Friday, 2010-10-15

*** nowen (~nowen@adsl-66-165-228.asm.bellsouth.net) has joined #wikid14:49
*** ken5m1th (~ken5m1th@c-24-61-209-87.hsd1.ma.comcast.net) has joined #wikid17:12
ken5m1thhey hey hey17:12
nowenhowdy howdy17:12
ken5m1thhows mr owen today?17:13
nowenpretty good.  looking forward to the weekend, despite being the solo parent17:13
nowenhow about you?17:13
ken5m1thHoping the rain stops, busy weekend ahead. not as busy as hackid was tho17:14
nowenI wish we would get some rain17:14
nowenhackid sounded pretty awesome17:14
ken5m1thIt was full of awesome17:14
nowenmight have to see about doing one here17:15
ken5m1thmy kids all (4 of them) want to volunteer for the next one, wherever it might be.17:15
ken5m1thMy wife even really enjoyed it17:16
ken5m1thI have a few wikid questions17:16
nowenok17:17
ken5m1thAbout the types of VPN devices it supports.  Work with Sonicwall firewall/vpn?17:17
nowencertainly!  via raidius17:18
ken5m1thI have a scenario that includes multiple entry points into the network and each has a different VPN.17:18
nowenalso, on our PC token you can do mutual https auth17:18
nowenhmm17:18
nowenno problem17:18
nowenI think17:19
ken5m1thOk, so if it's something like an Internet facing web site we can17:19
nowenare you using AD?17:19
ken5m1thhave the token presented to the web site as auth17:19
ken5m1thusing AD, but here is another rub. Each of these entry points has it's own AD domain17:19
ken5m1thBut I think they can all talk to eachother via MPLS17:20
ken5m1ththe VPN devices that is17:20
nowenhmm.  you should check into the MS radius server IAS/NPS and see if that can help17:20
nowenif you run the auth through IAS and AD, then disabling a user in AD removes their remote access capabilities too17:21
ken5m1thMaybe we could setup one of these that would act as a "sort of" proxy to all the other AD domains?17:21
nowenthat's what I'm wondering17:21
nowenI would have to think that MS has seen this a good bit17:22
nowenyou might need the latest, which is NPS on 2008, though17:22
nowenor, in the worse case, you just set up IAS on each domain server17:22
nowennot too bad, really17:22
nowenunless you have ALOT of domain servers17:23
ken5m1thNetwork Policy Server, I see.17:23
nowenyeah17:23
noweni wrote a tutorial for it17:23
nowenhttp://www.networkworld.com/news/2010/050710-two-factor-authentication-through-windows-server.html?hpg1=bn17:24
nowenfor Bill Brenner :)17:24
nowenhere's what I mean by mutual https auth: http://www.wikidsystems.com/WiKIDBlog/preventing-mitm-attacks17:25
nowenthe token checks the ssl cert for the user17:25
ken5m1thI think I am going to try and install wikid on a linux box here at the home lab17:29
nowengo for it.  the iso is centos 5, btw.17:30
ken5m1thI played with the VM, but only way for me to test is out well is having it live.  It's an existing box, I can install the packages right?17:30
nowenyes,  rpms17:31
ken5m1thlet me see what my dist is based on17:31
ken5m1thit's CentOS17:34
ken5m1thshould be easy17:34
nowenyep17:34
ken5m1thtake many resources if it's just handling auth for a few users?17:34
nowennot at all17:35
ken5m1thMaybe OpenVPN to start17:35
nowenit does use port 80 and 44317:35
nowenso if you are running apache, you will need some re-write rules17:35
nowenhttp://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-install-the-wikid-enterprise-rpms17:35
ken5m1thlet me see if my host runs anything on 80/443 now17:36
nowen80 is for the tokens and goes to /wikid/  443 is for the WiKIDAdmin and it goes to /WiKIDAdmin17:36
ken5m1thand both need to be externally accesible right?17:37
nowendepends on if you want access to WiKIDAdmin outside the firewall17:37
ken5m1thProb not17:37
ken5m1thjust be able to auth to OpenVPN and SSH from outside17:38
nowenyeah.  so, pam_radius17:38
nowenyou'll have to compile it from source, but it's easy17:38
nowenor I can send you the .so for centos517:39
ken5m1thI'll do that.  I have to go get ready for a conf call. Do I need a link for the rpm's from you or are they avail right on the site?17:52
nowenon the site17:53
nowendon't worry about getting spam17:53
ken5m1thok, thanks.  Have a great afternoon!17:53
nowenif I send you spam you can out me on twitter ;)17:53
nowenyou too. later!17:53
*** ken5m1th has parted #wikid (None)17:53
*** nowen has parted #wikid (None)20:39

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!