Thursday, 2010-11-11

*** ldralves (~support@201.29.199.180) has joined #wikid01:13
*** husaragi (456ab9e0@gateway/web/freenode/ip.69.106.185.224) has joined #wikid01:31
husaragianyone home?01:31
ldralvesye01:33
ldralvesyes01:33
husaragicoolies. quick question01:34
husaragii want to OpenVPN through my pfsens firewall and authenticate against my AD server inside...can i do that with wikid?01:34
husaragii know i can get the openvpn part all set up no prob01:35
husaragibut i want my AD users to be authenticated to the internal AD server so they can have access without having to put in their AD username and password after authenticating to wikid01:35
husaragiill be honest. i havent read a word of documentation yet01:36
ldralvesi think that it's  possible in paid version, because you will need radius module01:39
husaragiahh ok so i cant do radius with the free one?01:40
husaragilooks like radius is available in the community version also, but with the enterprise one you get the built in java radius server01:42
husaragii am guessing i can set this up and get it to work even with the community edition.01:42
husaragithanks01:42
*** ldralves has parted #wikid ("Ex-Chat")01:47
*** husaragi has quit (Quit: Page closed)02:19
*** husaragi (45ec8930@gateway/web/freenode/ip.69.236.137.48) has joined #wikid02:55
*** husaragi has quit (Quit: Page closed)03:10
*** manonst (4a697126@gateway/web/freenode/ip.74.105.113.38) has joined #wikid05:24
*** manonst has quit (Quit: Page closed)05:30
*** husaragi (0cbdd50a@gateway/web/freenode/ip.12.189.213.10) has joined #wikid15:13
husaragihey guys16:10
husaragii am trying to install from a USB key i made using the pendrivelinux installer16:10
husaragiwhen it gets to the part where it wants the image file...it says it cant find it on the disk16:11
husaragiwhat folder should i be looking in for the image file at that point?16:11
*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid16:26
husaragimorning nowen16:27
husaragiare my questions visible to you right now? or was the buffer cleared when you logged in16:28
nowenmorning16:28
nowenbuffer cleared, I'm afraid16:28
husaraginp. here it is again16:28
husaragii made a USB installer from the pendrivelinux USB stick creator16:28
husaragithe installer starts but when it gets to the part where it wants the CD images....it says it cant find them on any of the disks in the system16:29
husaragiwhat folder should i be looking in for the image file?16:29
nowenis this a usb installer for the server?16:29
husaragiI downloaded the .iso CentOS installer and created a USB stick installer from it16:30
husaragiso it should basically be just the contents of that CDROM installer but on a USB key16:30
nowenok16:30
husaragithe device in the system is /SDA1 but if i point at just that location the installer says it cant find any images on that disk16:31
husaragi15 min meeting. back in a few16:32
husaragiback16:47
husaragigot anything for me? can i point that installer at a specific folder?16:47
husaragiall i have to do is tell it local CD rom and it finds everything correctly if i am actually using a cdrom16:47
husaragiim curious why it is unable to find the images on the HD16:47
nowenok - why aren't you doing that?16:47
nowenwhy are you using a usb?16:48
husaragithere is NO CDROM available on the server where i am doing the production install16:48
nowenok16:48
husaragii think it might work if i just give it the correct folder16:49
husaragibut i dont know which folder it is wanting to look in16:49
husaragior more specifically which image file it wants16:49
husaragiif you can just tell me that i can point it at the right file and see if it works16:49
husaragiif it doesnt work i will open the box and temporarily connect a CDROM.16:49
noweni'm not really sure. I assume boot.iso16:50
husaragioh...are you not a WiKID team member? i thought i was talking to a dev lol16:51
nowenI am a team member, but I don't know the answer to that16:51
nowenI'm sorry - I meant mages/diskboot.img17:24
nowenthis might help: http://wiki.centos.org/HowTos/InstallFromUSBkey17:25
*** mwpeterson (~mwpeterso@99-14-173-232.lightspeed.ftwotx.sbcglobal.net) has joined #wikid20:08
mwpetersonis there a "bulk add" tool for loading and configuring a passel of network clients?20:09
nowennot at this time20:09
mwpetersonpatches welcome, I assume :)20:09
nowenindeed!20:09
mwpetersonfrom looking at the schema, it appears it could be done with postgresql updates20:11
nowencertainly20:11
nowenwhat20:11
nowenis your fav language?20:11
mwpetersonany guidance on that laying around in /opt/WiKID some place?20:11
mwpetersonperl. what else is there?20:11
nowenhehe20:11
nowenthese all radius?20:13
mwpetersonyep.20:13
mwpetersonwe have the main bastion server that is the chokepoint, but we configure the rest of our servers to allow wikid in case the LDAP server rolls its white belly to the sky20:14
mwpetersonbeing able to sudo with a token has saved my bacon a couple of times20:15
nowenshould be pretty basic for radius.  just a sql insert20:15
nowenor two20:15
mwpetersonmain data goes in full_network_client20:17
mwpetersonand the host_nc_map needs updating20:17
nowenyeah20:17
mwpetersonanything else?20:18
mwpetersonother than a wikid restart20:18
nowenI'm double checking20:19
mwpetersonrockstar!20:19
nowenwell- I'm double checking with the rockstar ;)20:19
mwpetersonah. you're just the API.20:20
nowenhaha20:20
nowenif that20:20
nowenalso, too lazy to check the code myself20:20
mwpetersonideally, I can get this into something puppet can drive, and then new servers "just work"20:20
nowenooh,. that's cool20:21
mwpeterson<aside>I highly recommend puppet if you have more than two servers to manage</aside>20:22
nowennc_return_attrib for any radius attirbutes..20:24
noweni want to play with puppet at some point20:24
nowenjust no time20:24
mwpeterson0 rows in that now, and I don't see that changing in the future.20:25
mwpetersonbut good to know.20:25
nowenThe insert should technically go into network_client.  The triggers in the DB will auto update full_network_client.  Probably won't matter but that's how WiKIDAdmin does it.20:27
husaragiyou guys know of anyone who has tried to run this under FreeBSD?20:27
nowenmmm, it's come up from time to time, but I don't know for sure20:28
mwpetersonnetwork_client...20:28
husaragiis there a tarball available?20:28
husaragithat could be compiled on freebsd?20:28
nowenhusaragi: wikid uses java and tomcat20:29
mwpetersonah. forgot to look at views.20:29
husaragioh its all java?20:29
husaragicool20:29
husaragiso it should run under anything then20:29
husaragithat supports those packages20:29
nowenshould, yes20:29
husaragiand bsd does so20:29
nowenhusaragi: documentation accepted!20:29
husaragihahaha! i didnt say i was gonna *try* it....but i might at some point20:30
husaragi i run most of my network monitors and security stuff on BSD20:30
husaragiso i wanted to see if i could get this running too20:30
husaragioh btw that diskboot.img or bootdisk.img was not the correct file. the installer bailed out on me when i tried to tell it that was the image file20:33
mwpetersondoing networking and security on BSD and not using OpenBSD?20:33
mwpetersonfor shame.20:34
husaragiwell the pfsense firewall was built on freebsd but my zabbix and nessus boxes also my snort reporters are all openbsd20:34
husaragijust going to connect a USB cdrom and see if it will install from that20:35
husaragithe usb key is not working for whatever reason. the file structure looks identical to the file structure on the install CD but no dice when you actually run the installer from the usb key20:36
nowenmwpeterson: http://pastebin.com/H6f0KyMS20:40
mwpetersonso insert/update/delete through the network_client view so delete can be a flag, rather than an action20:52
nowenbasically20:52
mwpetersonand maintain  the host_nc_map20:53
mwpetersonsince I don't see that being touched by that view.20:53
nowenyes20:53
mwpetersonthat y'all used views was probably the key detail I was missing.20:53
*** mwpeterson has parted #wikid (None)21:37
*** mwpeterson (~mwpeterso@99-14-173-232.lightspeed.ftwotx.sbcglobal.net) has joined #wikid21:52
mwpetersondo the token clients need 443 access, or just 8021:52
SEJeff_workmwpeterson, I believe they do diffie hellman key exchange over 8021:58
SEJeff_workNo point to encrypt twice21:58
nowenmwpeterson: just 8021:58
mwpetersongood. that might make my LB config simplier.22:04
husaragiso is there updated readme on the CD or something? im reading the install instructions you have posted online...22:10
husaragisays i just need to install from the .iso and configure networking22:10
husaragiby running wikidctl setup22:10
husaragibut when i try to run wikidctl its not found22:10
nowenit's in /opt/WiKID/bin22:10
husaragithere nothing in opt whatsoever22:11
nowenthere are a couple of scripts22:11
husaragicd /opt22:11
husaragils -a22:11
nowenthen it didn't install22:11
husaragi.22:11
husaragi..22:11
husaragiwonderful22:11
husaragibrb22:11
husaragiso i put the .iso burned CD into the machine and boot. run the installer and it completes....22:13
husaragibut theres nothing in /opt....22:14
husaragiwhat did i do wrong?22:14
nowenif you do an 'rpm -qa | grep wikid22:14
nowen '22:14
nowendoes it show anything?22:14
husaragiserver is in the other room. no IP kvm. back in a min22:15
nowenno ssh?22:15
husaragireturns blank22:16
husaragioh i didnt even think to try ssh. i didnt tell it to specifically start that service but maybe its default in that installer22:17
nowenhow big is your iso?22:17
nowendid you check the md5 sum?22:17
husaragi675mb22:17
husaragino i did not check the hash22:18
husaragii trusted your download server was not compromised. my bad i guess22:18
nowenI don't think it is22:18
* SEJeff_work watches with popcorn22:18
noweni show the iso as 661M22:18
husaragiwell thats probably right. im looking at a byte count22:19
husaragi675,00022:19
SEJeff_workdu -h perhaps22:19
husaragiit reads as 660mb22:19
nowendid you type 'install' at the install screen?22:20
husaragiunless i typo'd it as instal or something22:20
husaragii did it without typing anything once too22:20
husaragithinking it may default to 'install'22:21
nowenit doesn't because someone once complained about that22:22
husaragigoing to check the hash. if its good i will try the install on a different box. if its bad i will redownload22:22
noweneaaa3a969ec5b76a049f030fb529e5ec22:22
husaragithanks22:22
husaragimatch. i will re-run the install and verify that i type 'install' correctly22:22
husaragiit IS possible i fatfingered it22:22
nowenseems odd22:23
husaragiafk22:23
husaragii suspect it was due to attempting the install from the USB stick i created from the .iso22:29
husaragisomething is a little off with that, so it doenst seem to work right. like when it could not find the image file it needed for install22:30
nowenhmm22:30
husaragii booted from the CD and the installation is proceeding differently this time22:30
husaragijust FYI when i created the USB stick from the .iso22:31
husaragii originally tried to tell the USB stick creator program that it was a CentOS .iso image22:31
nowenit mostly is22:31
husaragibut the USB stick maker did not recognize your .iso as CentOS22:31
husaragiso i had to tell it to "use some other distro"22:31
husaragii suspect it was not able to do it correctly22:31
husaragiand subsequently my installation attempt failed22:32
*** CMatthews (d8ed3803@gateway/web/freenode/ip.216.237.56.3) has joined #wikid22:39
husaragiyeah there were definitely issues with the USB thing. it was trying to load ks-install.sh from CDROM: still. even though i had created the USB key22:39
CMatthewsSo... I'm completely new to the wikid product / two factor auth concepts and have a couple questions about how it will work for my environment. Okay to ask here, right place to inquire?22:40
nowenplease do22:40
CMatthewsFirst of all this is required for us for PCI DSS compliance... I'm sure thats not the first time you heard that...22:41
CMatthewsWe are a restaurant chain.22:41
nowenhaha, no22:41
CMatthewsWe have checkpoint firewalls at all of our sites.22:41
nowenok22:42
CMatthewsWe are primarily a microsoft shop.. but I don't care what types of servers I run.22:42
CMatthewsSo say I download the VM or ISO and get it operational.22:42
CMatthewsRadius server up and running.22:42
nowenyeah - do you using vm esx?  if so, I recommend getting the iso22:42
CMatthewsyeah ESX 4.x22:43
CMatthewskk will do ISO route22:43
nowenwe just build the vmware with the free server version.22:43
nowendo your checkpoints talk radius to AD or ldap now?22:43
CMatthewsAD now.22:43
CMatthewsSo how will I limit user connectivity to our restaurant networks without two factor auth.. We have a internal helpdesk and a small IT staff.22:44
CMatthewsWe use pcanywhere, vnc, direct unc connections, etc etc...22:44
CMatthewsall of this I want to lock without the two factor.22:44
nowenok - so the checkpoints all talk back to AD?  centrally?22:44
CMatthewsYes22:44
nowendoes it all go through the vpns?22:45
nowenI mean, you can lock your vpn down with 2FA and then let all the other stuff go on top of that22:46
CMatthewsone second I'm catching up another IT guy with this conversation so I can ensure I'm providing the right details.22:47
nowenok - just note that i have to go soon, I have a commitment22:49
nowenat a  bar with a friend ;)22:49
CMatthewsyes through the VPN22:50
nowenok, so the best way to set this up, IMO, is to have the checkpoints talk radius to the AD radius plugin IAS (now nps)22:50
CMatthewsok22:50
nowenIAS will proxy the users to the WIKID server22:50
nowenias is a free add on22:51
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-configure-ias-to-support-two-factor-authentication/?searchterm=ias22:51
CMatthewsyeah ty22:51
nowenthe big benefit is that a user can be controlled in AD alone.22:51
nowenjust remove them from the group and no more access22:51
nowenalso, you can set it to only proxy certain people, so testing is easy22:51
CMatthewsgood ncie22:52
husaraginowen, can i have AD users and locally authenticated users on the same wikid box?22:52
nowenyes22:52
nowenbut22:52
husaragii have a staff at this location with AD accounts. but staff in china i want to VPN in but they dont have AD accounts22:52
nowenthat should work.  one network client is the IAS server, the other is your VPN22:53
nowenyou might have to have two domains22:53
husaragithats fine.22:53
husaragithanks22:53
nowenCMatthews: see the install doc sections here: http://www.wikidsystems.com/support/wikid-support-center22:53
CMatthewsOkay so what is it that the user is entering the second factor id code into that grants them access to a client, is this through the wikis server webpage?22:54
nowensome are short and pictureless some are long and picture full22:54
nowenthe users get a software token.  the two-factors are possession of the (private key embedded in the) software token and knowledge of the PIN22:54
nowenthe software tokens get an OTP from the WiKID server22:55
husaragiI have confirmed that i was the USB creator that fubar'd the installer22:55
CMatthewsokay like the iphone or blackberry client will give the code, where do the users put the code in order to get auth?22:55
CMatthewsand22:55
CMatthewsAnd the licensing, we have about 20ish users who will be able to access the 400ish clients, so this is the 25 user client pack / 1 seat 1 domain, licensing plan?22:56
husaragiit failed to change all thereferences to CDROM: and left the installer in a broken state. just FYI22:56
noweninto the vpn's password box22:56
nowenhusaragi: I don't see us ever creating a usb version, though it's possible if we can automate it22:56
nowenand have time to set it up22:56
nowenCMatthews: yes that works22:57
husaragioh i wasnt asking you to. just letting you know for future reference if others try to do it22:57
nowenthere are no limited to the domains22:57
nowenhusaragi: oh, i know.  i was thinking that if we start getting a lot of requests, we would22:57
husaragiif i get time I will figure  out why the creator coudnt tell what distro the .iso was and fix it22:57
husaragiif i get a good USB stick image i will send it to you22:57
nowenthat would be good22:57
nowenyou know, the problem is maintenance  - what do we do for the next release22:58
nowenyou could also create a centos usb drive, boot it and then install wikid22:58
husaragicopy the scripts i change into that new relase?22:58
nowenjust download the rpms and install22:59
husaragimy issue is that i have a lot of pizza boxes without CDROMS22:59
husaragithe USB CDROM works fine, but its more convenient to carry a 1 inch USB stick than a usb CDROM drive23:00
nowenoh sure23:00
SEJeff_workIt is more convienient to use scp and ssh :)23:00
husaragialso true =)23:00
nowenwhat about puppet?23:00
CMatthewsnowen, thanks for your input. I'll start down this path of destruction and come back after I23:00
CMatthewsget stuck.23:00
nowenok - I'm usually here eastern hours23:00
husaragiim sort of in between that wonderful world of beginnerism and intermediary skill levels with linux23:01
husaragiso some of this stuff i just havent discovered yet or know how to do very well23:01
nowenhusaragi: yeah - I haven't played with puppet yet, but it seems like it might be worthwhile for you to dig in to23:01
husaragiwill check it out tonight23:01
nowenok - I gotta check out.  later peopel23:02
SEJeff_worklater23:02
husaragilater man. have a shot for me ;)23:02
nowenwill od23:02
*** nowen has quit (Quit: Leaving.)23:02
*** CMatthews has quit (Quit: Page closed)23:07
husaragihrm whats the default login for a fresh wikid install from the .iso?23:10
husaragifound it23:13
husaragihrm. or not23:15
husaragianyone know?23:19
husaragimachine rebooted after install and i see a login prompt but i cant find anywhere that says what the default login should be23:19
*** SEJeff_work has parted #wikid ("Leaving")23:19
*** husaragi has quit (Quit: Page closed)23:26

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!