Thursday, 2010-12-23

*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid14:05
*** jon___ (0cba3d04@gateway/web/freenode/ip.12.186.61.4) has joined #wikid16:00
jon___hi16:00
nowenhi16:00
jon___I'm looking for a two factor authencation16:01
jon___is it possible to schedule a demo?16:01
jon___for my team16:01
nowentell me a bit about what you are trying to secure?16:01
jon___just the vpn16:01
nowenok16:01
jon___we have ssl vpn16:02
jon___juniper16:02
nowenok, both systems talk radius, so integration is not an issue16:02
jon___yeah16:03
nowenhave you played with the token client?16:03
jon___yes with different vendor16:04
nowen?16:04
jon___yes16:04
jon___how can I schedule for a demo?16:04
jon___like webex/gotomeeting demo16:04
nowenI can schedule something - but right now it might be the week of 1/416:05
jon___that is fine16:05
nowenok16:05
nowenI got your email as well16:05
jon___my email is joe.tran@beryl.net16:05
jon___yeah, I just request from the website16:05
nowenfeel free to download the server if you'd like as well16:06
jon___WiKID is us base company?16:06
nowenyes16:06
nowenAtlanta, Ga16:06
jon___ok16:06
nowenhow many users do you have?16:07
jon___little over 30016:07
nowencool.  Using tokens already or is this a new thing?16:07
jon___So how does the server integrate into vpn?16:07
jon___through win 2008 NPS?16:08
nowenyou can set it up that way16:08
jon___we dont have token now16:08
jon___but it's nice to have hardware/software token16:08
nowendoes the Juniper talk to NPS now?16:08
jon___juniper with ldap16:08
jon___to AD16:08
nowenok - so, you will have to switch to radius from ldap, because ldap has no proxying capability16:09
nowenhave you seen our how-to on NPS?16:09
jon___yes, i have read on the website16:09
nowenand the Juniper how to for radius?16:09
jon___not yet16:09
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-use-wikid-strong-authentication-with-juniper-uac-appliance/?searchterm=juniper16:10
nowenso, the Juniper will talk Radius to NPS, then NPS will proxy the auth request to WiKID after verifying the user16:10
jon___user will prompt to enter the pin with generate/verify from wikid system?16:11
nowenthe user will start the WiKID token and enter their PIN.  The PIN is encrypted and sent to the WiKID server. If the PIN is correct, the account active & the encryption valid, the OTP is generated on your WiKID server, encrypted and returned to the user16:12
nowenthen the user logs in with username & otp16:12
jon___hardware and software token both available?16:13
jon___otp is AD password?16:13
nowenjust software - windows, mac, linux, android, j2me, iphone, etc16:13
nowenno, the AD password is no longer needed16:13
nowenNPS checks the user for permissions etc.16:13
jon___is there a way we can configure so user require to put their pin and AD pass?16:14
nowenthat is a question for Juniper.  I would recommend against it. it is considered "good thing" to not use your LAN password outside the lan16:14
jon___ok16:15
jon___what's the pricing look like for our environment?16:16
nowenhttp://www.wikidsystems.com/learn-more/financial - $24/user per year16:16
nowenthere is also a 30% discount if you pre-pay for 3 years16:16
nowenbut - we have no hardware tokens - is that an issue?16:17
jon___well16:18
jon___If the user remotely use soft token on this machine16:19
jon___it still generate legit pin code?16:19
nowenyou mean - can the user move the token to a different machine?16:19
jon___yes16:20
nowenwe have what we call "locked tokens" that hash data from the computer during the token registration process.16:21
nowenthat data is sent to the WiKID server and must be sent with each OTP request16:21
nowenalso, you should be able to do mutual https authentication.16:22
nowenthat will thwart MiTM attacks16:22
jon___and what if the user remotely16:22
jon___it'll sync through https?16:22
jon___we have a few users who office remotely16:23
nowenno - the token will validate the SSL cert for the users - and will give a warning if the cert has changed.16:23
jon___does soft token on a remote machine require sync to the server to keep up with the pin changes?  Or just once time setup and it's good?16:24
nowenjust a one-time setup16:24
jon___k16:24
nowenwe have scripts on the server that allow users to register their tokens based on their AD creds16:25
jon___We have user that randomly connect to our vpn from their home machine16:26
jon___in this case they can't have a token on their pc16:27
jon___is there a way we can generate some pin through the web16:27
jon___base on their AD credential?16:27
nowenwell, we always need to store the keys on the local machine - they are the second factor16:27
nowenwe have an html5 token16:28
jon___how is it work?16:28
jon___they have to copy the file/key to run on their local machine?16:28
nowenhttp://www.wikidsystems.com/downloads/html5-token/16:28
nowenit's automatic,  but FF & chrome only16:29
nowenthey could also use a wireless token16:29
jon___Can you explain the wireless token?16:30
nowenit's just a software token that runs on a phone.  Android, iphone, blackberry16:31
nowenetc16:31
nowenwhat kind of phone do you have?16:31
jon___office phone or mobile?16:33
jon___mobile i have iphone16:33
nowenmobile16:33
nowenok - go to the market and search for WiKID16:33
jon___appstore you mean?16:33
nowenyeah16:34
nowen;)16:34
jon___Does the trial WiKID server require serial to install?16:37
nowenno16:37
jon___You just select trial option when you configure it?16:37
jon___and it'll expire in 30 days?16:37
nowenno selection needed, just follow the standard directions16:38
nowenwe track usage via the certificate you request during the install16:38
jon___what happen after 30?16:40
jon___we can't use the product anymore?16:40
nowenby license, but in truth, we haven't set up the 30 cert processor yet16:41
nowen;)16:41
jon___well, i'm curious because i'm planning to do the trial16:42
nowenplease do!16:42
jon___wanting to know if the software no longer function after 3016:42
jon___or it still work after 3016:42
jon___we just need to buy the licence to be legal16:42
nowenyeah, it works fine.  In fact, if you want to go into production with the same box that is fine16:42
jon___ok16:42
jon___does it require anything as far as the licence?16:43
nowenyeah - we tend to focus more on adding new features than worrying about stealing16:43
nowenjust the cert16:43
jon___ok16:43
jon___how big is the vmware image?16:44
nowen629 meg16:44
nowenif you're using esx, grab the iso instead16:45
nowenthen create your own vmware image and boot the iso.  the vmware image was created with the free vmware server16:46
jon___is there any firewall/vpn that WiKID not support?16:48
nowennot in the Enterprise space.  Where I define enterprise as supporting radius16:48
nowenradius is a great standard for authentication16:49
jon___I agree16:50
jon___Can I use the token installed on my iphone to authentication my remote laptop?16:50
nowenyes16:50
jon___how is it work?16:51
nowenyou get the OTP on your iPhone and on your laptop, you enter your username and the OTP into your juniper page16:51
jon___when I generate the OTP it require AD credential?16:53
nowennbo16:53
nowenno16:53
jon___well, I ask enough question16:53
nowenNPS will validate that the user is active in AD, has the right permissions, etc16:53
jon___I would love to have a demo for my team16:53
nowenthen it will proxy the username and OTP to WiKID for the final auth16:54
nowenok16:54
jon___when you can schedule one, please send invite to joe.tran@beryl.net16:54
jon___i will forward to my team16:54
nowenok will do16:54
jon___we just become a pci compliance ship16:54
jon___shop16:54
nowenahh16:54
nowenyes, then two-factor auth is required16:54
jon___so this project will need to get done the next 3 months16:54
nowenok - that's the audit?16:55
jon___well16:55
jon___the audit will be in January i think16:55
nowensometimes, we have PCI people that have auditors coming in the next week16:55
jon___we dont have the audit yet16:55
jon___oh16:55
jon___WiKID require auditor too?16:56
nowenno - we just get a lot of PCI business16:56
jon___oh ok16:56
jon___yeah16:56
jon___it sure create alot of business out of the pci thing16:56
jon___which is cool16:56
jon___what's your name?16:56
nowenI tend to think that a lot of merchants are way more secure than they would be16:56
nowenNick Owen16:57
jon___Thanks Nick16:57
jon___appreciated your time16:57
nowennp.  have a great holiday16:57
jon___do you have an email?16:57
nowenyeah, nowen@wikidsystems.com16:59
nowenjust sent you an email17:01
nowenok - running out to do some last minute xmas shopping.  jon___ do you want the link for the iso?18:59
*** nowen has quit (Quit: Leaving.)19:05
*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid22:30
*** nowen has parted #wikid (None)22:44

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!