Thursday, 2011-04-21

*** alamarca_ (~alamarca@201.246.81.195) has joined #wikid01:17
*** alamarca has quit (Ping timeout: 240 seconds)01:18
*** finalbeta (~finalbeta@ip-81-11-184-217.dsl.scarlet.be) has joined #wikid07:11
*** finalbeta_ has quit (Ping timeout: 260 seconds)07:14
*** finalbeta has quit (Read error: Connection reset by peer)11:13
*** nowen (~nowen@adsl-66-164-120.asm.bellsouth.net) has joined #wikid12:51
*** alamarca_ has quit ()13:24
*** alamarca (~alamarca@201.246.81.195) has joined #wikid13:24
alamarcahi13:28
nowenmorning13:28
alamarcamorning13:35
alamarcanowen I am about to send mail13:36
alamarcaxD13:36
nowenok13:36
alamarcalook you mail13:44
nowengot it13:45
alamarcathnxs13:45
*** alamarca has quit ()13:45
*** alamarca (~alamarca@201.246.81.195) has joined #wikid13:51
alamarcanowen i repond you mail14:26
nowengot it  :)14:29
nowenare they capable of installing and managing it themselves?14:30
alamarcaI do not know14:41
*** Ken (a5bd4f32@gateway/web/freenode/ip.165.189.79.50) has joined #wikid15:56
KenHey Nick - Have time for two short questions?15:56
nowenyes15:57
KenK.  CA and Sub CA cert vail periods.  How long on the CA and sub CA certs?  How long on the client certs?15:59
nowenCA is 3 years, the others are 1, IIRC15:59
nowenyou can check them with keytool16:00
KenSo what happens after three years when the CA certs needs updating?16:00
nowenkeytool -list -v -keystore /opt/WiKID/private/intCAKeys.p12 -storetype pkcs12 -storepass yourpassphrase16:00
nowenyou can just create new ones16:00
nowenwe're going to be updated the CA code, btw16:01
nowenit will really tie into the subscription process.  we might be able extend the certs instead of re-creating16:02
nowenwhat's your concern?  That the certs will die and things will go bad?16:02
*** Ken_ (a5bd4f32@gateway/web/freenode/ip.165.189.79.50) has joined #wikid16:03
Ken_Hmm got booted.  You trying to tell me something Nick?16:03
nowenhehe16:03
nowenso, to re-state:  let me know your concerns, we're updating the CA code shortly16:03
nowencurrently, you just recreate the certs16:04
*** Ken has quit (Ping timeout: 253 seconds)16:05
Ken_What about the clients and their ties to the original cert chain?16:06
nowenthe token clients are not tied to the CA at all16:06
nowentheir keys are stored in the db16:06
Ken_What about the mutial validation16:12
nowenmutual validation is separate also.  the ssl cert is stored in the db16:16
*** Ken (a5bd4f32@gateway/web/freenode/ip.165.189.79.50) has joined #wikid16:18
KenSo is there anything using the soft tokens on a pc or mobile device that woud need to be update or touched in any way over the course of 10 years16:19
nowenthere shouldn't be16:21
nowenthe tokens use a 'flat public key' architecture16:21
*** Ken_ has quit (Ping timeout: 252 seconds)16:21
KenShoot I had a second question but forgot what it was. :)16:22
nowenfreenode is not liking you today16:22
KenNo it is not16:23
KenAny ideas on when the new andriod client will be out?16:23
nowenhmm. not a lot of data, but we need to push it forward16:24
KenWhere is WiKID based out of and how big is your staff?16:24
nowenAtlanta, depends ;)16:24
nowenwe're a pretty small company obviously.  we use a lot of contractors16:25
nowenfor example, we will go out of house for most non-java developement16:25
KenI remembered:  Where does PCI specifiy the need for xfactor or strong auth?16:25
nowenthe windows mobile phone token eg16:25
Ken?16:26
nowenyou want the rule #?16:26
nowenwe will outsource development of the windows mobile phone token16:26
KenYes.  I do some work for a company that deals in CC transactions16:26
nowen8.3 Implement 2-factor authentication for remote access to the network by employees, administrators, and third parties. Use technologies such as RADIUS or TACACS with tokens, or VPN with individual certificates.16:27
nowenthat might be dated16:27
KenThat should be close enought for me to investigate16:27
nowenhttp://publib.boulder.ibm.com/infocenter/wchelp/v7r0m0/index.jsp?topic=/com.ibm.commerce.pci.doc/concepts/csepcireq8.htm16:28
KenSo is there support for windows phones?16:28
nowen6.5 currently,16:28
nowenwe'll be doing a 7 soon.16:28
nowenhere's the pdf https://www.pcisecuritystandards.org/pdfs/pci_pa_dss.pdf 16:29
Ken10.2 If the payment application may be accessed remotely, remote access to the payment application must be authenticated using a twofactor authentication mechanism.16:33
KenThanks for your time Nick.  I am off to lunch.  Going to start our pilot this week.16:34
nowenawesome!16:36
nowenah - yes, 10.216:36
*** Ken has quit (Disconnected by services)16:45
alamarcanowen17:58
alamarcagood weekend17:58
alamarcagL17:58
*** alamarca has quit ()17:58
*** Matt_ (4211be12@gateway/web/freenode/ip.66.17.190.18) has joined #wikid18:46
Matt_Hello18:46
*** Matt_ is now known as Guest8475018:47
nowenhi18:47
Guest84750We are trying to determine what ports need to be open for the wikid server for a client to connect18:47
nowen8018:47
nowenthe WiKID admin runs on 44318:47
Guest84750Even for grabbing a token?18:47
nowenthe tokens use asymmetric encryption, so no need for ssl.  we went with 80 b/c it is usually open18:48
Guest84750alright thanks18:49
nowennp18:49
nowenyou can NAT the wikid box, too18:49
nowenjust use the external ip for the domain identifier18:49
Guest84750ok18:50
*** Guest84750 has quit (Ping timeout: 252 seconds)20:09
*** MattN (4211be12@gateway/web/freenode/ip.66.17.190.18) has joined #wikid20:58
MattNhello again. what doe s a "0" mean in response to trying to create a new domain from a new client.  the user is able to connect via port 80 using a straight telnet. any ideas?21:00
nowenMattN: hmm.  is there an anti-spyware solution keeping the token from writing to the drive?21:00
nowenwhat OS?21:00
MattNwindows 721:01
nowenand are they using the installer?21:01
MattNyes the installer bundle and also tried the no install executable21:01
nowendoes it happen after the PIN prompt?21:02
MattNbefore21:04
MattNright after we try adding the domain.21:04
nowencheck the anti-virus, anti-spyware21:04
MattNactually about an hour ago we were able to add the pin but we cancelled it21:04
nowenhuh21:05
nowendeleted the domain?21:05
MattNwell it never got added21:05
MattNwhen we try to add the domain it says connecting and throws 021:05
nowenis the a wikidtoken.wkd file on the pc?21:06
nowenare you on this pc or is this remote or are you on the phone?21:07
MattNwell i have remote session going on with him21:07
nowencool21:08
MattNi can see his computer21:08
nowencan you control it?21:08
MattNi can have him do whatever i want pretty much21:08
MattNwhat do you want me to check on his computer21:09
nowenI'm wondering if he has some anti-spyware that is blocking the connection or preventing the token from saving the file21:09
MattNso basically the connection to the gateway server is happening21:10
MattN?21:10
nowenyou see the traffic on your gateway?21:10
MattNyeah21:10
MattNi did tcpdump on his ip21:10
MattNand i see the traffic21:10
nowenis it just this user?21:10
MattNno everybody in that network21:11
nowenis this a remote office?21:11
MattN: 16:03:21.610460 IP 192.168.237.101.arkivio > gtwlsb01.tcprod.local.http: S 557591423:557591423(0) win 65535 <mss 1260,nop,nop,sackOK> 16:03:21.610511 IP gtwlsb01.tcprod.local.http > 192.168.237.101.arkivio: S 3830385880:3830385880(0) ack 557591424 win 5840 <mss 1460,nop,nop,sackOK> 16:03:21.736432 IP 192.168.237.101.arkivio > gtwlsb01.tcprod.local.http: . ack 1 win 65535 16:03:27.735477 IP gtwlsb01.tcprod.local.http > 192.168.237.101.a21:12
MattNtcpdump on the gateway21:12
MattNgtwlsb is the gateway server21:13
nowendo you see the server responding?21:13
MattNi see the traffic comign to it on http port21:13
MattNif you look at the tcpdump that i sent you21:14
nowenanything in the WiKIDAdmin logs?21:16
nowenyou might have to set the loggers to debug and have him run it again21:16
nowenalso, can the token client add this domain:  8888888888821:17
nowenthat should be 12 8s21:17
MattNok21:17
MattNthe 888xxx is stuck on connecting21:19
MattNwhich log filter i have to set to debug21:20
MattNon gateway21:20
nowenMattN: if you also can't add our domain, then it is probably something on the PC21:20
nowenor something in the network locally?21:21
MattNwhat logger file i have to set to debug21:21
MattNi see 5 options21:21
MattNsome are set to warn and info21:21
nowencom.wikidsystems,21:21
nowenwclient and wauth21:22
MattNok21:23
MattNtryign linux client connection21:24
nowenMattN: is this in production? testing?21:25
MattNworks in linux21:26
nowenhmm, linux on the same network?21:26
MattNyup21:27
nowenthe windows boxes must have anti-malware21:27
MattNyou were right21:27
MattNlooks like some IT policy on the antivirus that he cant turn off21:28
nowenwell, benefit of experience21:28
nowenis this one of your offices? or a different company?21:28
MattNour other branch21:28
MattNthanks for your help though21:33
MattNafter disabling anti virus its working in windows too21:34
nowenyou think you can get it changed?21:34
nowenwhat anti-virus is it21:34
nowen?21:34
MattNnod3221:34
nowenjust went through this with someone else21:35
MattNthey have to create some exception21:36
nowen1. Open NOD32. If it's not in advanced mode click "Toggle advanced mode" and answer yes to the prompt.2. Click on "Enter entire advanced setup tree"3. Navigate to Protocol Filtering and change the option to "Applications marked as Internet bowsers and email clients"21:37
nowenthat maybe on the client side21:37
MattNhaving him try that right now21:40
nowenany luck?21:53
MattNsorry21:56
MattNhe is trying now21:56
nowennp21:57
MattNhe is not seeing "Applications marked as Internet bowsers and email clients"22:00
MattNalthough he did it for wikidtoken application in the list22:01
MattNwhich application in particular22:02
nowenc:/program files/wikidtoken/wikidtoken.jar i would think22:03
MattNso he selected everything from protocol filtering in nod3222:04
MattNand still the same thing22:04
noweninstalling it now22:04
nowenwell, waiting for the download email now ;)22:07
MattNits ok22:08
nowenhttp://kb.eset.com/esetkb/index?page=content&actp=LIST_RECENT&id=SOLN56022:12
nowenthat might help22:12
MattNwill try that22:12
MattNright now i got him working on linux22:12
MattNso he is good now22:13
MattNthanks for you help though22:13
*** MattN has parted #wikid (None)22:13
nowenoh, ok22:13
nowencool22:13
noweni've got to head home22:23
*** nowen has parted #wikid (None)22:24

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!