Tuesday, 2011-03-29

*** WiKIDLogBot (~WiKIDLogB@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid12:42
pratchett.freenode.netUsers on #wikid: WiKIDLogBot malcolm_ @nowen12:42
malcolm_Hi nick12:54
malcolm_i will "cut and paste" :)12:54
nowenok12:54
malcolm_09:02] <malcolm_> Hi Nick [09:02] <malcolm_> I have a quick question please [09:03] <malcolm_> Is it possible to unlock user accounts via a DB script ? [09:03] <malcolm_> Our accounts on the server are being locked out - and never unlocking as our firewall is not releasing the session12:54
nowenso, this is the same issue?12:55
nowenwhat is the firewall doing?12:55
malcolm_i seems to not close the session12:55
nowenhow does that affect the WiKID server?12:55
malcolm_I believe there is a firmware update which we will have in the next weeks to fix12:55
malcolm_however until then12:55
malcolm_The accounts do not revert from being disabled12:55
nowenwhat kind of firewall is this?12:56
malcolm_ASA12:56
malcolm_with our old Radius it wasn't an issue12:56
nowenI've never heard of this from any of our other ASA users12:56
nowenwhat does it say in the WiKIDAdmin logs?12:57
malcolm_I asked and it seems a known bug - i'm not sure if we pehaps need a config change but the FW is managed by our datacentre12:57
malcolm_I can check - if you need me to12:57
nowenwell, you have access to the wikid admin, right?12:57
malcolm_yip12:58
malcolm_not usre what i'm looking for though ;)12:58
nowenin the logs, search for the string 'disable'12:59
malcolm_okay13:00
malcolm_nothing if I don't select a log file13:01
malcolm_however if I look at the users section13:01
malcolm_Stephen is logged in and his user is currently disabled13:01
nowenis log level set to debug?13:01
nowenok, what is his device id?13:02
malcolm_-374054516029882772713:02
nowenfind it on the user page and then search for it in the WiKIDAdmin logs13:02
malcolm_okay13:02
malcolm_it shows issued passcode13:03
malcolm_nothing about locking13:03
nowenand that's all?13:03
nowenlog level set to Debug?13:03
malcolm_i can check13:04
nowenon the WiKIDAdmin logs13:04
nowenthere is a drop down for the log level13:04
malcolm_No - we turned debugging off13:04
nowenno - look at the WiKIDAdmin log page13:04
malcolm_I am searching on the debug level13:04
nowentry setting the timestamp to days, instead of hours13:05
malcolm_sent you a snapshot of the output13:06
malcolm_also the current log levels13:07
nowenand you say he is disabled?13:07
malcolm_he was this morning13:07
nowenon the WiKID server?13:07
malcolm_when we got into the office13:07
malcolm_he couldn't login and I had to manually unlock him13:07
malcolm_in the users section13:07
nowenon the log filters, set com.wikidsystems, wClient, radius and wAuth to debug and apply changes13:08
malcolm_I don't seem to find the radius one13:10
nowencom.wikidsystems.radius.log.DBS...13:11
malcolm_ok cool13:11
malcolm_made that change13:11
nowenok - can you log into the VPN from where you are?13:12
malcolm_yes13:12
nowenok, give it a go and let's see what happens13:12
malcolm_cool - i'm in13:13
nowenok, so what's in the logs?13:13
malcolm_I see this - even though I managed to login13:15
malcolm_com.wikidsystems.radius.access.WikidAccess4Access denied for msiegel, domain code: XXXXXXXXXXX client: /192.168.10.113:15
malcolm_also this13:16
malcolm_135> Access-Request(1) LEN=216 192.168.10.1:1025 Access-Request by msiegel Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.13:16
nowenok, do you see one earlier that was accepts?13:16
malcolm_yes13:16
malcolm_Access-Accept(2) LEN=216 192.168.10.1:1025 Access-Request by msiegel succeeded13:16
malcolm_and my vpn is working13:16
nowenok, so the first one was accepted, then how many others?13:16
malcolm_funnily my user account is not disabled13:17
nowennot yet, perhaps, but each time the VPN sends the OTP is another bad passcode attempts13:17
malcolm_i see 1 denied and 1 bad mschap request13:18
nowenwhat is the Max bad password attempts limit on the domain?13:19
malcolm_613:19
malcolm_PCI requirement13:19
malcolm_hmm - i see where you are going13:20
nowenany more requests in the log?13:20
malcolm_no - only stephen and I are logged in13:20
nowenI mean any more auth validation requests for your account from the VPN13:21
nowencan you get me the radius configuration information from the ASA?13:22
malcolm_no13:22
malcolm_sorry13:23
nowencan you ask if accounting is on?13:23
malcolm_I can try and obfuscate it a bit13:23
malcolm_give me a sec13:24
nowenok - I'm going to grab some coffee brb.13:25
nowenif you WiKID max bad passcode attempts is set to 6, you should have gotten more failed attempts from the ASA13:31
malcolm_i have gotten no more failed attaempts13:55
nowenhmm and you're not disabled?13:55
malcolm_no13:55
malcolm_only stephen is disabled - also logged in13:56
nowenwell, remember that the session is managed by the ASA and wikid has nothing to do with that13:56
nowenonce the user is validated, the ASA is in charge of the session13:56
nowendid you find out if radius accounting is turned on on the ASA?13:57
malcolm_still awaiting the latest config13:57
malcolm_Nick I have to run - attending a webinar now14:01
malcolm_I will try pick this up tomorrow14:01
*** malcolm_ has quit (Quit: Page closed)14:01
*** new_purchaser (4658e7ca@gateway/web/freenode/ip.70.88.231.202) has joined #wikid19:08
new_purchaser@nowen: will I need to re-key after purchasing a license?19:09
nowennew_purchaser: no19:10
nowennew_purchaser: just about to process your payment - probably later today19:10
new_purchaserThat's great news.  Appreciate it!19:11
nowenno problem thanks for the business!19:11
*** new_purchaser has parted #wikid (None)19:11
*** nowen has quit (Quit: Leaving.)22:22

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!