Wednesday, 2011-03-09

*** Withoutaname (~Withoutan@unaffiliated/withoutaname) has joined #wikid00:06
*** Bart_ has quit (Ping timeout: 245 seconds)02:22
*** Withoutaname has quit (Read error: Connection reset by peer)09:21
*** AiaBart (d57e804a@gateway/web/freenode/ip.213.126.128.74) has joined #wikid10:58
AiaBartI was wondering if MS Chap2 was supported, because I am using it (in my ISA/IAS) setup, but authentication returns errors mentioning "Microsoft MS-Chap failed authentication"11:00
AiaBartSeems to be supported, but that doesn't make my setup work =)11:07
*** AiaBart has quit (Quit: Page closed)13:50
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid15:36
*** Aargh (d57e804a@gateway/web/freenode/ip.213.126.128.74) has joined #wikid16:02
AarghAargh =) I had it WiKID working with ISA2006/IAS and WiKID and a "Test" internal domain but ...16:03
AarghI had a created a user Bart and a token and it worked (after I figured out that usernames became case sensitive when using WiKID)16:04
AarghBut now I created an externally reachable domain 213******** instead of 010001*******16:05
nowenAargh: did you change the network client to the new domain?16:05
AarghYup, I used a client on my iPhone (which does work nicely)16:06
nowenright - but on the WiKIDAdmin, did you also edit the Network Client page?16:06
AarghBut the problem seems to be (logs) that the old user is being validated (old Bart on 010000 domain) not existent anymore)16:06
AarghNo, I didn't16:07
AarghMy ISA server and my IAS server are still there. Should I recreate those as well?16:08
nowendo that and be sure to restart - the radius plugin caches the info16:08
nowenthat depends on what you want to do.16:08
AarghThanks, I'll try that now.16:08
nowenyou probably should have all your traffic go through IAS16:09
nowenthat way, when a user is disabled in AD, they are locked out.16:09
AarghWell, I want the IAS Radius thingie to authenticate me as Bart16:09
AarghYou mean, IAS should be my gateway?!16:09
nowenno16:09
nowenthe credentials should go from ISA to IAS to WiKID.16:10
AarghBlind me hadn't seen I could/should change the domain on the "client" page16:10
nowenso, the ISA should not be in WiKID16:10
nowen;)16:10
AarghPS: The "manual" install guides didn't mention the "case sensitivity" which I have seen.16:11
nowenyou mean there are still OSs that aren't cap sensitive ;)16:12
AarghErrr, alas yes ... not everyone is running an OS with sense16:13
nowenhaha16:13
AarghAargh, still not working atm, stupid IAS server, something so slow there. Not patching anything through to WiKID server.16:17
nowenso, is the last thing you see the passcode request?16:18
AarghYup. And the IAS log files not being updated.16:18
AarghNo the code being issued =)16:21
nowenwhat I mean is in the WiKIDAdmin logs, if the last thing you see is the passcode being returned to the token, then you know that the request is not getting from IAS to WiKID16:22
nowenif you see anything after that, then  it should be the request from IAS16:22
AarghIssued passcode to device 235........ is the last code16:23
AarghWoohoo it's working! Blood, sweat and tears and mostly waiting after I learned that not everything was updated/active in a second in the Windows world.16:26
nowenhehe16:33
nowenyou know, a lot of the stuff that happens during config can be a pain, but it just doesn't happen in production when you're not changing everything16:34
*** malcolm (29df2122@gateway/web/freenode/ip.41.223.33.34) has joined #wikid16:46
malcolmhi there16:46
nowenAargh:  what version of iPhone OS are you running?  I just had someone say they were having troubles16:46
nowenhi malcolm16:46
malcolmwe are looking to install on sles and are having issues with the rpms16:47
malcolmany chance we will be able to chat to someone on the phone ?16:47
nowenmalcolm: the rpms are really Redhat rpms16:47
malcolmhow would we build it on sles ?16:48
nowenif you download the ISO, it is essentially centos16:48
nowenI'm not really familiar with sles.16:49
nowenbut some people have gotten it running on ubuntu16:49
nowenand other flavors16:49
malcolmi assume the source is closed ;)16:49
malcolmfor the enterprise edition16:49
nowenyes, but the only difference in the code is the radius plugin and the wireless encryption16:50
nowenif you want to make changes to the scripts, etc, we will accept them16:50
nowenbut, we have to review all that stuff - it is a security app after all16:50
malcolmi understand16:51
malcolmWe need a solution to work with our Cisco ASA550516:51
nowenwe're working on debian packaging now16:51
malcolmthis seems to be the best16:51
malcolmWe were using AD auth but now for PCI it is no longer 2 factor16:52
nowendo you have to have sles?  the iso comes with everythning needed16:52
malcolmI know but finding a box in production is a major hassle and we need to have it working by friday16:52
nowenooh16:53
nowendo you do any virtual stuff?16:53
malcolmonly in our test eniron16:54
malcolmCan I get a copy of the enterprise source16:55
malcolmit will probably be the easiest to complile16:55
nowenyes, I can do that16:56
malcolmcool - can I get a download link please16:56
nowensend me an email to nowen at wikidsystems.com16:56
malcolmokay17:01
malcolmI've sent17:01
nowenwe might be able to incorporate sles into our built, not sure17:01
malcolmgreat - lets hope the source will work17:05
nowenmalcolm: what else will you have running on the server?17:17
malcolmOpanldap, rsyncs17:29
nowenok - the wikid token uses port 8017:29
malcolmwhat does that mean ?17:49
nowenthe tokens talk to the WiKID server over http17:49
malcolmdoes that mean we need to allow access to the server fromthe web ?17:49
malcolmAlso - we seem to have it installed17:50
malcolmon sles17:50
nowenthat was fast17:50
malcolmwhat is the default username17:50
malcolmand password17:50
nowenany documentation is much appreciated17:50
malcolmthe WiKIDAdmin is not working17:50
malcolmi am guessing that we may have dbase issues17:50
nowenWiKIDAdmin/2Factor.  if it is not working, it is a db issue17:50
nowenyes17:50
malcolmdammit17:51
malcolmbut it seems we are 90% there17:51
nowendid the db config script run ok?17:51
malcolmso talk to me about tokens17:51
malcolmno we did it all manually17:51
malcolmthe db stuff17:51
malcolmand we created symlinks etc17:52
malcolmso basically our wikid server needs to have internet access for the tokens ?17:52
nowenyes17:52
malcolmdoes it speak to your server directly ?17:52
malcolmor do the token clients speak to it ?17:52
malcolmso if we needed we could lock the FW rules down.17:53
nowenthe tokens send the PIN to the server, the server responds with the OTP.  all encrpyted, etc http://www.wikidsystems.com/learn-more/technology/overview17:53
nowensure17:53
nowenbut the server needs an external ip.  it can be nat'd17:54
malcolmok - so from Internet17:55
malcolmYour IP -> our IP (port 80)17:55
malcolmand our ip to your ip port 8017:56
nowennot quite.  the token talks directly to your IP17:56
malcolmencrypted but running over normal web port17:56
malcolmah ha - ok - how does it get our address ?17:56
malcolmI can see the 12 digit domain code17:57
malcolmbut not sure how that relates to our domain >17:57
malcolm?17:57
malcolmdo you have a landline ?17:58
malcolmare you at  your offices - maybe it would be better to chat17:58
nowenthe 12 digit codes is your IP.  So , 65.192.1.1 becomes 06519200100117:59
nowenI have to go out for a meeting, sorry17:59
nowenin fact, I have to go now.18:01
nowenhttp://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/referencemanual-all-pages18:02
nowenoopp18:02
nowens18:02
nowenmalcolm: check out the commands on this page: http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-install-the-wikid-enterprise-rpms18:02
nowenthe db needs to be loaded18:03
nowenyou might just be able to run /opt/WiKID/sbin/load_db.sh18:03
nowenonce you get logged in go to that first line18:03
nowenlink and follow the manual18:03
nowenI'll be back in about 3-4 hours18:04
*** nowen has quit (Quit: Leaving.)18:04
malcolmthanks18:14
*** malcolm has quit (Quit: Page closed)18:14
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid20:21
*** nowen has quit (Ping timeout: 276 seconds)21:58
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid22:10
*** nowen has quit (Quit: Leaving.)23:41

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!