Security Conformance
FAPI
1. Click on the Create Test Plan
option from the FAPI
Dashboard
2. In the Create Test Plan
form provide the Test plan name, FAPI Test Plan, FAPI Profile, Client Authentication type, Request Object Method and Description.FAPI Response Mode
will be selected by default.
3. Provide Json data in below format in the Test Configuration
section. Edit the Client details, PSU credentials & endpoint details as required. Make sure that the Two factor authentication is disabled for the PSU user and the Client accepts Redirect URI https://conformance-sbx.banfico.io/
.
Sample config for Private Key JWT authentication
4. Click Run Test Plan
option to start the Test execution. You can use the Save Test Plan
option, if the Test plan needs to be executed in future. Test Plan Scheduler option can be enabled, if the Test plan needs to be executed in future.
5. Live Test Results will be fetched once the Test execution gets started.
6. User will be redirected to Test details page, once the Test execution gets completed.
7. Clone Test Plan
option can be used to create a new Test plan with the existing test configurations.
8. Test report will be downloaded on clicking the Download Report
option
9. On clicking the View Full Report
option, test report will be displayed. Test result details of individual Test cases can be viewed on clicking the View Result
option
Penetration testing
If the Bank wants to perform Penetration testing for their Web Application or API, then can create a Test request in our Conformance portal
1. Click on the Create Test Request
option from Penetration Testing
Dashboard
2. Provide the Test request name, Test type, Description, Test configuration details and Submit the Test request
3. Once the Test Request is created, Banfico user will receive a Mail notification. Banfico user will update the status of Test Request
to In Progress
, add Comments (if any) and will start the Penetration testing.
4. Once the Testing is completed, status of Test Request
will be updated to Completed
and the Test Report will be attached in the Comments section