Does anyone know of any way to log the incoming cert details even if webseal rejects the request?
We get questions every day about operation aborted screens detailing "HPDIA0114E Could not acquire a client credential." Most of the time it is because the user's cert is not imported in correctly, although sometimes it is because the user's account is not valid in the ISVA registry. However, there is no log of the incoming cert and/or why it was rejected.
Is there any way to log the incoming cert detail even during instances when webseal rejects them? It would even be great if we could log when the cert fails CRL check or expiration date, etc.
We use the username mapping module, so the only thing I wondered if there was some way to maybe make that log when it fires. Otherwise, the only other thing I could think is switching to an EAI/InfoMap to accomplish this logging, but that introduces new dependencies on our existing flows.
Just curious if anyone else has managed to capturing incoming cert details when mTLS is used. Thanks!
------------------------------
Matt
------------------------------