Previous Topic: How to Track Problems in CA Identity Manager

Next Topic: CA Identity Manager Protection

How to Trace Components and Data Fields

When CA Identity Manager integrates with SiteMinder, you can use the SiteMinder Policy Server Profiler to trace components and data fields in the Identity Manager extensions for the Policy Server. The Profiler lets you configure filters for the tracing output so that only specific values for a component or data field are captured.

Note: For instructions on using the Policy Server Profiler, see the CA SiteMinder Web Access Manager Policy Server Administration Guide.

You can enable tracing for the following components:

Function_Begin_End

Provides low-level trace statements when certain methods in the Identity Manager extensions for the Policy Server are executed.

IM_Error

Traces runtime errors in the Identity Manager extensions for the SiteMinder Policy Server.

IM_Info

Provides general tracing information for the Identity Manager extensions.

IM_Internal

Traces general information about internal Identity Manager operations.

IM_MetaData

Provides tracing information when Identity Manager processes directory metadata.

IM_RDB_Sql

Provides tracing information for relational databases.

IM_LDAP_Provider

Provides tracing information for LDAP directories.

IM_RuleParser

Tracks the process of parsing and evaluating member, owner, and admin policies, which are defined in an XML file that gets interpreted at runtime.

IM_RuleEvaluation

Traces the evaluation of member, admin, owner, and scope rules.

IM_MemberPolicy

Traces the evaluation of member policies, including membership and scope.

IM_AdminPolicy

Traces the evaluation of admin policies.

IM_OwnerPolicy

Traces the evaluation of owner policies.

IM_RoleMembership

Traces information relating to role membership, such as the list of roles a user has and the list of members in a certain role.

IM_RoleAdmins

Traces information relating to role administration, such as the list of roles a user can administer and the list of administrators for a certain role.

IM_RoleOwners

Traces information relating to role ownership, such as the list of roles a user owns and the list of owners for a certain role.

IM_PolicyServerRules

Traces evaluatation of member rules, such as RoleMember, RoleAdmin, RoleOwner rules, which are resolved by the Policy Server, and scope rules, such as All and AccessTaskFilter rules for AccessTasks

IM_LLSDK_Command

Traces communication between the internal Identity Manager SDK and the policy server. This trace component is used by Technical Support.

IM_LLSDK_Message

Traces messages that are explicitly sent by Java code to the Policy Server from the internal Identity Manager SDK. This trace component is used by Technical Support.

IM_IdentityPolicy

Traces the evaluation and application of Identity Policies.

IM_PasswordPolicy

Traces the evaluation of password policies.

IM_Version

Provides information about the Identity Manager version.

IM_CertificationPolicy

Traces the evaluation of certification policies.

IM_InMemoryEval

Traces the processing of Identity Manager policies, including member, admin, owner, and Identity Policies. This trace component is used by Technical Support.

IM_InMemoryEvalDetail

Provides additional detail about the processing of Identity Manager policies, including member, admin, owner, and Identity Policies. This trace component is used by Technical Support.

The data fields for which you can configure tracing are listed in the CA SiteMinder Web Access Manager Policy Server Administration Guide.