Friday, 2010-11-05

*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid12:11
*** SEJeff_work (~jeff__@209.160.84.1) has joined #wikid16:13
*** SEJeff has quit (Ping timeout: 276 seconds)16:16
*** SEJeff_work has quit (Ping timeout: 252 seconds)16:23
*** SEJeff_work (~jeff__@209.160.81.1) has joined #wikid16:35
*** mwpeterson (40f1258c@gateway/web/freenode/ip.64.241.37.140) has joined #wikid18:00
mwpetersonso, nowen, your openvn server...18:03
nowenoh, is it still up?18:03
mwpetersonis it up and I can't get to it from where I'm at?18:03
mwpetersonor is it not up and working as expected? :)18:04
mwpetersonbecause it's not answering, but who knows how much filtering Panera is doing on outbound connections18:05
nowenworks for me18:05
nowenon ubuntu18:05
mwpetersonhost: ec2-174-129-51-65.compute-1.amazonaws.com port: tcp 119418:05
mwpetersonis what I have in the client.conf from your zip18:06
nowenhmm.  I have 204.236.215.17918:06
mwpetersonthat's differently bad. :) connection refused on tcp 119418:07
mwpetersonswitching to udp gets me further18:11
mwpetersonself-signed certificate error now.18:11
nowenI've uploaded my working client.conf file to www18:13
*** mwpeterson has quit (Ping timeout: 265 seconds)18:21
*** mwpeterson (40f1258c@gateway/web/freenode/ip.64.241.37.140) has joined #wikid18:28
mwpetersonI either fell, off or the webclient just gave up displaying anything when it got to the bottom of the screen :)18:28
nowenoops18:29
nowendid you get me msg that I uploaded a working client.conf?18:29
mwpetersonI did.18:30
mwpetersondownloaded it from www/webdemo/client.conf18:30
mwpetersongot the ca.crt from there as well]18:30
mwpetersongetting self-signed certificate errors from openvpn18:30
nowenhuh18:31
mwpetersonyeah, that's my take on it as well.18:31
nowenaren't all openvpn certs self-signed, if you use there stuff18:31
nowenyou have to go out of your way to use signed certs18:31
mwpeterson*shrug* openvpn is outside my solution domain, for now.18:32
nowenthis is on a mac?18:33
mwpetersonbut if we're beyond all the obvious things and it's working for you, then I can fight with it later18:33
nowencommand line or some gui client?18:33
mwpetersonmmhmm, using Viscosity gui18:33
nowensome setting in it?18:33
mwpetersonnothing obvious18:33
mwpetersonif you see strange tweets from me, you'll know somebody at Panera was running firesheep :)18:34
nowenhehe18:35
mwpeterson<subject change/>18:35
mwpetersonchallenge response with mobile tokens when network is unavailable18:36
nowenok18:36
mwpetersonhow's that work? where do I get the challenge?18:36
nowenyour network client has to support it.  it is a radius standard, but adoption may vary18:36
nowenyou can test it via example.jsp18:36
mwpetersonok.18:36
mwpetersonso right now I got it trying to get a token from your example server18:37
mwpetersonsince your server didn't give me a challenge, this won't work.18:37
nowenfrom www?18:38
nowenyeah, I don't have that setup there18:38
mwpetersonprobably same story for openssh/pam/linux/radius with my wikid server18:38
nowenhmm, I could set up a whole example.jsp page online now that I think about it18:39
nowenthat could be a nightmare though18:39
nowenhave to think about that18:39
nowenI've heard that some flavors of pam support it18:39
mwpetersongood to know. I'll add it to the copious freetime list.18:40
mwpetersonthough, I can't imagine how often I'd be able to ssh when I have no network.18:40
nowenhaha18:40
nowenthat's the thing18:40
nowenpeople ask about offline pre-sales.18:41
nowennever after they deploy18:41
nowenpeople tend to buy phones that work in the places they go, or go places they work18:41
mwpetersonthat other really secure authentication company probably has it18:41
nowentime-based systems probably don't need it18:42
mwpetersonI can see a slightly contrived example where you require wireless tokens to decouple it from the laptop, but you work in a TEMPEST shielded building with no cell coverage.18:42
mwpetersonnothing I'd want to support, of course.18:42
nowenor perhaps you just have to use their proprietary protocol and not radius18:42
mwpetersonblech. did that in a previous life. they were always about a version behind the version of Solaris I was running.18:44
mwpetersonI'm much happier without all that headache.18:45
mwpetersonthanks!18:45
nowenyeah.  "Certified" to with our product == lock in ;)18:46
*** finalbeta_ (~finalbeta@ip-83-134-158-172.dsl.scarlet.be) has joined #wikid19:13
*** finalbeta has quit (Ping timeout: 250 seconds)19:16
*** mwpeterson has quit (Quit: Page closed)20:41
*** nowen has quit (Quit: Leaving.)21:24
*** proprietarysucks (~nathanr@static-96-247-50-178.lsanca.fios.verizon.net) has joined #wikid22:56
proprietarysuckshi, interested in some help getting set up if anyone is around22:56
proprietarysucksI've tried the community as well as enterprise iso.22:56
proprietarysuckstrying to get google sso + wikid going22:56
proprietarysucksfor the sole purpose of being able to control access to our google apps domain by ip address22:57
proprietarysucksafter setting the apps domain to have the certificate and to redirect, it just doesn't redirect. not sure if I'm missing something23:38
proprietarysuckswith my laptop I go to the google docs site and it just goes straight to the normal google log in page23:39
proprietarysucksI was under the impression it was going to go to the wikid log in page23:39

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!