What is the best trace to troubleshoot certificate / keyring problems?
The best trace to see what keyring and certificates are being read is an R_datalib trace.
It is best to include a Sectrace along with the R_datalib trace.
Below are the trace commands:
TSS ADD(acid) TRACE
TSS REFRESH(acid) JOBNAME(*)
ST SET,ID=TSS,TYPE=OMVS,DEST=SYSLOG,FORMAT=DUMP,SFUNC=RDATALIB,END (issued on the console) This will route all trace records to the MVS syslog....
Recreate the problem.
ST DEL,ID=TSS (issued on the console)
TSS REM(acid) TRACE
Both traces will print together as one trace in plain text and is emailable.