You could also just do a packet trace. Send the output to Wireshark. It can format all the TLS hand-shaking traffic. The question I'd have, given the original description is whether AT-TLS is being used at all. Perhaps the program is using OpenSSL or GSK?
https://www.ibm.com/support/pages/how-capture-and-format-ssl-component-trace ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN