Friday, 2011-01-28

*** Marcel (507fdbd1@gateway/web/freenode/ip.80.127.219.209) has joined #wikid09:34
*** nowen (~nowen@pool-72-83-75-46.washdc.east.verizon.net) has joined #wikid13:44
nowengreetings. Let me know if you have any questions about WiKID13:45
*** Marcel has quit (Quit: Page closed)15:07
*** Reinier (507fdbd1@gateway/web/freenode/ip.80.127.219.209) has joined #wikid15:07
Reinierhello15:08
nowenhi15:10
nowenstill getting the same error?15:10
Reinierwe checked the logs now, the logs said "Could not validate the client certificate"15:11
nowendid you create the intermediate and localhost certs?15:11
Reinieryes15:12
nowenand restart the server?15:12
Reiniermultiple times now, but it still gives that weird "0" when trying to connect15:13
nowenhow did you install the server?  iso, vmware image, rpm?15:13
Reinierwith the iso15:14
nowenhave you tried running the token in debug mode?15:14
Reinierwe've tried that, but when we try to change the jw.properties in the .jar package the token chrashed15:15
nowenoh - drop the jw.properties file in the same directory as the jar file15:16
nowenit will use that one instead15:16
nowenif it works, you can paste the output into http://pastebin.com15:22
nowenhow did you find out about us?  all the sudden we've got a spate of .nl traffic ;)15:24
nowenbrb - got a quick meeting15:26
*** Reinier_ (507fdbd1@gateway/web/freenode/ip.80.127.219.209) has joined #wikid15:30
*** Reinier has quit (Ping timeout: 265 seconds)15:32
Reinier_hello i posted it on pastebin15:35
Reinier_http://pastebin.com/U6JuLKmg15:35
nowenhmm, vista... did you install the token in a directory you can write to?15:37
Reinier_we found out about WiKID when we bought our new firewall15:37
Reinier_a netgear15:38
nowenahh15:38
nowenyes, they have a special radius thing for us15:38
Reinier_sorry its a windows 7, detection error i think ;)15:38
nowenall that  "NET_ADDR:       null" stuff is odd15:38
nowensame thing, I think, the user cannot save data to c:/program files/15:39
nowenalso, see what happens when you browse to http://192.168.100.81/wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=192168100081&CT=115:39
Reinier_i get a http status 405 - http method GET is not supported by this URL15:42
nowenok, that's ok - and where is the token installed?15:43
nowenalso, will you run 'date' on the terminal and make sure it is correct15:44
Reinier_we've got the token installed on c:\program files and we tried to copy it to the my documents folder, the account is a local admin account15:44
Reinier_the date is correct15:45
nowentry to add this domain:  8888888888815:45
nowenif your token client can't add that domain, then it is a problem with the token15:48
Reinier_it could not connect with 88888888888815:51
nowenok - can your rerun the installer and when prompted for the location, choose the User15:52
nowenfolder?15:52
nowenor you can just drop this http://www.wikidsystems.com/webdemo/tokens/j2se/3.1.10/wikidtoken-3.1.10.exe into a user folder15:52
nowenor you can use the web start token: http://www.wikidsystems.com/webdemo/tokens/j2se/3.1.8/token.jnlp15:53
nowenthe web start token is pretty cool actually and very customizable via text files on a server15:57
Reinier_we've tried both the user folder option and the web start token, both have the same results :(15:58
nowenis there a firewall on this pc that would block the token?15:59
Reinier_we've disabled our firewalls16:00
nowendo you use an outside DNS provider?16:03
Reinier_we have a internal dns server that relays to our ISP (if  the right way to say it in english?)16:04
Reinier_*(is that16:04
nowenyes, ok16:04
nowendo you get the same output from the token debug for both your domain and the 888 domain?16:05
Reinier_yes16:05
nowenI wonder if there is a problem with your routing - the token request goes out, but the response comes back at a 016:05
nowenthat could mean that the response is getting blocked or that the response is just not getting back to the token16:06
Reinier_it shouldn't go outside right now, we're still in the 192.168.100.x network, it should never pass our gateway16:07
nowenyeah16:09
nowencan you get out from the WiKID server?16:09
Reinier_yes we can go outside from the wiKID server16:13
nowen in your logs, where is says that it couldn't validate the certificate is a little bomb icon.16:16
nowencan you click on that and pastebin the results?16:16
Reinier_http://pastebin.com/4VeWfDts16:21
nowenon the terminal, can you run 'ls-all /opt/WiKID/private'16:23
nowenyou should be able to paste that here16:23
Reinier_http://pastebin.com/DJSAwqZF16:27
nowenwhat happens when you browse to http://888888888888.wikidsystems.net?16:29
Reinier_i arrive at the wikidsystems homepage16:29
nowenhmm16:30
nowenman i am  a bit stumped here16:30
nowenwhen you restart the token are you prompted for a passphrase?16:31
Reinier_What would be the next logical step? it's getting late over here, the company is going to close, could you send us a e-mail?16:32
Reinier_yes we get prompted for a passphrase16:32
nowenhmm16:32
nowenyes, maybe a little sleeping on it would be good16:32
nowenyou can also try from a different computer16:33
nowenvery odd16:33
nowenIf I think of something, I will send you an email16:33
Reinier_that would be great, thank you for the support :)16:34
*** Reinier_ has quit (Quit: Page closed)16:35
*** nowen has parted #wikid (None)16:36
*** nowen (~nowen@m552336d0.tmodns.net) has joined #wikid19:43
Ownagenowen: you gonna be on for a bit?19:48
OwnageI'm about to head to lunch in 10 mins for about an hour19:49
Ownagebut if you're gonna be around after that, I could use some help if you're up for it19:49
nowenProbably not that long, but I can check back in.19:50
nowenI'll log in an hour or two if that works19:51
*** nowen has quit (Quit: Bye)20:17
Ownagenowen I'm back. I don't see leaves and joins so just holler when you're around. thanks21:15
*** nowen (~nowen@m552336d0.tmodns.net) has joined #wikid21:24
nowenOwnage you there?21:25
Ownageyessir21:25
nowenHow's it going?  What issues are you having.21:26
nowenBtw, I'm on my phone, so limited capabilities21:26
Ownagewhat I'm trying to do is be able to pick and choose based on username and/or ip who can log in to our google apps account21:27
Ownagethat's really the only thing I want to do21:27
Ownageso that has led me down this path where basically looks like I need SSO21:27
Ownagewhich brought me here to wikid21:27
Ownageso anyways, I've got wikid up and running, but I've not figured out how to successfully get google to auth with it21:27
Ownagethere's a couple of issues I'm having21:27
nowenOk21:28
Ownagefirst of all I can't seem to find any documentation about what URLs to use for the google sso settings21:28
Ownagehttps://public-fqdn-of-wikid/_what_ for example21:29
Ownagethe only thing I could really find was a howtoforge article21:29
nowenYou mean on the google setup page?21:29
Ownageright21:30
Ownagethe howtoforge uses /wikid/GSSO21:30
Ownageand then two apparently random URLs21:30
Ownageso what I did was use /wikid/GSSO and google.com and google.com21:30
Ownagehowever I fail auth on trying this way21:30
Ownageso I guess the first Q is: is that what it's supposed to be?21:31
nowenLook in the /opt/WiKID/tomcat/webapps/wikid/21:32
nowenIs there a GSSO directory or has the name changed?21:33
Ownagethere is not21:33
OwnageWEB-INF, META-INF, errors, ADRegister, images21:34
Ownagethose are the dirs21:34
nowenDid you enable it under protocols?21:35
Ownageyes21:35
nowenHmm.21:35
Ownageverifying21:36
Ownagedefinitely enabled, showing green enabled21:36
Ownagethe server has been restarted as well21:36
OwnageI'll disable, re-enable21:38
OwnageI did a search before and after21:38
Ownageno new files or directories are created from disabling or enabling21:39
Ownagein case you can see pastebins, here are the 5 items which show for locating GSSO: http://pastebin.com/TYBFv8dc21:39
Ownagetrying a service stop, start for good measure21:40
Ownageweird wikidctl stop is taking forever21:41
nowenHmm21:41
Ownagethere it goes21:42
Ownageprobably vm-related21:42
nowenI can't get to my lab machines from here21:50
OwnageI understand21:51
nowenI can check on it first thing Monday. Not sure what's going on21:52
nowenI'm also pinging someone else.21:54
nowenIf I hear back I will hop back on and let you know. Otherwise, I'll be back on monday22:15
Ownageno problem thanks man22:16
nowenLater22:16
*** nowen has quit (Quit: Bye)22:16

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!