[Openid-specs-ab] Issue #111: OP-IDToken-SigEnc (Signed and encrypted ID Token) Test is unable to decrypt ID Token for certain response_type requests (openid/certification)

Edmund Jay issues-reply at bitbucket.org
Thu Mar 19 20:36:43 UTC 2015


New issue 111: OP-IDToken-SigEnc (Signed and encrypted ID Token) Test is unable to decrypt ID Token for certain response_type requests
https://bitbucket.org/openid/certification/issue/111/op-idtoken-sigenc-signed-and-encrypted-id

Edmund Jay:

The test is unable to decrypt the returned ID Token when authentication request response_type is the following :

code id_token
code id_token token


```
#!text

Test info

Profile: {'openid-configuration': 'config', 'extras': True, 'response_type': 'code+id_token+token', 'crypto': 'encrypt+sign', 'registration': 'dynamic'}
Test description: Signed and encrypted ID Token [Extra]
Test ID: OP-IDToken-SigEnc
Issuer: https://connect.openid4.us
Test output


__RegistrationRequest:post__
[check]
	status: INFORMATION
	description: Registration Response
	info: {"client_id":"lsQ586bP4hClaEweukk2Xw","client_secret":"ov6nmZkVCcrAWQ","registration_access_token":"uy2EqubSA3aTyA","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/1nI65i1ZpqLDPWliK3zRKQ","client_id_issued_at":1426797152,"client_secret_expires_at":0,"contacts":["roland.hedberg at umu.se"],"application_type":"web","redirect_uris":["https:\/\/op.certification.openid.net:60103\/authz_cb"],"post_logout_redirect_uris":["https:\/\/op.certification.openid.net:60103\/logout"],"jwks_uri":"https:\/\/op.certification.openid.net:60103\/export\/jwk_60103.json","subject_type":"pairwise","id_token_signed_response_alg":"RS256","id_token_encrypted_response_alg":"RSA1_5","id_token_encrypted_response_enc":"A128CBC-HS256","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
__AuthorizationRequest:pre__
[check-response-type]
	status: OK
	description: Checks that the asked for response type are among the supported
[check-endpoint]
	status: OK
	description: Checks that the necessary endpoint exists at a server
[-]
	status: ERROR
	info: No suitable verification keys found
Trace output


0.000277 ------------ DiscoveryRequest ------------
0.000288 Provider info discover from 'https://connect.openid4.us'
0.000293 --> URL: https://connect.openid4.us/.well-known/openid-configuration
0.392640 ProviderConfigurationResponse: {
  "authorization_endpoint": "https://connect.openid4.us/abop/op.php/auth",
  "check_session_iframe": "https://connect.openid4.us/abop/opframe.php/1",
  "claim_types_supported": [
    "normal"
  ],
  "claims_locales_supported": [
    "en-US"
  ],
  "claims_parameter_supported": true,
  "claims_supported": [
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "preferred_username",
    "profile",
    "picture",
    "website",
    "email",
    "email_verified",
    "gender",
    "birthdate",
    "zoneinfo",
    "locale",
    "phone_number",
    "phone_number_verified",
    "address",
    "updated_at"
  ],
  "display_values_supported": [
    "page"
  ],
  "end_session_endpoint": "https://connect.openid4.us/abop/op.php/endsession",
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "id_token_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "issuer": "https://connect.openid4.us",
  "jwks_uri": "https://connect.openid4.us/connect4us.jwk",
  "op_policy_uri": "https://connect.openid4.us/abop/op.php/op_policy",
  "op_tos_uri": "https://connect.openid4.us/abop/op.php/op_tos",
  "registration_endpoint": "https://connect.openid4.us/abop/op.php/registration",
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "request_parameter_supported": true,
  "request_uri_parameter_supported": true,
  "require_request_uri_registration": false,
  "response_types_supported": [
    "code",
    "code token",
    "code id_token",
    "token",
    "token id_token",
    "code token id_token",
    "id_token"
  ],
  "scopes_supported": [
    "openid",
    "profile",
    "email",
    "address",
    "phone",
    "offline_access"
  ],
  "service_documentation": "https://connect.openid4.us/abop/op.php/servicedocs",
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "token_endpoint": "https://connect.openid4.us/abop/op.php/token",
  "token_endpoint_auth_methods_supported": [
    "client_secret_post",
    "client_secret_basic",
    "client_secret_jwt",
    "private_key_jwt"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "ui_locales_supported": [
    "en-US"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "userinfo_endpoint": "https://connect.openid4.us/abop/op.php/userinfo",
  "userinfo_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "version": "3.0"
}
0.687089 JWKS: {
  "keys": [
    {
      "e": "AQAB",
      "kid": "ABOP-00",
      "kty": "RSA",
      "n": "tf_sB4M0sHearRLzz1q1JRgRdRnwk0lz-IcVDFlpp2dtDVyA-ZM8Tu1swp7upaTNykf7cp3Ne_6uW3JiKvRMDdNdvHWCzDHmbmZWGdnFF9Ve-D1cUxj4ETVpUM7AIXWbGs34fUNYl3Xzc4baSyvYbc3h6iz8AIdb_1bQLxJsHBi-ydg3NMJItgQJqBiwCmQYCOnJlekR-Ga2a5XlIx46Wsj3Pz0t0dzM8gVSU9fU3QrKKzDFCoFHTgig1YZNNW5W2H6QwANL5h-nbgre5sWmDmdnfiU6Pj5GOQDmp__rweinph8OAFNF6jVqrRZ3QJEmMnO42naWOsxV2FAUXafksQ"
    }
  ]
}
0.687965 ------------ RegistrationRequest ------------
0.688339 --> URL: https://connect.openid4.us/abop/op.php/registration
0.688346 --> BODY: {"subject_type": "pairwise", "jwks_uri": "https://op.certification.openid.net:60103/export/jwk_60103.json", "contacts": ["roland.hedberg at umu.se"], "application_type": "web", "grant_types": ["authorization_code", "implicit"], "post_logout_redirect_uris": ["https://op.certification.openid.net:60103/logout"], "redirect_uris": ["https://op.certification.openid.net:60103/authz_cb"], "response_types": ["code id_token token"], "require_auth_time": true, "id_token_encrypted_response_alg": "RSA1_5", "default_max_age": 3600, "id_token_encrypted_response_enc": "A128CBC-HS256", "id_token_signed_response_alg": "RS256"}
0.688355 --> HEADERS: {'Content-type': 'application/json'}
1.126182 <-- STATUS: 200
1.126294 <-- BODY: {"client_id":"lsQ586bP4hClaEweukk2Xw","client_secret":"ov6nmZkVCcrAWQ","registration_access_token":"uy2EqubSA3aTyA","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/1nI65i1ZpqLDPWliK3zRKQ","client_id_issued_at":1426797152,"client_secret_expires_at":0,"contacts":["roland.hedberg at umu.se"],"application_type":"web","redirect_uris":["https:\/\/op.certification.openid.net:60103\/authz_cb"],"post_logout_redirect_uris":["https:\/\/op.certification.openid.net:60103\/logout"],"jwks_uri":"https:\/\/op.certification.openid.net:60103\/export\/jwk_60103.json","subject_type":"pairwise","id_token_signed_response_alg":"RS256","id_token_encrypted_response_alg":"RSA1_5","id_token_encrypted_response_enc":"A128CBC-HS256","default_max_age":3600,"require_auth_time":true,"response_types":["code id_token token"],"grant_types":["authorization_code","implicit"]}
1.127051 RegistrationResponse: {
  "application_type": "web",
  "client_id": "lsQ586bP4hClaEweukk2Xw",
  "client_id_issued_at": 1426797152,
  "client_secret": "ov6nmZkVCcrAWQ",
  "client_secret_expires_at": 0,
  "contacts": [
    "roland.hedberg at umu.se"
  ],
  "default_max_age": 3600,
  "grant_types": [
    "authorization_code",
    "implicit"
  ],
  "id_token_encrypted_response_alg": "RSA1_5",
  "id_token_encrypted_response_enc": "A128CBC-HS256",
  "id_token_signed_response_alg": "RS256",
  "jwks_uri": "https://op.certification.openid.net:60103/export/jwk_60103.json",
  "post_logout_redirect_uris": [
    "https://op.certification.openid.net:60103/logout"
  ],
  "redirect_uris": [
    "https://op.certification.openid.net:60103/authz_cb"
  ],
  "registration_access_token": "uy2EqubSA3aTyA",
  "registration_client_uri": "https://connect.openid4.us/abop/op.php/client/1nI65i1ZpqLDPWliK3zRKQ",
  "require_auth_time": true,
  "response_types": [
    "code id_token token"
  ],
  "subject_type": "pairwise"
}
1.128629 ------------ AuthorizationRequest ------------
1.129045 --> URL: https://connect.openid4.us/abop/op.php/auth?nonce=bfZenj6BBBSZ&state=1YIXyrfSOJ7lvIx5&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60103%2Fauthz_cb&response_type=code+id_token+token&client_id=lsQ586bP4hClaEweukk2Xw&scope=openid
1.129053 --> BODY: None
3.379834 QUERY_STRING:
4.163024 <-- state=1YIXyrfSOJ7lvIx5&access_token=-pll6bVUJFcvtDt6T6P1ydQ8PfSB79FUk75CerrijI0&token_type=Bearer&expires_in=3600&id_token=eyJhbGciOiJSU0ExXzUiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwiamt1IjoiaHR0cHM6XC9cL29wLmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldDo2MDEwM1wvZXhwb3J0XC9qd2tfNjAxMDMuanNvbiIsImtpZCI6ImEwIn0.cR4vXqqYJPv_jYDs8CiaNmPGfL7bRQUFOHluAdiVfUnI7Ymf2uJ5t48I5IuX-Y6q_MhtdUjZ_CsSy6agiogjstIrHvF6Voirbd1jRMqLf5fCLpFLOfAkoHsQIC9Fp9xx8Aq1VB_D64u031YaFJQqLOPZn0sZSzJsI8vgCWosgFEQFTJbH6AvyVPdTC3R5vDmy7_UM6A6Gy8D_arAFPIc24-n64Ik81LV-1TnSG2M3kI7SGmvvxY4IaD3N2YpLLqpsGL5dmfn_3dzDkROeO4kvvp-puufFq4cChe0Q9H3GsafhKBHAHTsrOehozgljd-l8ffhaMdxc6JGawhsooQCpA.ZqcbQp1V_pfx81FAtBXySA.Eze_GtuMOnVMt18Ep3HP_tdT3McR59g-2FTPnPRY5cqpnktBHrXIstnF-BMiKQK75co9HMl8IJt-VCqaoe4zbmg0e3rx2SIqqoyj7iunajWzgRmxMGeoGFdn-2_xTKFS9cNruSRyhrAEipBYqk7r_JFWd2-JzXhljZ4qDVSqxzB5HkkiiqakeNzroI4t9hUGdiE9k8vC_ucx0cWZWRUD8_PUcQvPQIoYGPjq3KO2KE4h_sxpNvANcn6TbRl4skTDTQdp8o03ZbROxLRoCVv0UuY-neU47lsqSh-UN0N78WK5BdmM6Lm2V_-H6SEEKto3
 b8FEzG7it02SXI6jpIb51zHAkyo1lLdifC8XQHYdgKLIKEDcZkyXW1QGXLDh9BRxptmts1GudtjEWxRHz1FjfcIncx22a3jZXPnOD4Z-FZ2mFe2a5gBjaDJHlww6Dl9EWb_w-5VgQpROvSE7eJ0wSM5xJOmLioGpeBhRBWjUFcfZ7eiG3JhmpTj3hSNxjLrsFtYMIMQErcjSIfRsCXycNloi29GOu1qxaVp-HDzrb754GYDHqXRMkvrRqkSOPLQmQzjF7uuzsbT3teNBCDriMDdCq1Z48NbnbLA9Ywqki07xZSfA89_fvDXG_e1EP4I2pvENqxk6rz8LfaZQj0MpB8zU0DVbHQHBZxpqvBZ8R6mm5jPff6bwsZw7N-ZSyXE9_OgNRu7AVVrVk-3ohBSnsWLwu75TQf_2JMYvs9JKtXXUOxIZRmrCRBtN62PYPIgev0Is1q56nd1WxZXE5Jdavfr8hISB3Jplz_-JlfIvVuqn3DpTwMsLFDJU4EWAK11OkGzWye1MvRxA4Mhei_SwDh6YJoQ1j3HMbBbUFoQNiXmx3eNAfP59vx6X8K6kZjcrCPnIa8iTZzltdA2rP4KkJjJ8WBI4nmYR2rWOqDzTy9sd_7HbEjFEsZwEf4O4zMaPqc_Nb3u_J3AfV7gVHQ5huTqc-UCwwZz03i9oOs3DevObk9AKSDYMpfzpmor2YPoYARECioj1pscngYc_HH-QgOY6-eLmJK929PGN7yrWq_NJAfOPRv85xisaoCz1NOYS9OB1Ef3Dbdsk5BdYfl-pbZ-EOhzybqeOVebVE5uAT4I.u1CXJItksMg4JKMnJixZPw&session_state=4ac2b9617cbb2282ddb0be5c69793e33806e164e67001f61f20cdc2220dede6c.991df293dfe571b3a10bfed74cab5749&code=fIvSgooay2tAxf9O3SlHfTLcGgxAIx675N7l2
 8mKCCE
4.498137 AuthorizationResponse: {
  "access_token": "-pll6bVUJFcvtDt6T6P1ydQ8PfSB79FUk75CerrijI0",
  "code": "fIvSgooay2tAxf9O3SlHfTLcGgxAIx675N7l28mKCCE",
  "expires_in": 3600,
  "id_token": {
    "claims": {
      "at_hash": "wb5DEA70-dbUVxOJT1V5zw",
      "aud": [
        "lsQ586bP4hClaEweukk2Xw"
      ],
      "auth_time": 1426795020,
      "c_hash": "3ARo5R4w5hYWVmOBDi3o9A",
      "exp": 1426797454,
      "iat": 1426797154,
      "iss": "https://connect.openid4.us",
      "nonce": "bfZenj6BBBSZ",
      "sub": "08168380e7545ea909d82cb017d721feafe378670a79f93357da5715c0dbf52d"
    },
    "jwe header parameters": {
      "alg": "RSA1_5",
      "enc": "A128CBC-HS256",
      "jku": "https://op.certification.openid.net:60103/export/jwk_60103.json",
      "kid": "a0"
    },
    "jws header parameters": {
      "alg": "RS256",
      "jku": "https://connect.openid4.us/connect4us.jwk",
      "kid": "ABOP-00"
    }
  },
  "session_state": "4ac2b9617cbb2282ddb0be5c69793e33806e164e67001f61f20cdc2220dede6c.991df293dfe571b3a10bfed74cab5749",
  "state": "1YIXyrfSOJ7lvIx5",
  "token_type": "Bearer"
}
4.498789 ------------ AccessTokenRequest ------------
4.499204 --> URL: https://connect.openid4.us/abop/op.php/token
4.499211 --> BODY: code=fIvSgooay2tAxf9O3SlHfTLcGgxAIx675N7l28mKCCE&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60103%2Fauthz_cb
4.499221 --> HEADERS: {'Content-type': 'application/x-www-form-urlencoded', 'Authorization': 'Basic bHNRNTg2YlA0aENsYUV3ZXVrazJYdzpvdjZubVprVkNjckFXUQ=='}
5.329000 <-- STATUS: 200
5.329135 <-- BODY: {"access_token":"L1TpM0nAB2T-NgF2J_3V4X7JoYDBKBjI9DVRNIAvdIQ","token_type":"Bearer","expires_in":3600,"id_token":"eyJhbGciOiJSU0ExXzUiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwiamt1IjoiaHR0cHM6XC9cL29wLmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldDo2MDEwM1wvZXhwb3J0XC9qd2tfNjAxMDMuanNvbiIsImtpZCI6ImEwIn0.rs03K6e_zbdJGY1OQcZm3n4gjJRBzMvsffZ45fohgs1RqZtFrPSzjn5kJV8qOALavrz4-u3jBYT86UiDfZgc26ZKxviWVRPtLVqwzYed0nIKmW7MEPX6wxL4iTcBDO1Qtdlu1UsAj2OS7T79eZwnHpYpzdEJdJZQnS9UYAzJskEFjlRHBmWvXaz-reApoOCR6rypWyZpD1MizhQpqpVNMOZfOMScFBY0nlvPjYvDkHZO5bP4gl29UvKujKWuFU02CmnrV4dAx6CAw82TTUrkyEF4GWfoPtYrRA2BA6nADb0H-PY0V5WoUl1X-LzPrDRqsFTtvc71xx5hIIcx37bSFQ.7UqnTPyocMvAw3EUltZ7MQ._pnurPSUwJWE0qzHNXzCttepF7sNWDAcbx4N6Qx34i1aYJ54yh17tbll0sopGRAobivlZ0_I42Zy74rz4D21gmNr8e858F_egsZlQFmKfqMT3UoZz8hM70foP8nsDdidv-33WdeRKgFhlBP47JAtpbpY4zkXPHA-7hFQerxkHY7qRQKtwLSRj9LUW7ZRKF2uhla8xYTgNwPoNI9OewbMDIQ199LizQD4sRPfJEitu5AJhUGeyTmGiX0x0RcVd3CH2smKAEGM35Bs7XWz6pm9m-a4BqHiz4PHioBT7iGCe49-ktPmJdpXZhQyQBTyg6PkG_M
 hUMibEY9DPQXFMTB1NEZQF6X9iEgTXF4bjWmneJPmDX3vC_-w22Q2VdNmfbZzTZT0m_jsEJ5pFSYkRnrwatoFfAO0gNpFhwprnQ0o9ycci4psVJlSmxVxcmw_N-EVWQ6O-pXkuO-Ac64gx4O-TWtcyXAhHJiVZY7tZkCje8ZaxG-KwMrwkijCxjQfXRtbbkPal4W7aTUwTyZwRBQ1KtLVsjfvwTtF9whZ7k8yij2FFpy5eBZwkMtm03dwxTqSwnR6VXbRfcyalYgig1QyL6RMGM1C40Ju9Gufk1DkgQQY0Uxsufyx150ApEVUYvD0BSJcuLlCAx89Ip86O8G06HljYI2_31VJbnKjibfZRDySSx3Sgp_XUhc7MSaqeaYCm1zYza4WfeEm5y0G_BA9cuKuks-05hM14129Z1pgYCOxv90HT4Md-3p1exEnbHTScxo4kDOSYQ84oXEPDUOtNvsBj5lCUFgfoYbTO3SqvQ7oX0fc9p2BB2rlNSrhgPG7DDn7Kp9M8MGYo_HrRjqiHe_wisIZavKrB5wHco5KoTc02vjm9-c6y0OFBxr3UHePBAxtnkItgFR3PnIbUoB7kH0GNg_qaPW3mQqeoKmW3KXknQTN7i0rbKRgc-5thEoWF69jOKz3tXtA2MObW08I3soUM24FK3n42B2l_tN2yEDx2q5eceHmiqgDp6JJ8UCj.rww1pTeZmZZECO1H3XbqXw"}
5.669136 [ERROR] MissingKey:No suitable verification keys found
Result

FAILED
```




More information about the Openid-specs-ab mailing list