[Openid-specs-ab] Issue #63: OP-IDToken-c_hash (D Token has c_hash when ID Token and Authorization Code returned from Authorization Endpoint) Unable to verify c_hash (openid/certification)
Edmund Jay
issues-reply at bitbucket.org
Thu Feb 19 21:41:24 UTC 2015
New issue 63: OP-IDToken-c_hash (D Token has c_hash when ID Token and Authorization Code returned from Authorization Endpoint) Unable to verify c_hash
https://bitbucket.org/openid/certification/issue/63/op-idtoken-c_hash-d-token-has-c_hash-when
Edmund Jay:
The test log shows that that it can't find the the check for c_hash
```
#!text
Test info
Profile: {'profile': 'CIT', 'sub': 'none', 'register': True, 'discover': True, 'extra': False}
Test ID: OP-IDToken-c_hash
Issuer: https://connect.openid4.us
Test output
__RegistrationRequest:post__
[check]
status: INFORMATION
description: Registration Response
info: {"client_id":"t9VnqznZHWQJjzcJTjD9ew","client_secret":"-l97gIX989qrPA","registration_access_token":"Wf9-uv_SGO4zXA","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/fMaP-xjLX7glW5yu3BJVGA","client_id_issued_at":1424381744,"client_secret_expires_at":0,"registration_client_uri_path":"fMaP-xjLX7glW5yu3BJVGA","application_type":"web","redirect_uris":["https:\/\/oictest.umdc.umu.se:8102\/authz_cb"],"jwks_uri":"https:\/\/oictest.umdc.umu.se:8102\/export\/jwk_8102.json","subject_type":"public","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
__AuthorizationRequest:pre__
[check-response-type]
status: OK
description: Checks that the asked for response type are among the supported
[check-endpoint]
status: OK
description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[check-http-response]
status: OK
description: Checks that the HTTP response status is within the 200 or 300 range
[-]
status: ERROR
info: Couldn't find the check: 'verify-chash'
Trace output
0.000586 ------------ DiscoveryRequest ------------
0.000593 Provider info discover from 'https://connect.openid4.us/'
0.000598 --> URL: https://connect.openid4.us/.well-known/openid-configuration
0.806657 ProviderConfigurationResponse: {
"authorization_endpoint": "https://connect.openid4.us/abop/op.php/auth",
"check_session_iframe": "https://connect.openid4.us/abop/opframe.php/1",
"claim_types_supported": [
"normal"
],
"claims_locales_supported": [
"en-US"
],
"claims_parameter_supported": true,
"claims_supported": [
"name",
"given_name",
"family_name",
"middle_name",
"nickname",
"preferred_username",
"profile",
"picture",
"website",
"email",
"email_verified",
"gender",
"birthdate",
"zoneinfo",
"locale",
"phone_number",
"phone_number_verified",
"address",
"updated_at"
],
"display_values_supported": [
"page"
],
"end_session_endpoint": "https://connect.openid4.us/abop/op.php/endsession",
"grant_types_supported": [
"authorization_code",
"implicit"
],
"id_token_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"id_token_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"id_token_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"issuer": "https://connect.openid4.us",
"jwks_uri": "https://connect.openid4.us/connect4us.jwk",
"op_policy_uri": "https://connect.openid4.us/abop/op.php/op_policy",
"op_tos_uri": "https://connect.openid4.us/abop/op.php/op_tos",
"registration_endpoint": "https://connect.openid4.us/abop/op.php/registration",
"request_object_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"request_object_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"request_object_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"request_parameter_supported": true,
"request_uri_parameter_supported": true,
"require_request_uri_registration": false,
"response_types_supported": [
"code",
"code token",
"code id_token",
"token",
"token id_token",
"code token id_token",
"id_token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"address",
"phone",
"offline_access"
],
"service_documentation": "https://connect.openid4.us/abop/op.php/servicedocs",
"subject_types_supported": [
"public",
"pairwise"
],
"token_endpoint": "https://connect.openid4.us/abop/op.php/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"client_secret_basic",
"client_secret_jwt",
"private_key_jwt"
],
"token_endpoint_auth_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"ui_locales_supported": [
"en-US"
],
"userinfo_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"userinfo_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"userinfo_endpoint": "https://connect.openid4.us/abop/op.php/userinfo",
"userinfo_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"version": "3.0"
}
1.556268 JWKS: {
"keys": [
{
"e": "AQAB",
"kid": "ABOP-00",
"kty": "RSA",
"n": "tf_sB4M0sHearRLzz1q1JRgRdRnwk0lz-IcVDFlpp2dtDVyA-ZM8Tu1swp7upaTNykf7cp3Ne_6uW3JiKvRMDdNdvHWCzDHmbmZWGdnFF9Ve-D1cUxj4ETVpUM7AIXWbGs34fUNYl3Xzc4baSyvYbc3h6iz8AIdb_1bQLxJsHBi-ydg3NMJItgQJqBiwCmQYCOnJlekR-Ga2a5XlIx46Wsj3Pz0t0dzM8gVSU9fU3QrKKzDFCoFHTgig1YZNNW5W2H6QwANL5h-nbgre5sWmDmdnfiU6Pj5GOQDmp__rweinph8OAFNF6jVqrRZ3QJEmMnO42naWOsxV2FAUXafksQ"
}
]
}
1.557056 ------------ RegistrationRequest ------------
1.557472 --> URL: https://connect.openid4.us/abop/op.php/registration
1.557478 --> BODY: {"subject_type": "public", "jwks_uri": "https://oictest.umdc.umu.se:8102/export/jwk_8102.json", "application_type": "web", "grant_types": ["authorization_code", "implicit"], "redirect_uris": ["https://oictest.umdc.umu.se:8102/authz_cb"], "response_types": ["code id_token token"], "require_auth_time": true, "scope": ["openid", "profile", "email", "address", "phone"], "default_max_age": 3600}
1.557516 --> HEADERS: {'Content-type': 'application/json'}
2.420268 <-- STATUS: 200
2.420335 <-- BODY: {"client_id":"t9VnqznZHWQJjzcJTjD9ew","client_secret":"-l97gIX989qrPA","registration_access_token":"Wf9-uv_SGO4zXA","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/fMaP-xjLX7glW5yu3BJVGA","client_id_issued_at":1424381744,"client_secret_expires_at":0,"registration_client_uri_path":"fMaP-xjLX7glW5yu3BJVGA","application_type":"web","redirect_uris":["https:\/\/oictest.umdc.umu.se:8102\/authz_cb"],"jwks_uri":"https:\/\/oictest.umdc.umu.se:8102\/export\/jwk_8102.json","subject_type":"public","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
2.420781 RegistrationResponse: {
"application_type": "web",
"client_id": "t9VnqznZHWQJjzcJTjD9ew",
"client_id_issued_at": 1424381744,
"client_secret": "-l97gIX989qrPA",
"client_secret_expires_at": 0,
"default_max_age": 3600,
"grant_types": [
"authorization_code",
"implicit"
],
"jwks_uri": "https://oictest.umdc.umu.se:8102/export/jwk_8102.json",
"redirect_uris": [
"https://oictest.umdc.umu.se:8102/authz_cb"
],
"registration_access_token": "Wf9-uv_SGO4zXA",
"registration_client_uri": "https://connect.openid4.us/abop/op.php/client/fMaP-xjLX7glW5yu3BJVGA",
"registration_client_uri_path": "fMaP-xjLX7glW5yu3BJVGA",
"require_auth_time": true,
"response_types": [
"code id_token token"
],
"subject_type": "public"
}
2.421786 ------------ AuthorizationRequest ------------
2.422057 --> URL: https://connect.openid4.us/abop/op.php/auth?nonce=bVZQDuEzrqHm&state=sNH1Jr4dTUxB4fLf&redirect_uri=https%3A%2F%2Foictest.umdc.umu.se%3A8102%2Fauthz_cb&response_type=code+id_token+token&client_id=t9VnqznZHWQJjzcJTjD9ew&scope=openid
2.422062 --> BODY: None
5.354467 <-- state=sNH1Jr4dTUxB4fLf&access_token=4Swhj51E01q_MwLQVBy_Q68vKxD06giTZwDSgcGLpks&token_type=Bearer&expires_in=3600&id_token=eyJhbGciOiJSUzI1NiIsImprdSI6Imh0dHBzOlwvXC9jb25uZWN0Lm9wZW5pZDQudXNcL2Nvbm5lY3Q0dXMuandrIiwia2lkIjoiQUJPUC0wMCJ9.eyJpc3MiOiJodHRwczpcL1wvY29ubmVjdC5vcGVuaWQ0LnVzIiwic3ViIjoiYWxpY2UiLCJhdWQiOlsidDlWbnF6blpIV1FKanpjSlRqRDlldyJdLCJleHAiOjE0MjQzODIwNDYsImlhdCI6MTQyNDM4MTc0Niwibm9uY2UiOiJiVlpRRHVFenJxSG0iLCJhdXRoX3RpbWUiOjE0MjQzODE2OTksImNfaGFzaCI6IlhKRmdBOHUtNU10TFBRd2FxYUhfZUEiLCJhdF9oYXNoIjoiWm14ZklyMmlkQjE3RUozVHJHemxLUSJ9.ElmnwwQXPhKeV6um-_LZxTuHwJmmFu3ZVNP2NE64Yc3TpYQ-lZD0kjhZFnCMdOLFo3S9LUkRf_YvkJFZm4rg4UaXS_dwa4zgpGIPFUQKvJ-gb9LnjpXNuBM7-fw23WUZNBzU4nraeR_I4Yfwq0Txamx78EkpgtmFIvqm5SNO5LJoU-FMVvW4ksuEZd3Jwd5zRUnX-smuqMsoD5Jzm6kUezmWnwpTL2_djeYxgUkyuDZtjywJ8ormSh6RDK_SBurFRDprPOmK740XIztLx43_OcqY05q6z070VKYZtht_YgPDHOzdQ58r601xdXw4EXiuLhX-_SecdHKQVc9gVTTozA&session_state=c84b4283ff79a1ed59d6997ba4566e6dadc4a0467d6dbaef25ac75b0ec628df8.9e0106
af4459130c22eb102a0bd304d3&code=6Fp4OLlXrJtovFcgMixlVbi81oTB-ARDvebz4hc4xsU
6.125822 AuthorizationResponse: {
"access_token": "4Swhj51E01q_MwLQVBy_Q68vKxD06giTZwDSgcGLpks",
"code": "6Fp4OLlXrJtovFcgMixlVbi81oTB-ARDvebz4hc4xsU",
"expires_in": 3600,
"id_token": {
"at_hash": "ZmxfIr2idB17EJ3TrGzlKQ",
"aud": [
"t9VnqznZHWQJjzcJTjD9ew"
],
"auth_time": 1424381699,
"c_hash": "XJFgA8u-5MtLPQwaqaH_eA",
"exp": 1424382046,
"iat": 1424381746,
"iss": "https://connect.openid4.us",
"nonce": "bVZQDuEzrqHm",
"sub": "alice"
},
"session_state": "c84b4283ff79a1ed59d6997ba4566e6dadc4a0467d6dbaef25ac75b0ec628df8.9e0106af4459130c22eb102a0bd304d3",
"state": "sNH1Jr4dTUxB4fLf",
"token_type": "Bearer"
}
6.127230 [ERROR] Unknown:Couldn't find the check: 'verify-chash'
Result
FAILED
```
More information about the Openid-specs-ab
mailing list