[Openid-specs-ab] Issue #64: OP-UserInfo-SigEnc (Can Provide Signed and Encrypted UserInfo Response) Decryption failure (openid/certification)
Edmund Jay
issues-reply at bitbucket.org
Thu Feb 19 21:48:13 UTC 2015
New issue 64: OP-UserInfo-SigEnc (Can Provide Signed and Encrypted UserInfo Response) Decryption failure
https://bitbucket.org/openid/certification/issue/64/op-userinfo-sigenc-can-provide-signed-and
Edmund Jay:
The test log shows a general decryption failure notice. It would be nice to know specific details or what the test is expecting so that we can narrow down whether it's an OP or RP problem.
```
#!text
Test info
Profile: {'profile': 'CIT', 'sub': 'none', 'register': True, 'discover': True, 'extra': False}
Test ID: OP-UserInfo-SigEnc
Issuer: https://connect.openid4.us
Test output
__RegistrationRequest:post__
[check]
status: INFORMATION
description: Registration Response
info: {"client_id":"RD52Gyp5c3mxi97BIoqClw","client_secret":"BOG35o0fO4jV4g","registration_access_token":"EPje9SX4MGySuQ","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/w4b8t3BIXJRBj43PjV5bIA","client_id_issued_at":1424382127,"client_secret_expires_at":0,"registration_client_uri_path":"w4b8t3BIXJRBj43PjV5bIA","application_type":"web","redirect_uris":["https:\/\/oictest.umdc.umu.se:8102\/authz_cb"],"jwks_uri":"https:\/\/oictest.umdc.umu.se:8102\/export\/jwk_8102.json","subject_type":"public","userinfo_signed_response_alg":"RS256","userinfo_encrypted_response_alg":"RSA1_5","userinfo_encrypted_response_enc":"A128CBC-HS256","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
__AuthorizationRequest:pre__
[check-response-type]
status: OK
description: Checks that the asked for response type are among the supported
[check-endpoint]
status: OK
description: Checks that the necessary endpoint exists at a server
[-]
status: ERROR
info:
Trace output
0.000313 ------------ DiscoveryRequest ------------
0.000329 Provider info discover from 'https://connect.openid4.us/'
0.000337 --> URL: https://connect.openid4.us/.well-known/openid-configuration
0.808669 ProviderConfigurationResponse: {
"authorization_endpoint": "https://connect.openid4.us/abop/op.php/auth",
"check_session_iframe": "https://connect.openid4.us/abop/opframe.php/1",
"claim_types_supported": [
"normal"
],
"claims_locales_supported": [
"en-US"
],
"claims_parameter_supported": true,
"claims_supported": [
"name",
"given_name",
"family_name",
"middle_name",
"nickname",
"preferred_username",
"profile",
"picture",
"website",
"email",
"email_verified",
"gender",
"birthdate",
"zoneinfo",
"locale",
"phone_number",
"phone_number_verified",
"address",
"updated_at"
],
"display_values_supported": [
"page"
],
"end_session_endpoint": "https://connect.openid4.us/abop/op.php/endsession",
"grant_types_supported": [
"authorization_code",
"implicit"
],
"id_token_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"id_token_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"id_token_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"issuer": "https://connect.openid4.us",
"jwks_uri": "https://connect.openid4.us/connect4us.jwk",
"op_policy_uri": "https://connect.openid4.us/abop/op.php/op_policy",
"op_tos_uri": "https://connect.openid4.us/abop/op.php/op_tos",
"registration_endpoint": "https://connect.openid4.us/abop/op.php/registration",
"request_object_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"request_object_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"request_object_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"request_parameter_supported": true,
"request_uri_parameter_supported": true,
"require_request_uri_registration": false,
"response_types_supported": [
"code",
"code token",
"code id_token",
"token",
"token id_token",
"code token id_token",
"id_token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"address",
"phone",
"offline_access"
],
"service_documentation": "https://connect.openid4.us/abop/op.php/servicedocs",
"subject_types_supported": [
"public",
"pairwise"
],
"token_endpoint": "https://connect.openid4.us/abop/op.php/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"client_secret_basic",
"client_secret_jwt",
"private_key_jwt"
],
"token_endpoint_auth_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"ui_locales_supported": [
"en-US"
],
"userinfo_encryption_alg_values_supported": [
"RSA1_5",
"RSA-OAEP"
],
"userinfo_encryption_enc_values_supported": [
"A128CBC-HS256",
"A256CBC-HS512",
"A128GCM",
"A256GCM"
],
"userinfo_endpoint": "https://connect.openid4.us/abop/op.php/userinfo",
"userinfo_signing_alg_values_supported": [
"none",
"HS256",
"HS384",
"HS512",
"RS256",
"RS384",
"RS512"
],
"version": "3.0"
}
1.577756 JWKS: {
"keys": [
{
"e": "AQAB",
"kid": "ABOP-00",
"kty": "RSA",
"n": "tf_sB4M0sHearRLzz1q1JRgRdRnwk0lz-IcVDFlpp2dtDVyA-ZM8Tu1swp7upaTNykf7cp3Ne_6uW3JiKvRMDdNdvHWCzDHmbmZWGdnFF9Ve-D1cUxj4ETVpUM7AIXWbGs34fUNYl3Xzc4baSyvYbc3h6iz8AIdb_1bQLxJsHBi-ydg3NMJItgQJqBiwCmQYCOnJlekR-Ga2a5XlIx46Wsj3Pz0t0dzM8gVSU9fU3QrKKzDFCoFHTgig1YZNNW5W2H6QwANL5h-nbgre5sWmDmdnfiU6Pj5GOQDmp__rweinph8OAFNF6jVqrRZ3QJEmMnO42naWOsxV2FAUXafksQ"
}
]
}
1.578804 ------------ RegistrationRequest ------------
1.579190 --> URL: https://connect.openid4.us/abop/op.php/registration
1.579198 --> BODY: {"subject_type": "public", "jwks_uri": "https://oictest.umdc.umu.se:8102/export/jwk_8102.json", "userinfo_encrypted_response_alg": "RSA1_5", "userinfo_encrypted_response_enc": "A128CBC-HS256", "application_type": "web", "grant_types": ["authorization_code", "implicit"], "userinfo_signed_response_alg": "RS256", "redirect_uris": ["https://oictest.umdc.umu.se:8102/authz_cb"], "response_types": ["code id_token token"], "require_auth_time": true, "scope": ["openid", "profile", "email", "address", "phone"], "default_max_age": 3600}
1.579205 --> HEADERS: {'Content-type': 'application/json'}
2.440673 <-- STATUS: 200
2.440757 <-- BODY: {"client_id":"RD52Gyp5c3mxi97BIoqClw","client_secret":"BOG35o0fO4jV4g","registration_access_token":"EPje9SX4MGySuQ","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/w4b8t3BIXJRBj43PjV5bIA","client_id_issued_at":1424382127,"client_secret_expires_at":0,"registration_client_uri_path":"w4b8t3BIXJRBj43PjV5bIA","application_type":"web","redirect_uris":["https:\/\/oictest.umdc.umu.se:8102\/authz_cb"],"jwks_uri":"https:\/\/oictest.umdc.umu.se:8102\/export\/jwk_8102.json","subject_type":"public","userinfo_signed_response_alg":"RS256","userinfo_encrypted_response_alg":"RSA1_5","userinfo_encrypted_response_enc":"A128CBC-HS256","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
2.441241 RegistrationResponse: {
"application_type": "web",
"client_id": "RD52Gyp5c3mxi97BIoqClw",
"client_id_issued_at": 1424382127,
"client_secret": "BOG35o0fO4jV4g",
"client_secret_expires_at": 0,
"default_max_age": 3600,
"grant_types": [
"authorization_code",
"implicit"
],
"jwks_uri": "https://oictest.umdc.umu.se:8102/export/jwk_8102.json",
"redirect_uris": [
"https://oictest.umdc.umu.se:8102/authz_cb"
],
"registration_access_token": "EPje9SX4MGySuQ",
"registration_client_uri": "https://connect.openid4.us/abop/op.php/client/w4b8t3BIXJRBj43PjV5bIA",
"registration_client_uri_path": "w4b8t3BIXJRBj43PjV5bIA",
"require_auth_time": true,
"response_types": [
"code id_token token"
],
"subject_type": "public",
"userinfo_encrypted_response_alg": "RSA1_5",
"userinfo_encrypted_response_enc": "A128CBC-HS256",
"userinfo_signed_response_alg": "RS256"
}
2.442378 ------------ AuthorizationRequest ------------
2.442630 --> URL: https://connect.openid4.us/abop/op.php/auth?nonce=ZLrbyFX60UnR&state=mK4esGpQUo3BSk2U&redirect_uri=https%3A%2F%2Foictest.umdc.umu.se%3A8102%2Fauthz_cb&response_type=code+id_token+token&client_id=RD52Gyp5c3mxi97BIoqClw&scope=openid
2.442636 --> BODY: None
6.121955 <-- state=mK4esGpQUo3BSk2U&access_token=IUIiVKwSIl-rpE8Oz7TdV9pRdrMvJtb39lTfbk6cac0&token_type=Bearer&expires_in=3600&id_token=eyJhbGciOiJSUzI1NiIsImprdSI6Imh0dHBzOlwvXC9jb25uZWN0Lm9wZW5pZDQudXNcL2Nvbm5lY3Q0dXMuandrIiwia2lkIjoiQUJPUC0wMCJ9.eyJpc3MiOiJodHRwczpcL1wvY29ubmVjdC5vcGVuaWQ0LnVzIiwic3ViIjoiYWxpY2UiLCJhdWQiOlsiUkQ1Mkd5cDVjM214aTk3QklvcUNsdyJdLCJleHAiOjE0MjQzODI0MjksImlhdCI6MTQyNDM4MjEyOSwibm9uY2UiOiJaTHJieUZYNjBVblIiLCJhdXRoX3RpbWUiOjE0MjQzODE2OTksImNfaGFzaCI6ImRyYlg4eWRFWXc2aHdBd1Z2RC1HZXciLCJhdF9oYXNoIjoiUUptejhtUTRDQThYd19kcFpXU19mdyJ9.fjaUOGJ1rRBvvdhO6MSTvDf0sXn7mQazkN9nvJJQjgefAAwwTuK-spCZuMTDPcRx7IZWeMi7CiTXR875DJsgxO80UPhJMWPdY7HAoWFCaw764SkE2n3_fCzfBiBdsM3Ms9Mj-fSXo5Pv43V2llCX7oS9APlRERtCooBqXaxZlh6zGy4GLOia1OdkLhtFV6yZeziPh1En048_xx6vgF_UNcqGIK5VIpaWgmy75PPpjAj0F0i9G4Th2xCnTO7E3sH-wPh5FngQlX4d-Pk9c0kSpY4JCCPjkDRv7O0vYPLwAxlV2xHTFp3HSC7h2q4drXM7HHElP-F31L4HvLBHYveOEQ&session_state=976ae08080e3c4ed84766523095fa2d0ddfef9f79092c61f1bd52600923c074c.192630
4213b478377660c30395f0ddaa&code=GawnWUp3OYrBMHVtBQMtbRD7A4fs7km8W7Vgaoq9YJI
6.871910 AuthorizationResponse: {
"access_token": "IUIiVKwSIl-rpE8Oz7TdV9pRdrMvJtb39lTfbk6cac0",
"code": "GawnWUp3OYrBMHVtBQMtbRD7A4fs7km8W7Vgaoq9YJI",
"expires_in": 3600,
"id_token": {
"at_hash": "QJmz8mQ4CA8Xw_dpZWS_fw",
"aud": [
"RD52Gyp5c3mxi97BIoqClw"
],
"auth_time": 1424381699,
"c_hash": "drbX8ydEYw6hwAwVvD-Gew",
"exp": 1424382429,
"iat": 1424382129,
"iss": "https://connect.openid4.us",
"nonce": "ZLrbyFX60UnR",
"sub": "alice"
},
"session_state": "976ae08080e3c4ed84766523095fa2d0ddfef9f79092c61f1bd52600923c074c.1926304213b478377660c30395f0ddaa",
"state": "mK4esGpQUo3BSk2U",
"token_type": "Bearer"
}
6.872217 ------------ AccessTokenRequest ------------
6.872493 --> URL: https://connect.openid4.us/abop/op.php/token
6.872497 --> BODY: code=GawnWUp3OYrBMHVtBQMtbRD7A4fs7km8W7Vgaoq9YJI&grant_type=authorization_code&redirect_uri=https%3A%2F%2Foictest.umdc.umu.se%3A8102%2Fauthz_cb
6.872503 --> HEADERS: {'Content-type': 'application/x-www-form-urlencoded', 'Authorization': 'Basic UkQ1Mkd5cDVjM214aTk3QklvcUNsdzpCT0czNW8wZk80alY0Zw=='}
7.729610 <-- STATUS: 200
7.729682 <-- BODY: {"access_token":"XVXmy4HGycBvTLzYkXEckExBwUMqOEafLb7s8Uf5QBY","token_type":"Bearer","expires_in":3600,"id_token":"eyJhbGciOiJSUzI1NiIsImprdSI6Imh0dHBzOlwvXC9jb25uZWN0Lm9wZW5pZDQudXNcL2Nvbm5lY3Q0dXMuandrIiwia2lkIjoiQUJPUC0wMCJ9.eyJpc3MiOiJodHRwczpcL1wvY29ubmVjdC5vcGVuaWQ0LnVzIiwic3ViIjoiYWxpY2UiLCJhdWQiOlsiUkQ1Mkd5cDVjM214aTk3QklvcUNsdyJdLCJleHAiOjE0MjQzODI0MzIsImlhdCI6MTQyNDM4MjEzMiwibm9uY2UiOiJaTHJieUZYNjBVblIiLCJhdXRoX3RpbWUiOjE0MjQzODE2OTl9.Kxd-qVzhAQTMnpeuJO93aA4-w1HngCCjhcybN7DvT26BknOaY3T0lpWtpQNjsQXZiOcCXvcUuDudR0ZEUqUyG40R5GLd19u5OGjDkxnaMaiXWbtEIg6gqYBjfUhsHa6F2CGvdH5kEBPc5qJr_fIWaNuTtWOggQkVacDslD_75tHYDnZVEX_9yVgSiVxOKyGq3CStGrpa46hwyth6Q1PXIzQUzaXNIxSSlC5g8QgC82dPucANZOcRdMkCd1woHoVqNm6PxhjfwYuHh_b3GLApP1ScwN0RvM2NXaGXIbiKU3IRjZHSStbfkFQs4ejzyxuMfyhwK0mkxs6W3RYsy-6Iqw"}
7.731599 IdToken JWT header: {u'alg': u'RS256', u'kid': u'ABOP-00', u'jku': u'https://connect.openid4.us/connect4us.jwk'}
7.731608 AccessTokenResponse: {
"access_token": "XVXmy4HGycBvTLzYkXEckExBwUMqOEafLb7s8Uf5QBY",
"expires_in": 3600,
"id_token": {
"aud": [
"RD52Gyp5c3mxi97BIoqClw"
],
"auth_time": 1424381699,
"exp": 1424382432,
"iat": 1424382132,
"iss": "https://connect.openid4.us",
"nonce": "ZLrbyFX60UnR",
"sub": "alice"
},
"token_type": "Bearer"
}
7.732452 ------------ UserInfoRequest ------------
7.732781 --> URL: https://connect.openid4.us/abop/op.php/userinfo
7.732785 --> BODY: None
7.732792 --> HEADERS: {'Authorization': u'Bearer XVXmy4HGycBvTLzYkXEckExBwUMqOEafLb7s8Uf5QBY'}
9.584022 <-- STATUS: 200
9.584148 <-- BODY: eyJhbGciOiJSU0ExXzUiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwiamt1IjoiaHR0cHM6XC9cL29pY3Rlc3QudW1kYy51bXUuc2U6ODEwMlwvZXhwb3J0XC9qd2tfODEwMi5qc29uIiwia2lkIjoiYTAifQ.Y1ndkWrLUKE-cWxOXqSPcI737KcSiJfS-Mfs13RGFPH1OWr2MXZ82K3ioCIysxpRfM_aa18o_FZi2IR3tdqTBWNzveEC4J2htZtdoQD7Li5kyZTSr1KSZcma6eamb_feDxkwIQu5SUzSDq2QLs_YDPQcbD_0MfyhshubF_6z6TX8e4Rhy2qQY9f9Epk6QfxMcAma5nkK9BwPXnwDthCKkeKzuwUMo9v6Pg3eicGi0n8Zod-WeX3pGUbAs0ucLa9lNxwbhqq9jE41Rm0Bxc-xCJbkUSlXB85on6-WxfbSTB01SDw67_JMZtA_8_r_Rt87z2f2cfG9TYVTCxfXyWq46Q.9ra8frNcqFUS0GsI4z1rJA.wYGCzNwj6Uc1ItyJdgnPyuLyW1IW7CBKuuCVB0JHmcuXMTjtU7KsG5LZv4wD2HmjHiPUeD9ctMJ204bCsSW-MlsUyX0O23IOiXsX9MnAAKToK-FvG7_6KObOfmEcyeAIm4gIXD0anApiUinv4vR1sYZV7ZKQk3DeKFxxZNnhfW0hhUIN7RZ_rcWOjt6o5qCNNQkO_BpCiiir5Gxxcu35LqOWfPjM-m9HT8B2396yldxxktf79hM8znxaRcWv3ZyFKaIQ9N7pJGsbjrjz__hGk1pS2OkO6-bujMq70n_VrvvZrK8lEBggIu2JboX3phDMyFrDaZ-s3erJ3Q2RZYvnm50hSi3k685n0vSSzxdqtFkH9lfNOGf824x1QoaS1lN7h7XfKaUhODWhJQ0D9_TIS8T5ly-F6drzpwEsifeOwzW3PgN3vZm6rK_kXbZnzHoooU
aUlvdj5G26BHQgzWpUb9qVFFVZxEmaekxR5rBntDF2bnhU89FO3NNqEXjOVXeP1pJjDxfyzejyJpxafl-Lcux07f3zxb9skvm9wqBHKwoFJeLzxbocpnVPTOek9UTYgRvrEom031a7uVLG0dDYXRj9vGjZKovzXqlSwvgHDKgaNL2_s-KYPBZeBEZK9Uvj.GcPWbDCcNZECuMPkSqWXXg
9.597596 [ERROR] DecryptionFailed:
Result
FAILED
```
More information about the Openid-specs-ab
mailing list