Tuesday, 2010-11-16

*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid13:36
*** davidspollack (4a022302@gateway/web/freenode/ip.74.2.35.2) has joined #wikid20:31
davidspollackhi20:31
davidspollackim considering the wikidsystems 2 factor system ... and have some questions20:31
davidspollackhello?20:32
*** davidspollack has quit (Client Quit)20:35
*** dpollack (4a022302@gateway/web/freenode/ip.74.2.35.2) has joined #wikid21:14
dpollackhello21:27
nowenhi21:27
nowenjust sent you an email21:28
nowenwe currently only have master/slave replication21:28
dpollacksorry phone call21:29
nowennp21:29
dpollackso if i had 3 servers I could have one master & 2 slaves?21:34
nowennot at this time.  the next major release will allow for 3 masters21:34
dpollackok21:35
dpollackcan you explain, in a nutshell, wher ethis would fit in to my VPN config?21:35
dpollacki currently use a cisco ASA 551021:35
dpollackand we are doing CLIENT vpn21:36
nowensure.  just use radius21:36
dpollackwith a windows ISA radius21:36
nowenyeah21:36
nowendoes the cisco talk to the ias now?21:36
dpollackand the IAS authenticates windows AD users/pwd21:37
dpollackyes21:37
nowenjust add WiKID as a radius server in IAS and create a policy to proxy authentications to it21:38
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-configure-ias-to-support-two-factor-authentication/21:38
dpollackok thanks21:41
dpollackwhy not just replace the IAS server with the wikiid server?21:46
dpollackjust wondering21:46
nowenwell, depends, but the best reason is then all you need to do is remove a user in AD and they have 0 access.  otherwise, remove in AD and WiKID21:47
dpollackah ok.21:47
dpollackso the IAS server proxies over to the WikID radius server21:48
dpollackis it possible to keep the wikid ID database updated as AD changes?21:48
nowenyes, but first validates that the users are active and in the right group (if you configure it that way)21:48
dpollackright, but it passes to wikid for the pwd auth21:48
nowenwe don't currently have a mechanism to remove users from wikid if they are deleted from AD, if that's what you mean.  it could be done though via an ldap script21:49
dpollackwikid is running ldap under the hood ?21:50
nowenno - the script would make an ldap call to ad21:50
dpollackk21:52
dpollackluckily we're small so its not a big issue, but im sure its a showstopper for big clients21:52
dpollackin any case I'm loking forward to trying it out.21:56
dpollacklooking21:56
nowencool.  we're here to help21:56
dpollacknot every day you get the CEO doing tech support on IRC ;)21:56
nowenhehe21:57
*** dpollack has quit (Quit: Page closed)22:10
nowenlater all22:25
*** nowen has quit (Quit: Leaving.)22:25
*** MRicketts (d8ed3803@gateway/web/freenode/ip.216.237.56.3) has joined #wikid23:39
*** MRicketts has quit (Client Quit)23:41

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!