Monday, 2011-03-07

*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid13:14
manonst_nowen: you around?14:32
nowenyes14:32
manonst_so v4 is going to support a new mechanism for domain codes, in addition to that14:33
manonst_i was wondering if the domain it registers to could download a logo - across the board for all clients14:33
nowenhmm14:33
manonst_then when the user sees a list of all of the tokens they have registered, perhaps a logo is next to it14:33
nowenyou mean like a favicon?14:34
manonst_i was hoping for larger than that14:34
manonst_but you want to target hosting environments and such14:34
manonst_branding is important14:34
manonst_let me get you an examplke14:35
nowenok14:35
manonst_do you have itunes?14:35
manonst_http://itunes.apple.com/us/app/entrust-identityguard-mobile/id384717687?mt=814:35
nowennot on this machine14:35
manonst_actually you can see via the web interface14:35
nowenyes14:35
manonst_that pitches wikid as the platform, but the provider as the service14:36
nowenyes14:36
nowenlooks nice14:36
manonst_as long as the logo is the right size14:36
manonst_its quite a bit of work to do for all clients, but it really gives it a polished branded feel14:37
manonst_and allows it to work server side automatically when you add the domain code14:37
nowenyes14:37
nowenlooks doable. I'm adding to the 4.x list14:40
manonst_cool14:45
manonst_i'm not sure we want to do this, but it might even be cool to offer logos on a per domain level14:45
manonst_to allow individual clients to use their own logos14:46
nowenyeah, we will do it on a per-domain level14:46
nowenwhat you do would then be up to you14:46
*** manonst_ is now known as manonst14:46
*** bigbash (~bigbash@pdpc/supporter/student/bigbash) has joined #wikid14:51
nowenhi bigbash14:52
bigbashHi nowen14:52
bigbashOh found what I was looking for :)14:53
nowenhehe, what was that?14:54
bigbashI wanted to make a nixie clock with a button feature that display/generate a token I was just looking for some C++ info14:54
nowennot sure I follow.14:55
nowenis the nixie clock to be an OTP generator?14:55
bigbashyes14:56
nowenhuh14:56
bigbashjust though it'd be a fun idea14:56
nowendoes the nixie clock have internet?14:56
bigbashA friend and I are challengin each other to design something with nixie tubes14:56
bigbashit will14:56
nowenok14:56
nowenwe don't have a C++ client.  java here, there is a python client14:57
bigbashhmm I think it was just the dll that I found14:57
nowendon't confuse network clients with token clients - the former is if you want to login to your clock, the latter for OTPs14:58
bigbashSays dll for the 3.0 WiKID Strong Authentication Server for ASP, VB, .net, C# and C++14:58
nowenthat's the network client14:58
bigbashah14:59
nowenso, can you use java or python?15:01
nowenor we can guide you in creating a C++ client, perhaps15:01
bigbashJava might work15:02
nowenwhat hardware are you using? is there a specs page?15:02
bigbashI'm going to use an arduino to control everything15:02
bigbashmost likely the arduino uno15:03
nowenok15:03
bigbashso if i did decide to write it from scratch where were you going to guide me to?15:07
nowenwell, I can send you the doc describing the token api15:08
bigbashthat would be awesome, i was trying to find it on the site15:08
nowenand if you read python: http://code.google.com/p/pywikid/15:08
nowenyeah, we don't get a lot of people wanting to write tokens, but maybe that will change15:09
bigbashCouldn't hurt to have plenty of options15:09
nowentrue, true!15:10
bigbashI'm going to idle here for a few, I have to run out and do something quick15:10
nowenk15:10
bigbashnowen, do you want me to pm you my email?15:54
nowensure, I'll put it up on the web somewhere soon, but that would be quickest15:54
bigbashok15:55
nowenahh ;)15:55
bigbashsame from twitter :)15:56
bigbashgot it15:57
nowenk15:57
bigbashnowen, the pdf seems to not have anything, I get an error on both linux and windows16:05
nowenresending16:06
*** makobug (~csec14_2@newproxy.umiacs.umd.edu) has joined #wikid16:26
nowenbigbash: it would help if I hit the send button16:36
bigbashhehe16:36
bigbashok it works16:37
bigbashthank you16:37
bigbashnowen, so is the UTF reg value the save as the deviceID?16:49
bigbash*same16:49
nowenno, they are not17:01
bigbashok, I'm just going through what's getting passed back and forth, I'm going to setup a test vm and just mess with stuff :)17:02
bigbashthanks again for the help and the doc17:02
nowenokl17:05
makobugQuick question about WiKID's password reset mechanism.  The website mentions that the WiKID server sends an OTP to the Domain Controller as the user's new password. So am I correct in assuming that the OTP [encrypted with the client's-pubkey] is sent to the client as well? Then when the client goes to log into the Domain Controller, said client is authenticated with this OTP ?17:36
nowenmakobug: that code has been deprecated, but that is correct17:37
nowenthe account is (was) flagged to require a password reset17:38
*** Makobit (~AndChat@129-2-142-19.wireless.umd.edu) has joined #wikid17:38
nowenit shouldn't be hard to add something similar back into the server17:38
*** Makobit is now known as Guest3056917:39
nowenthough we might do it differently17:39
*** Guest30569 has quit (Client Quit)17:39
makobughmm, mmkay17:47
nowenwhat's your use case?17:47
makobugI'm not entirely sure yet. I'm participating in a competition involiving hardening systems. We are introduced to a pre-existing network that will have a WiKID server in use so I wanted to make sure I understand the authentication scheme17:48
nowenhmm, interesting. is it some hacking comp?17:49
makobugIt's the Collegiate Cyber Defense Competition: http://www.midatlanticccdc.org/CCDC/17:49
makobugwe're on the defending side :)17:49
nowenawesome17:50
nowenbut then you have a short time frame?17:50
makobugyes indeed17:50
nowenwhat is the server configured to do?17:52
makobugWe're not entirely sure. We've been given pretty limited information: https://docs.google.com/viewer?a=v&pid=explorer&chrome=true&srcid=0B4IJmcpK0sWiZjFiNjAxMjItNWEyOC00Y2MwLTk2ZmUtNTQyZjQ1YzE0N2Nm&hl=en&authkey=CIjlpaoF17:54
makobugpage 11 has the network map, page 13 has general information and page 15 has the services we have to provide17:54
makobugmy guess currently is that it will be used to authenticate intranet users trying to access the OpenPDC web portal17:55
makobugas well as potentially using it to autheticate domain users for just about anything. It's my understanding that as long as we provide the necessary services, we can do just about anything with it. So using it as the big authentication mechanism for all of the machines on that intranet/the firewall would be awesome17:56
makobugit is also my impression that the intranet may not even be functioning correctly from the start. the WiKID server might not even be configured to authenticate anyone for anything :p17:56
makobugThanks for the help btw. I think my verbosity filter is off today :p17:59
makobugDrop me a line of you have any tips/time/thoughts you're willing to share :) thanks again (mako@umdcsec.org)18:07
*** makobug has parted #wikid (None)18:07
*** makobug (~csec14_2@128.8.135.198) has joined #wikid23:06
*** nowen has quit (Quit: Leaving.)23:18
*** makobug has quit (Quit: Leaving.)23:45

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!