<h4id="hardening-on-startup-scripts-for-services-interacting-with-vault"><strong>Hardening on startup scripts for services interacting with Vault</strong></h4>
@@ -2258,6 +2259,7 @@
<li>New tests related with <ahref="../testing/testplan/vendor_extensibility/">Vendor Extensibility</a></li>
<li><ahref="../testing/testplan/api_security_service/">Security Service Testplan</a> updated according to new features and Technical debts.</li>
<li>New test on <ahref="../testing/testplan/api_security_service/">Security Service Testplan</a> related with PKI security Method flow, GET request to security perform by AEF must returns CA_Root on authenticationInfo attribute at SecurityInfo.</li>
<li>Removed supported Feature negotiation test of <ahref="../testing/testplan/api_access_control_policy/">API Access Control Policy</a>, because currently spec (v18.7.0) not support any feature.</li>
<li>Send <strong>POST</strong> to ccf_publish_url <strong>https://{CAPIF_HOSTNAME}/published-apis/v1/{apfId}/service-apis</strong></li>
<li>body <ahref="../api_publish_service/service_api_description_post_example.json"title="Service API Description Request">service api description</a> with apiName <strong>service_1</strong></li>
<li>Store <strong>serviceApiId</strong></li>
<li>Use <strong>APF Certificate</strong></li>
</ul>
</li>
<li>
<p>Perform <ahref="../common_operations/#onboard-an-invoker"title="Invoker Onboarding">Invoker Onboarding</a> store apiInvokerId</p>
</li>
<li>Discover published APIs</li>
<li>
<p>Create Security Context for this Invoker for both published APIs</p>
<p>This test case will check that an API Provider can't retrieve ACL from CAPIF if service-api-id and aef-id are not valid</p>
<p><strong>Pre-Conditions</strong>:</p>
@@ -2008,8 +1906,8 @@
</ol>
</li>
</ol>
<h2id="test-case-9-retrieve-acl-without-securitycontext-created-previously-by-invoker">Test Case 9: Retrieve ACL without SecurityContext created previously by Invoker</h2>
<h2id="test-case-8-retrieve-acl-without-securitycontext-created-previously-by-invoker">Test Case 8: Retrieve ACL without SecurityContext created previously by Invoker</h2>