Friday, 2011-02-11

*** Subhash (ca3f7192@gateway/web/freenode/ip.202.63.113.146) has joined #wikid09:47
Subhashhi09:47
Subhash12345678912309:48
Subhashii am seeing the wClient connection to the server was NOT successfully established09:48
Subhasherror09:48
Subhashii am seeing the wClient connection to the server was NOT successfully established [15:19] <Subhash> error09:49
*** Subhash has quit (Quit: Page closed)12:16
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid13:55
*** nowen has quit (*.net *.split)15:20
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid15:21
*** ChrisClymer (62672c03@gateway/web/freenode/ip.98.103.44.3) has joined #wikid18:13
ChrisClymerHey Nick...quick question18:13
ChrisClymerI'm looking into some of the ways to tie Wikid into windows logons18:14
ChrisClymerIt sounds like IAS/NPS can be used to add two-factor auth to the windows platform18:15
ChrisClymerits unclear to me if that allows for adding the second factor to local or RDP window system logins18:15
ChrisClymerand I've also heard some rumblings that this will work for windows servers, but is problematic on Domain Controllers18:16
ChrisClymerany thoughts?18:16
nowenhey chris - still there?18:43
ChrisClymeryup18:44
nowenso, if you want to change the windows login, you have to change the GINA18:45
nowenthe ctlr-alt-del thingy18:45
ChrisClymernowen, I suppose another way for me to ask is:  how would you tie WiKID into windows login18:45
* ChrisClymer nods18:45
nowenyou can do that with PGINA18:45
nowenhttp://www.pgina.org/index.php/Main_Page18:45
nowenI tested it years and years ago18:45
nowenit worked18:45
ChrisClymerhm.  but not neccesarily something you want to do on a DC18:46
nowenno, the other option would be to run everything through a vpn or ias18:47
nowenisa that is18:47
ChrisClymeryeah, thats the other option I was considering...surprised that there don't seem to be better solutions here18:48
ChrisClymeralso, your name comes up in almost every search query I've done around this :D18:48
nowenhehe, yeah18:49
nowenwhat is the scenario?18:49
ChrisClymerin a nutshell just trying to put two-factor auth of some sort around RDP logins to DCs on an internal network18:50
ChrisClymerso a VPN solution seems overcomplicated18:50
nowenyeah18:50
ChrisClymerRSA has some agent-based solutions...and specifically reccomend not using them on DCs, which doesnt give me great confidence in the agents18:52
ChrisClymerI'm guessing they're doing the same thing that PGINA does18:52
nowenyeah18:53
nowenand MS has not been good about letting people change the gina18:54
nowenthe RSA code has stored "OTP"s i think - so you can login to your laptop without network access18:54
manonstnowen: i found a better way20:26
manonstcommerical though...20:26
manonsthttp://www.lsexperts.de/download/LSE_RadiusCredentialProvider_Flyer_EN_rev3.pdf20:26
manonstthey have a separate version for GINA versus credential provider20:27
nowenhmm20:28
manonstkinda pricey20:29
manonsti think 250 users was like $5,60020:30
nowenwhy is it better than pgina?20:37
manonstuntil recently pgina was kind of a dead project20:52
manonstthey went silent from 2007 to 2010 - hopefully its being actively maintained20:53
manonstbut that would worry me20:53
nowenyeah, it was dead for a while21:13
manonsti should check it out again, the project has completely revamped - i haven't played with 2.x21:20
manonsthmm RADIUS plugin link doesn't appear to work21:28
manonsthttp://www.pgina.org/index.php/Plugins21:28
manonstactually most links appear broken21:29
nowenyeah21:35
nowensf recently updated a lot of stuff21:36
nowenhttp://sourceforge.net/projects/pgina/files/21:36
manonstyeah found it, no documentation21:38
manonstbut at least ldap and radius are supported under 2.x for x6421:38
nowenit's interesting, but honestly most companies don't want to risk screwing with the gine21:40
nowengina21:40
manonstyeah, i've seen a lot of issues in the past21:40
manonstthe credential provider paradigm is different however21:40
nowenwhat do you mean?21:41
manonstGINA only applies to Windows versions < Vista/2k821:41
nowenoh, is windows 7 doing something different?21:42
manonstyep, Vista, 2k8, Win7, 2k8 R2 use a credential provider21:42
nowenok - guys I'm out of here.  I will be scarce next week - vacation time23:02
*** nowen has quit (Quit: Leaving.)23:03
*** ChrisClymer has quit (Ping timeout: 245 seconds)23:12

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!