Thursday, 2011-05-05

*** alamarca has quit (Ping timeout: 248 seconds)05:25
*** alamarca (~alamarca@201.246.76.78) has joined #wikid05:39
*** Paul__ (559f5502@gateway/web/freenode/ip.85.159.85.2) has joined #wikid10:04
*** Paul__ has parted #wikid (None)10:05
*** alamarca has quit (Quit: Saliendo)12:55
*** alamarca (~alamarca@201.246.76.78) has joined #wikid13:12
*** alamarca has quit (Ping timeout: 240 seconds)13:17
*** nowen (~nowen@98.66.164.120) has joined #wikid14:11
*** Scott___ (4080b9c4@gateway/web/freenode/ip.64.128.185.196) has joined #wikid14:27
Scott___Are the tokens that this uses a physical token, or is it like a software?14:28
*** Scott___ has quit (Client Quit)14:30
*** aktnz (52b014f2@gateway/web/freenode/ip.82.176.20.242) has joined #wikid17:30
aktnzgood evening from Terneuzen, the Netherlands17:30
nowengood afternoon from Atlanta, Ga, USA17:31
aktnzA couple of days ago I installed the Wikid Strong authentication server and I must admit it works really great. So I ordered a couple of  licenses (home use). Can you tell me in what way they are delivered ??17:34
nowenhehe, well, we actually haven't set up the license/certificate system yet,  it is in the works.17:34
nowenso what you have is a production cert17:35
aktnzAh OK :), does this license expire at some time ??17:36
nowenlegally it is a 1 year subscription. the intermediate CA is good for 3.  localhost is 117:37
aktnzAre there any other customers in the Netherlands  or Benelux - countries as far as you know ??17:39
nowenyes, definitely.17:40
nowenis the Dutch translation working ok?17:44
aktnzWell I work for the "gemeente Terneuzen" (local governement) and I am sure a lot of  "collegues" might be interested in Wikid  !!17:44
aktnzI installed in the default language. Is a Dutch translation available ??17:45
aktnzAtlanta that is in the southern part of the USA, or am I wrong ? Wel, Terneuzen is a small town in the south-western part of the Netherlands, close to the Beigium border.  Some "nice" cities in our neighborhood are Antwerp (50 km), Brussels (100 km), Paris (350 km), Amsterdam (200 km).17:49
nowenaktnz: there should be a Dutch option in the token client17:52
nowenyes, Atlanta is in the South.  Sounds like you're in the center of a lot of activity :)17:52
aktnzdefinitely :) By the way the android - client works like a charm !!!!17:58
aktnzReally great stuff !!18:02
nowenoh really? I think the UI could use some work18:09
nowenbut it is quite handy18:21
nowenaktnz: I mean there should be a Dutch option in the PC token, not the android18:22
aktnzOK, should it be possible to use wikid with strongswan (ipsec) ?18:27
nowenif you can use a username/password combo to login and the server supports radius, or pam and thus pam-radius, then it should work18:30
nowenI would love to have some documentation on that if it works18:30
aktnzstrongswan supports  eap, radius or xauth (username/password). Looks good, I guess ........18:36
aktnzhttp://wiki.strongswan.org/projects/strongswan/wiki/EapRadius18:38
nowencool18:39
aktnzWell, I'll start "playing" with it the next couple of days.........18:39
nowenyeah, let me know how it goes18:39
nowenI think when I looked at it, there was no radius support18:39
*** alamarca (~alamarca@201.246.76.78) has joined #wikid18:40
aktnzMaybe you looked at OpenSwan in stead of StrongSwan. The last one is absolutely much better.18:40
alamarcahi18:40
nowenoh that could be18:40
nowenhi alamarca18:40
*** alamarca has quit ()18:45
*** alamarca (~alamarca@201.246.76.78) has joined #wikid18:53
aktnz@nowen: I will keep you informed about wikid - ipsec. Configuring ipsec is not the easiest task but I will give it a try :)18:55
*** alamarca has quit (Remote host closed the connection)18:56
nowenhehe, no, not easy, or I would have documented it already:-)18:56
*** alamarca (~alamarca@201.246.76.78) has joined #wikid18:56
aktnz@nowen, I must leave now. See you later :)19:07
nowenlater ;)19:07
*** aktnz has quit (Quit: Page closed)19:08
*** alamarca has quit (Read error: Connection reset by peer)19:47
*** alamarca_ (~alamarca@201.246.76.78) has joined #wikid19:47
*** alamarca_ has quit (Client Quit)19:47
*** alamarca (~alamarca@201.246.76.78) has joined #wikid19:48
*** alamarca has quit ()20:13
*** alamarca (~alamarca@201.246.76.78) has joined #wikid20:17
*** alamarca has quit ()20:46
*** alamarca (~alamarca@201.246.76.78) has joined #wikid20:48
*** wpg (83cc9101@gateway/web/freenode/ip.131.204.145.1) has joined #wikid20:52
wpgyo, anyone here know if Wikid can be configured to do 2-factor auth with Cisco ASA, & AD?20:53
wpgI have read some of the docs on the wikid website, but they look kind of outdated20:53
nowenwpg: yes20:56
nowenshould be no problem20:56
nowenjust use radius20:56
nowenyou will want to use either IAS or NPS to route the auth requests through AD20:56
wpgI saw in the Cisco Concetrator doc - it mentioned opening a web browser to test, and that threw me off..20:57
wpgmost of our clients use the Cisco any-connect vpn client20:58
nowenyeah, it could be referencing the web ssl vpn20:58
nowenbut the back is all that matters20:58
wpgI assume I could use FreeRADIUS instead of IAS?20:58
nowenis you want to use AD for authorization, then you have to use ias.  if you don't care about checking ad groups, then you can have the cisco talk straight to the WiKID box20:59
wpgwhat if I had the FreeRADIUS server talking to the AD servers?  ie.. either via ldap or as part of the domain?21:00
nowenthat should work fine too21:00
nowenwe have a doc on freeradius/openldap that should also work21:01
nowenhadn't thought of that - freeradius can check authz to AD via LDAP>21:01
nowen?21:01
wpgyeah, that's how we do our wireless auth on our campus21:02
nowenmakes perfect sense, just hadn't thought of it21:02
wpgfor testing, should I be able to do this using the community edition?21:02
nowenthe community edition does not support radius21:03
wpgarghh21:03
nowenyou can test with enterprise, we're pretty lax about the 30 day limit.  Also, if you program and know freeradius, then maybe you can write a module21:04
wpgok, thanks for the help21:05
nowennp21:06
nowenwpg: http://www.wikidsystems.com/community-version/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release/?searchterm=what%20is%20the%20difference21:14
wpgthanks!21:26
wpgdo you guys have any .edu clients?21:26
nowenyes, and we're working on some more21:26
* nowen >_>21:27
wpgcan you tell me who some of them are?21:27
nowenin general our users don't like anyone knowing what systems they run.  I can forward some via email, if they agree21:28
nowenmostly, we get .edus that need PCI compliance21:28
wpgyep - that's us21:29
alamarca...21:29
nowenthere's a good sampling of .edus in here now :)21:30
wpganyone?21:30
nowenshy people.21:31
nowenhehe21:31
alamarcabye21:31
wpgare you in ATL Nick?21:33
nowenyes21:33
wpgsweet21:33
nowenare you going to SELF by any chance?21:33
wpgsorry - what do you mean?21:34
nowenSoutheast Linux Fest21:34
nowenit's in Spartanburg21:35
wpgwhen is it?21:35
nowenhttp://www.southeastlinuxfest.org/  June 10-12, 2011 21:35
wpgProbably not, why do you ask?21:36
nowensaw you were in Auburn. I'll be there21:36
wpgyeah, that would be cool though..21:36
nowenit's a pretty good linux fest21:37
wpgI would like to meet you21:37
nowennot that i have been to many21:37
wpgare you on AIM?21:37
nowenno21:37
wpgemail?21:37
wpg:)21:37
nowennowen at wikidsystems.com21:37
wpgthanks..21:38
nowennp21:38
wpgwhere in ATL is you company?21:38
nowenmidtown. the Earthlink building on 17th21:38
wpghere is mine - gouldwp-at-auburn.edu21:39
wpgI will try the enterprise trial21:39
wpgI see it has a RADIUS server built in21:40
nowenyes21:40
nowendon't worry about spam.21:40
wpgcoming from FreeRADIUS how does is compare (sorry for the 20 questions)21:40
nowenit's not really a radius server. it is just a listener.21:41
wpgahh21:41
wpggotcha21:41
nowenI would not replace freeradius with it21:41
nowenwe can return attributes etc21:41
wpgok well, if I have more questions once I get my hands dirty, I might hit you up if you don't mind.  thanks againfor your help.  It was nice chatting w/ you.21:42
nowensame here! enjoy21:43
wpgwar eagle! ;)21:43
nowenhehe, I went to UVa undergrad and UGa grad school21:43
wpg:)21:44
nowenand I live in the land of Ga Tech21:45
wpgwe were just up there a few weeks ago on Tech's campus for a IPv6 meeting21:46
wpgcya21:46
nowenhmm, what does that say about IPv6 that people have to have meetings about it? :)21:46
nowenlater21:47
wpgyeah - no doubt21:47
wpgand still have no clue about it21:47
wpgheh21:47
wpghehe21:47
nowenlol21:47
wpggotta go - will be talking w/ you21:48
*** wpg has quit (Quit: Page closed)21:48
*** nowen has parted #wikid (None)22:23
*** sakhi has quit (Ping timeout: 258 seconds)22:36
*** alamarca has quit (Ping timeout: 264 seconds)23:10

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!