51:19 | INFO |
EnsureAuthorizationRequestContainsPkceCodeChallenge
Skipped evaluation due to missing required element: effective_authorization_endpoint_request code_challenge
|
||||||
|
2025-04-28 07:51:19 | SUCCESS |
EnsureResponseTypeIsCode
Response type is expected value
|
||
|
2025-04-28 07:51:19 | SUCCESS |
EnsureMatchingClientId
Client ID matched
|
||
|
2025-04-28 07:51:19 | SUCCESS |
EnsureValidRedirectUriForAuthorizationEndpointRequest
redirect_uri is one of the allowed redirect uris
|
||||
|
2025-04-28 07:51:19 | SUCCESS |
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
|
||||
|
2025-04-28 07:51:19 | SUCCESS |
DisallowMaxAgeEqualsZeroAndPromptNone
The client did not send max_age=0 and prompt=none parameters as expected
|
|
2025-04-28 07:51:19 | INFO |
CheckForUnexpectedClaimsInRequestObject
Skipped evaluation due to missing required element: authorization_request_object claims
|
||||||
|
2025-04-28 07:51:19 | INFO |
CheckForUnexpectedClaimsInClaimsParameter
Skipped evaluation due to missing required element: authorization_request_object claims.claims
|
||||||
|
2025-04-28 07:51:19 | INFO |
CheckForUnexpectedOpenIdClaims
Skipped evaluation due to missing required element: authorization_request_object claims.claims
|
||||||
|
2025-04-28 07:51:19 | INFO |
CheckRequestObjectClaimsParameterValues
Skipped evaluation due to missing required element: authorization_request_object claims.claims
|
||||||
|
2025-04-28 07:51:19 | INFO |
CheckRequestObjectClaimsParameterMemberValues
Skipped evaluation due to missing required element: authorization_request_object claims.claims
|
||||||
|
2025-04-28 07:51:19 |
SUCCESS
|
CreateAuthorizationCode
Created authorization code
|
||
|
2025-04-28 07:51:19 |
SUCCESS
|
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
|
||
|
2025-04-28 07:51:19 | SUCCESS |
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
|
||
|
2025-04-28 07:51:19 |
SendAuthorizationResponseWithResponseModeQuery
Redirecting back to client
|
|||
|
2025-04-28 07:51:19 |
OUTGOING
|
oidcc-client-test-idtoken-sig-none
Response to HTTP request to test instance XzAC0lizZom7Atp
|
||||
|
2025-04-28 07:51:20 |
INCOMING
|
oidcc-client-test-idtoken-sig-none
Incoming HTTP request to /test/a/ArconCI/token
|
||||||||||||||||||||||||
|
Token endpoint |
2025-04-28 07:51:20 |
CheckClientIdMatchesOnTokenRequestIfPresent
client_id not present, nothing to check
|
|
|
2025-04-28 07:51:20 | SUCCESS |
ExtractClientCredentialsFromBasicAuthorizationHeader
Extracted client authentication
|
||||||
|
2025-04-28 07:51:20 | SUCCESS |
ValidateClientIdAndSecret
Client id and secret match
|
|
2025-04-28 07:51:20 | SUCCESS |
ValidateAuthorizationCode
Found authorization code
|
||
|
2025-04-28 07:51:20 | SUCCESS |
ValidateRedirectUriForTokenEndpointRequest
redirect_uri is the same as the one used in the authorization request
|
||
|
2025-04-28 07:51:20 |
SUCCESS
|
GenerateBearerAccessToken
Generated access token
|
||
|
2025-04-28 07:51:20 |
SUCCESS
|
GenerateIdTokenClaims
Created ID Token Claims
|
||||||||||||
|
2025-04-28 07:51:20 | INFO |
AddAtHashToIdTokenClaims
Skipped evaluation due to missing required string: at_hash
|
||
|
2025-04-28 07:51:20 | INFO |
AddAuthTimeToIdTokenClaims
Skipped evaluation due to missing required element: effective_authorization_endpoint_request max_age
|
||||||
|
2025-04-28 07:51:20 |
SUCCESS
|
SignIdTokenWithAlgNone
Created id_token with alg none
|
||
|
2025-04-28 07:51:20 | INFO |
EncryptIdToken
Skipped evaluation due to missing required element: client id_token_encrypted_response_alg
|
||||||
|
2025-04-28 07:51:20 | SUCCESS |
CreateTokenEndpointResponse
Created token endpoint response
|
||||||||
|
2025-04-28 07:51:20 |
OUTGOING
|
oidcc-client-test-idtoken-sig-none
Response to HTTP request to test instance XzAC0lizZom7Atp
|
||||||||
|
2025-04-28 07:51:20 |
INCOMING
|
oidcc-client-test-idtoken-sig-none
Incoming HTTP request to /test/a/ArconCI/jwks
|
||||||||||||||||||||||||
|
Jwks endpoint |
2025-04-28 07:51:20 |
OUTGOING
|
oidcc-client-test-idtoken-sig-none
Response to HTTP request to test instance XzAC0lizZom7Atp
|
||||||||
|
2025-04-28 07:51:25 |
SKIPPED
|
oidcc-client-test-idtoken-sig-none
The test was skipped: Client did not send a userinfo request after receiving an unsigned id_token. As clients are not required to support unsigned (alg: none) id_tokens this is okay.
|
|
2025-04-28 07:51:25 |
FINISHED
|
oidcc-client-test-idtoken-sig-none
Test has run to completion
|
||
|
2025-04-28 07:51:28 |
|
TEST-RUNNER
Alias has now been claimed by another test
|
||||
|