Monday, 2011-03-14

*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid13:00
*** dhahn (266f9a61@gateway/web/freenode/ip.38.111.154.97) has joined #wikid21:13
dhahnHello21:13
nowenhi21:13
dhahnI'm having a little trouble understanding if I can use wikid with my Cisco PIX boxes and what the user would experience in logging onto the system.21:14
nowenok21:14
dhahnJust trying to understand21:14
nowenthe user would login with their username and the WiKID OTP, which they would get from the token21:14
dhahnAnd they can get the token from a client on their machine or their smart phone?21:15
nowenyes21:15
nowentho, you can limit that to one or the other if you want21:15
dhahnok, that's good to know21:15
dhahnIs there any information on if the native OS X IPSEC client works with the wikid OTP to a cisco box?21:16
dhahn(I know that's a very specific question)21:16
nowenhmm21:17
nowenif the ipsec client supports radius, I don't know why there would be an issue.  but that might be a big if21:18
dhahnok.  I'll see if I can run down that piece21:19
nowenit should just send the password through to the auth server, right?21:19
dhahnI think so.  Are they sending their passord or the code from the OTP or both?21:22
nowenwell, that's really a question for cisco.  most people tho use only the OTP. most vpn clients are setup that way.  and there is a benefit in not using the lan password outside the lan21:23
dhahnSo, they would provide their username and the OTP code?21:24
nowenyes21:24
nowenyou can run it through AD if you like using the MS radius plugin21:25
nowenias/nps21:25
nowenand you can do the same with freeradius21:25
dhahnOK.  I think that's fine as the Cisco just asks the wikid/RADIUS server if the auth is good21:25
dhahnFreeRADIUS is likely.  We don't have an MS infrastructure.  Mostly macs21:25
nowenwhere are the users stored?21:25
nowenwe have a how-to for freeradius/openldap21:26
dhahnAt this time, we move credentials around manually to the systems that need them.  passwd files, et al.  Looking to add openldap later, but, not before this is solved.21:27
dhahnSo, in this scenario, I'm guessing we'd feed freeradius via PAM with the passwd/shadow files and then wikid for the OTP code?21:28
nowenwell, you can just have the users in WiKID.  Or you could setup freeradius and have it go to WiKID.  then when you add openldap, you can just re-config freeradius21:28
dhahnCan wikid use PAM authentication credentials for the user list?21:28
nowenyes, or straight to WiKID.  The benefit of using freeradius is that you don't have to change the individual configs later21:28
nowennot sure I follow - what do mean user list?21:29
dhahnI expect we'll be going through quite a few changes later, so, fastest to completion is likely the option that will win.21:29
dhahnUserlist - somewhere there has to be a tie together of the username and the OTP issued isn't there?21:29
nowenso, for PAM, there are a couple of things to set, if you set auth and account to use radius, then the list will be in WiKID (or radius server),  does that answer the question?21:31
nowenIt depends a bit on the OS21:32
dhahnI think so.  It would be a linux based server and mac and windows clients.21:32
nowenbut if you set account for local, then the user has to have an account on the local system21:32
dhahnwe typically update /etc/passwd files, so, that's easy to manage21:32
nowenyeah, then I think just have the auth go to WiKID21:34
dhahnok, sounds good.  Thanks for the help.21:34
nowennp21:34
nowenfeel free to download and get it set up21:34
dhahnWill do21:46
*** dhahn has quit (Ping timeout: 252 seconds)21:50
*** nowen has quit (Quit: Leaving.)21:57

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!