*** alamarca has quit (Ping timeout: 240 seconds) | 06:21 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 06:34 | |
*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid | 12:12 | |
*** perestrelka (~vlad@194.242.5.47) has joined #wikid | 12:25 | |
perestrelka | hello, anybody around? | 12:25 |
---|---|---|
nowen | yes | 12:29 |
nowen | perestrelka: let me know what you need | 12:30 |
alamarca | hi nowen | 13:00 |
nowen | hello alamarca | 13:04 |
*** alamarca has quit (Ping timeout: 246 seconds) | 13:05 | |
perestrelka | nowen: can my question on licensing of wikid can be answered here? | 13:15 |
nowen | sure | 13:15 |
perestrelka | if we plan to have two replicating wikid servers, will this require us to license twice of seats we plan to have? | 13:17 |
nowen | no, just one set of seats | 13:17 |
perestrelka | nowen: good. thanks =) | 13:17 |
nowen | np :) | 13:17 |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 13:26 | |
alamarca | hi nowen | 13:27 |
nowen | hi alamarca | 13:27 |
nowen | how was your demo? | 13:27 |
alamarca | nice | 13:27 |
alamarca | two customers saw the same day, both are interested and asked prices | 13:28 |
alamarca | now I have to train more in the product for both win | 13:28 |
nowen | nice. | 13:29 |
perestrelka | can I get a download link to iso of wikid entreprise server? Looks like Radius support is not availabile in community edition I'm testing currently | 13:30 |
perestrelka | hm.. VMware image would be even better | 13:30 |
nowen | http://wikidsystems-dl.com/WiKID_Enterprise-3.4.55.vmware.zip | 13:31 |
alamarca | need more tutorial please nowen | 14:03 |
nowen | alamarca: what do you want to do? | 14:05 |
nowen | http://www.wikidsystems.com/support/wikid-support-center/how-to < lots of tutorials there (but english only) | 14:06 |
alamarca | ok thnxs | 14:06 |
nowen | you should set it up to work with your VPN | 14:06 |
alamarca | which was not to enter the directory to wikidadmin | 14:07 |
*** mjc_ (~mcarey@74.61.243.29) has joined #wikid | 14:12 | |
perestrelka | nowen: thanks again | 14:19 |
nowen | np | 14:19 |
mjc_ | nowen: this is Marcus, how you doing | 14:37 |
nowen | mjc_: on the phone brb | 14:37 |
nowen | what's up mjc_? | 14:50 |
nowen | welcome to #wikid :) | 14:50 |
* alamarca read | 14:55 | |
nowen | alamarca: I'm sorry, can you repeat? | 14:56 |
alamarca | anything from reading the manuals | 14:56 |
*** Ken_ (a5bd4f32@gateway/web/freenode/ip.165.189.79.50) has joined #wikid | 15:58 | |
Ken_ | Greetings all | 15:58 |
nowen | hi Ken_ | 15:58 |
Ken_ | NE1 have an idea as to where the wkd file is located on a Mobile Device such as Andriod? | 15:59 |
nowen | hmm. I might have to ask around, or dig on my phone | 16:00 |
Ken_ | I took a look at my phone and could not locate one. Is it stored differently on mobile devices? | 16:04 |
Ken_ | It being the cert | 16:04 |
nowen | well, they all tend to have the "sandbox" model, with their own directory, etc | 16:05 |
Ken_ | Yeah I need to remove change the cert with my testing and it will be a requirement for support if it gets to that | 16:06 |
Ken_ | Oh I gave up on the AD reg | 16:06 |
nowen | by cert do you mean the wikidtoken.wkd file? | 16:07 |
Ken_ | yes | 16:08 |
nowen | hmm | 16:08 |
nowen | not sure I follow, you can just delete the domains, correct? | 16:08 |
nowen | btw, we intend to re-write the android token. the ui is problematice | 16:08 |
nowen | -e | 16:08 |
nowen | hmm, so, you never figured out the AD thing? Maybe you could run it inside on a separate server and have the traffic go the other way? | 16:12 |
Ken_ | Yeah I noticed. The client is bound to the domain it was setup to. How do you set the client to auth to a new domain once one has been setup? | 16:12 |
nowen | If you hit the menu button, is there an option for Add Domain? | 16:13 |
*** vp_ (40b3d246@gateway/web/freenode/ip.64.179.210.70) has joined #wikid | 16:15 | |
vp_ | Hi, Owen. | 16:16 |
*** vp_ has parted #wikid (None) | 16:17 | |
Ken_ | It does but the recreated domain has the same name | 16:17 |
alamarca | in IPhone sometimes when I enter a domain closes the application and does not add the domain | 16:17 |
alamarca | but you put your name in the administration of WiKID | 16:18 |
nowen | Ken_: ahh, same name, different ID? | 16:18 |
alamarca | I changed the name but shows it with the same name (the domain) | 16:18 |
Ken_ | Same name and ID | 16:19 |
nowen | alamarca: hmm, you might need to delete the old domain | 16:19 |
nowen | Ken_: did you delete the old one? | 16:19 |
nowen | if you hold your finger down on the domain, a menu pops up to delete | 16:20 |
Ken_ | It's a new VM Build with the same domain information | 16:20 |
nowen | Ken_: you still need to delete the old domain and re-register | 16:21 |
alamarca | I was just trying to understand and help KEN, thnxs nowen | 16:21 |
nowen | ;) | 16:22 |
alamarca | i follow in twitter | 16:22 |
alamarca | nice picture | 16:22 |
alamarca | :D | 16:22 |
nowen | hehe, same to you :) | 16:22 |
alamarca | AHAHA | 16:23 |
alamarca | thnxs | 16:23 |
alamarca | close the app in the iphone, when add domain | 16:23 |
alamarca | :( | 16:23 |
nowen | what version of IOS ? | 16:23 |
alamarca | 4.3.2 | 16:24 |
nowen | alamarca: can you add 888888888888? | 16:27 |
alamarca | yes | 16:28 |
alamarca | :S | 16:28 |
nowen | is your iPhone on wifi? | 16:28 |
alamarca | yes | 16:29 |
alamarca | :/ | 16:29 |
alamarca | but my domain is 201246118158 | 16:29 |
nowen | yes, it is a problem with DNS and a change we should make | 16:29 |
alamarca | yes | 16:29 |
alamarca | this domain that you gave me where I can validate? | 16:30 |
nowen | the token first checks DNS, so 201246118158.wikidsystems.net, which should fail | 16:30 |
nowen | however, many DNS providers point you to a search page instead of failing properly | 16:30 |
nowen | this confuses the client | 16:30 |
alamarca | yes | 16:31 |
nowen | so, if DNS works, no problem. We need to catch it better, though | 16:31 |
*** vp (40b3d246@gateway/web/freenode/ip.64.179.210.70) has joined #wikid | 16:34 | |
vp | Hi Nick | 16:35 |
nowen | hi | 16:35 |
vp | am trying to migrate to the new version right now. | 16:35 |
nowen | from what version? | 16:36 |
vp | pg_dump -h localhost -U postgres -p 3333 wikid > remotedump.sql gives me open failed: connect failed: connection timed out | 16:36 |
vp | can you please help me out on this? | 16:36 |
vp | from version 2.0 build 109 | 16:37 |
nowen | holy cow | 16:40 |
nowen | how many users do you have? | 16:42 |
nowen | nevermind, I have it in email | 16:42 |
nowen | vp: let me dig up some docs on that | 16:43 |
vp | sure, please. thx. | 16:43 |
nowen | http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-upgrade-to-the-wikid-strong-authentication-server-3.0/?searchterm=2.0 | 16:46 |
nowen | those docs are pretty old, but worked for earlier 3.x releases | 16:46 |
nowen | so, first setup a 3.x server | 16:47 |
vp | that is what I am following, but when I came to a part where Creating a copy of the 2.0 database | 16:50 |
vp | I typed "pg_dump -h localhost -U postgres -p 3333 wikid > remotedump.sql" | 16:50 |
vp | and it returned an error message with "channel 2: open failed: connect failed: Connection timed out" | 16:51 |
nowen | run 'netstat -anp | grep 3333' | 16:51 |
nowen | does it return anything? | 16:51 |
vp | you mean when I typed "pg_dump -h localhost -U postgres -p 3333 wikid > remotedump.sql"? | 16:52 |
vp | no, nothing but the error message with "channel 2: open failed: connect failed: Connection timed out" | 16:52 |
nowen | no, I just mean run that command and make sure that the ssh tunnel is still up | 16:52 |
vp | so I run "pg_dump -h localhost -U postgres -p 3333 wikid > remotedump.sql" after 'netstat -anp | grep 3333', right? | 16:53 |
nowen | no, just 'netstat -anp | grep 3333' by itself | 16:54 |
vp | ok, I just did. | 16:54 |
nowen | did it return anything? | 16:54 |
vp | and it says that '(Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) tcp 0 0 127.0.0.1:3333 0.0.0.0:* LISTEN ' | 16:54 |
nowen | ok good | 16:55 |
vp | now then what? | 16:55 |
nowen | hmm | 16:55 |
*** alamarca has quit (Ping timeout: 246 seconds) | 16:57 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 16:57 | |
nowen | are you sure you used the right IP addresses in the ssh -L command? | 16:57 |
vp | I used the our wikid server ip address. | 16:59 |
nowen | and the address of the new server? | 17:00 |
vp | 192,168.70.200 | 17:01 |
vp | sorry, it is 192.168.75.200 | 17:01 |
vp | so I did 'ssh -L 3333:192.168.75.200:5432 root@192.168.75.200' | 17:02 |
nowen | ahh - no, the last IP should be the old server, the first one should be the new 3.x server | 17:02 |
vp | I think there is a misunderstanding. | 17:04 |
vp | I am just trying to upgrade from version 2 to the latest version on same server. | 17:04 |
nowen | yes, you can't do that ;) | 17:04 |
nowen | you need to set up 3.x on a new server and migrate the database to it. | 17:05 |
vp | ok, then my question is that can I upgrade from version 2 to the latest version on same server? | 17:06 |
nowen | no, i'm afraid not | 17:07 |
nowen | you can set up 3x server in vmware, move the db, build 3.x on the old machine and move the db. | 17:07 |
vp | is there a document provided about it on your website? | 17:09 |
nowen | not quite, but what you would do is follow the upgrade doc, then then the replication doc. | 17:09 |
*** alamarca has quit (Ping timeout: 246 seconds) | 17:10 | |
nowen | or I could walk you through it | 17:10 |
vp | can you please provide me with those links about upgrade and replication? | 17:12 |
nowen | upgrade is the one I already gave http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-upgrade-to-the-wikid-strong-authentication-server-3.0/?searchterm=2.0 | 17:13 |
nowen | and replication is http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-configure-the-wikid-strong-authentication-system-for-replication | 17:13 |
vp | Nick, I have a quick question here. What if we don't want to keep our DB? meaning that we just want to upgrade the system without considering DB. | 17:14 |
nowen | ahh - yes, that might be easier | 17:14 |
vp | does this make it simpler to upgrade? | 17:15 |
nowen | yes, probably so | 17:15 |
vp | ok, then that would be great. | 17:15 |
nowen | I think you'll have less than 10 users, right? they would need to re-register | 17:15 |
vp | because I won't keep the DB. | 17:15 |
vp | yes | 17:15 |
vp | yes | 17:15 |
nowen | do you have physical access to the server? | 17:15 |
vp | yes, I do | 17:16 |
nowen | then, I recommend you download the ISO and pop it in the box. it will build a 3.x server with all the software, etc | 17:16 |
nowen | http://wikidsystems-dl.com/wikid-enterprise-3.4.62-b445-install.iso | 17:17 |
nowen | just burn that file to CD | 17:17 |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 17:26 | |
vp | Thank you very much, Nick. I will try with that first. If there is anything else I need. I will come back to you. | 17:27 |
alamarca | nice | 17:27 |
nowen | ok | 17:29 |
alamarca | nowen, which was the directory where you move the files to avoid crowding wikidadmin | 17:30 |
nowen | alamarca: do you mean /opt/WiKID/tomcat/webapps/wikid? | 17:33 |
alamarca | this is the default directory of the installation I need the other directory in which I need not enter wikidadmin | 17:34 |
nowen | yes, that directory is not protected by the WiKIDAdmin username/password | 17:39 |
*** alamarca has quit (Ping timeout: 246 seconds) | 17:54 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 17:58 | |
nowen | alamarca: I can't replicate your wauth problem | 18:04 |
alamarca | yes | 18:05 |
alamarca | thnxs | 18:05 |
alamarca | çNow we are reading the documentation submitted for distribution in Chile | 18:06 |
*** mjc_ has quit (Quit: Leaving.) | 18:13 | |
*** alamarca has quit (Quit: Saliendo) | 18:27 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 18:27 | |
alamarca | ON *:JOIN:#PaXanGa: { notice $nick Bienvenido al canal del clan mas poderoso } | 18:29 |
*** finalbeta has quit (Ping timeout: 248 seconds) | 18:45 | |
*** finalbeta (~finalbeta@ip-213-49-94-78.dsl.scarlet.be) has joined #wikid | 18:48 | |
*** alamarca has quit (Quit: Saliendo) | 18:57 | |
*** mjc_ (~mcarey@74.61.243.29) has joined #wikid | 19:09 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 19:20 | |
alamarca | hi all | 19:20 |
nowen | hi alamarca :) | 19:21 |
nowen | Ken_: did you get your android token working btw? | 19:22 |
alamarca | HAHA | 19:22 |
*** alamarca has quit (Client Quit) | 19:23 | |
nowen | mjc_: what's up? | 19:25 |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 19:25 | |
alamarca | the strange thing is that even I do not feel OP AHAHHAA channel distributors or voice as we at least say I ajajajajaja | 19:26 |
alamarca | ajajaja | 19:27 |
nowen | :) | 19:27 |
alamarca | not? | 19:42 |
nowen | not sure I follow...? | 19:42 |
nowen | are you not getting the one-time passcode? | 19:43 |
alamarca | ahahaha | 19:44 |
alamarca | solo queremos ayudar y trabajar m($.$)m | 19:44 |
alamarca | just want to help and work m($.$)m | 19:45 |
alamarca | I have been designated as the engineer TelChile WiKID expert therefore belong to this channel and we are forever being evaluated wikid distributors in Chile, so I'd like to send me any documentation that I can serve andres.lamarca @ telchile.net and what you need in Chile or Latin America can help you without any problem | 19:47 |
nowen | ok, alamarca I will send you what I have. most of the information is also on the website ;) | 19:48 |
alamarca | how? | 19:49 |
nowen | I have sent you an email with the pdfs | 19:50 |
alamarca | plis | 19:51 |
*** alamarca_ (~alamarca@201.246.118.158) has joined #wikid | 19:57 | |
nowen | alamarca: also, you can look at this page: http://www.wikidsystems.com/learn-more/technology/overview | 19:57 |
*** alamarca_ has quit (Client Quit) | 19:58 | |
*** alamarca_ (~alamarca@201.246.118.158) has joined #wikid | 19:59 | |
*** alamarca_ has quit (Client Quit) | 19:59 | |
*** alamarca_ (~alamarca@201.246.118.158) has joined #wikid | 20:00 | |
*** alamarca_ has quit (Client Quit) | 20:00 | |
*** alamarca_ (~alamarca@201.246.118.158) has joined #wikid | 20:00 | |
*** alamarca_ has quit (Client Quit) | 20:00 | |
*** alamarca_ (~alamarca@201.246.118.158) has joined #wikid | 20:03 | |
*** alamarca_ has quit (Client Quit) | 20:03 | |
alamarca | aloha | 20:10 |
alamarca | 17:10 in chile | 20:12 |
alamarca | USA? | 20:12 |
alamarca | nowen | 20:26 |
alamarca | hi | 20:26 |
alamarca | we want to be distributors in South America | 20:26 |
Ken_ | Owen? | 20:30 |
nowen | yes Ken_ | 20:32 |
Ken_ | OK Last week I was playing with replication and managed to hose both my VM's. No biggie really so I have a new one up and I cannot get RADIUS working. Grr. Do you remember what we did when I first jetted the VM up? | 20:36 |
Ken_ | Logs were showing:Exception in thread: DATAGRAM LEN = 67 FROM 10.123.62.200:62184 java.lang.NullPointerException at com.wikidsystems.radius.nas.UnknownNAS.unknownNAS(UnknownNAS.java:31) at com.theorem.radserver3.RADIUSSession.v(DashoA10*..) at com.theorem.radserver3.RADIUSSession.e(DashoA10*..) at com.theorem.radserver3.RADIUSSession.d(DashoA10*..) at com.theorem.radserver3.RADIUSSession.run(DashoA10*..) at java.lang.Thread.run(Thread.ja | 20:37 |
nowen | did you restart after creating then network client? | 20:37 |
Ken_ | So I restarted with the restart switch now it does not log jack | 20:37 |
Ken_ | No iptables | 20:37 |
nowen | iptables is off? or the port is not opening? | 20:38 |
Ken_ | What is the unix command to view udp ports? | 20:38 |
nowen | for listening? netstat -anp | grep 1812 | 20:39 |
nowen | for 1812, of course | 20:39 |
Ken_ | OK so if I pass a bogus password to a valid username there is no log created. | 20:39 |
Ken_ | Is that correct? | 20:40 |
nowen | is the passcode numeric? | 20:40 |
Ken_ | hmm no. it was alpha | 20:40 |
nowen | non-numeric passcodes get blocked early to stop script kiddies from disabling | 20:40 |
nowen | you can see it in the logs, if you up logging | 20:40 |
Ken_ | <71> Access-Accept(2) LEN=67 10.123.62.200:38162 Access-Request by XXXXXXX succeeded | 20:40 |
nowen | woot | 20:41 |
Ken_ | OK. I will need to be able to see failed auth logs - how to? | 20:41 |
nowen | hmm, start by setting com.wikidsystems to debug, but i have to test to be sure. it might also require com.wikidsystems.client.wClient | 20:43 |
Ken_ | If the pw is numeric it logs fail auth. :) | 20:46 |
nowen | good | 20:47 |
nowen | I know there are other options to stop brute force attackers, but we were asked for this. I think it makes sense. chances are you will also get logs of the attempts at the entry point | 20:48 |
Ken_ | I will have logs there too but those will be submerged in a plethora of other logs. It will be helpful to get an audit from the WiKID servers | 20:52 |
Ken_ | OK CentOS Question | 21:04 |
nowen | ok | 21:04 |
Ken_ | My firewall is logging failed connections to a number of centos sites via port 80. Any ideas? | 21:05 |
Ken_ | Updates? | 21:05 |
nowen | hmm, yes | 21:05 |
Ken_ | OK to keep these blocked? | 21:06 |
nowen | sure, also, 'chkconfig yum-updatesd off' | 21:06 |
nowen | and 'service yum-updatesd stop' | 21:06 |
*** mjc_ has quit (Quit: Leaving.) | 21:34 | |
*** vp has quit (Ping timeout: 252 seconds) | 21:36 | |
*** alamarca has quit () | 21:43 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 21:46 | |
*** alamarca has quit (Client Quit) | 21:47 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 21:50 | |
*** nowen has parted #wikid (None) | 22:00 | |
*** alamarca has quit () | 22:00 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 22:00 | |
*** alamarca has quit () | 22:09 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 22:13 | |
*** mjc_ (~mcarey@74.61.243.29) has joined #wikid | 22:14 | |
*** alamarca has quit () | 22:18 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 22:19 | |
*** alamarca has quit (Client Quit) | 22:20 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 22:20 | |
*** finalbeta has quit (Ping timeout: 248 seconds) | 22:24 | |
*** alamarca has quit (Remote host closed the connection) | 22:39 | |
*** alamarca (~alamarca@201.246.118.158) has joined #wikid | 22:40 | |
*** mjc_ has quit (Quit: Leaving.) | 22:46 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!