UCS uses for the UMC authentication SAML at least if ucs-sso.$domainname is reachable for the web browser. Debug for SAML can be activated by the following command:
ucr set saml/idp/log/level=DEBUG \
saml/idp/log/debug/enabled=true
Afterwards, log messages can be found in /var/log/syslog.