(max_age requires auth_time)
   |success            = Causes reauthentication when authentication age over 30 seconds
   |success            = auth_time claim returned and causes reauthentication when authentication age over 30 seconds
   |failure            = Fails

Latest revision as of 17:53, 11 June 2014

{{#if:|Feature Test |Feature Test }}   Providing ID Token with max_age Restriction
Test Type   bgcolor={{{color}}}}}|normal
Identifier   bgcolor={{{color}}}}}|FTR-op-maxage  
Description   bgcolor={{{color}}}}}|Exchange with max_age request value of 30 seconds  
Role tested   bgcolor={{{color}}}}}|OP  
Success Criteria   bgcolor={{{color}}}}}|auth_time claim returned and causes reauthentication when authentication age over 30 seconds  
Failure Criteria   bgcolor={{{color}}}}}|Fails  

Features Proven


  1. Run the automated OP testing tools either using the online OP test site at http://openidtest.uninett.no/test#!/connect or by downloading and running the OP testing scripts at http://www.kodtest.se/oictest/.
    1. Instructions on getting started with OP testing can be found at http://openidtest.uninett.no/connect-gettingstarted.
  2. Open the result page for your solution and this test.
  3. Record the outcome from the test "(mj-25)Requesting ID Token with max_age=1 seconds Restriction" in the results page:
    1. If the success criteria was met, set the outcome to "Works".
    2. If the test failed, set the outcome to "Failed" and enter information about the failure in the Notes section.
    3. If other issues occurred set the result to "Issues" and describe them in the Notes section.
  4. Add either four tilde ~~~~ signs or a text name into the "Tested by" parameter.
  5. Update the Date Tested, Browser, and Operating System lines of the results page.