User guide
Chapter 4: Operation and Maintenance
4-18
Supplementary Information
The cause of authentication failure is recorded in the access log.
For details about supplementary information in the access log, refer to “Messages Logged and Output in
Single Sign-on” – ‘Access Log In Single Sign-on Mode” – “Access Log of the Repository Server”’ –
“Supplementary Information in the Access Log of the Repository Server” in Messages.
The cause of the authentication failure will not always be recorded.
*1 This access log may be output two or more times.
Example
10.131.201.10 – 10.131.201.199 [2002/09/11 20:28:22 +0900] –
"cn=User001,ou=User,ou=interstage,o=fujitsu,dc=com"
Authentication(basicAuth)failed. (Count up failure count)
Access Log of Authentication Server
The access log of the authentication server records the result of the repository server authentication
processing in response to a user authentication request from the business server.
If load balancing is being performed using multiple authentication servers, the access log may be
distributed and recorded depending on the load balancing setting.
The record format and contents are as follows:
client – business-server – repository-server [date/time] – “user-
identification-information” processing-result (supplementary-information)
Client
IP address of the client that requests authentication.
Business Server
IP address of the business server that issued the authentication request
For an authentication request from an application using Single Sign-on JavaAPI, the character string
“SSO-JavaAPI” is recorded. In this case, the IP address of the computer on which the application is
running is recorded.
"unknown" is recorded if the authentication request generation source cannot be determined.
Repository Server
IP address of the repository server requested for authentication processing. If repository server load is
distributed using the repository server (update system) and repository server (reference system), the IP
address of the repository server (reference system) is recorded.
"unknown" is recorded if the repository server is not requested to perform authentication processing.