Monday, 2011-05-09

*** mick_laptop has quit (Changing host)02:31
*** mick_laptop (~mick@clamwin/admin/mickhome) has joined #wikid02:31
*** perestrelka (~vlad@194.242.5.47) has joined #wikid07:14
*** perestre1ka has quit (Ping timeout: 276 seconds)07:15
*** Raj (7d15f1b1@gateway/web/freenode/ip.125.21.241.177) has joined #wikid09:37
Rajhi09:37
*** Raj has quit (Quit: Page closed)09:47
*** nowen (~nowen@adsl-98-66-164-120.asm.bellsouth.net) has joined #wikid12:13
*** simplehometech (40471102@gateway/web/freenode/ip.64.71.17.2) has joined #wikid17:43
simplehometechhello17:43
nowenh17:43
simplehometechi need to secure a corporate wireless using 2 factor auth17:43
nowenok17:43
simplehometechcan you explain how wikid can help with that?17:43
simplehometechit looks like you use tokens17:43
simplehometechcan you use someother method also?17:44
simplehometechi would perfer to not use tokens17:44
nowenWiKID is a software-only token system17:44
simplehometechso how would that work to secure wireless17:44
nowenbut, our tokens communicate with the server so, it might not work in your scenario17:45
nowenbut it depends17:45
nowenhow does authentication work currently?17:45
simplehometechdo you have any white papers on how that would work?17:46
nowennot specific to wireless17:46
nowenbut you can see how it works here: http://www.wikidsystems.com/learn-more/technology/overview17:46
simplehometechdo you have customers that use wikid to secure wireles?17:46
nowenmostly it is vpn, but to be honest, we don't necessarily know what people use it for.17:47
simplehometechah17:47
nowenI seem to recall some using for wifi17:47
simplehometechcan you ask around to see if anyone has more info?17:48
nowenhere's the rub as I see it:  the WiKID token needs to communicate to the server to get the OTP.  If you PCs don't yet have internet access, then you are limited to the smart phone tokens.17:49
nowenif you are implemented more of a 'walled garden' wireless setup and the PC tokens can get access to the WiKID server, then that would also work17:50
simplehometechcurrently the company has a wireless network that is more like a guest network17:50
simplehometechexternal internet only17:50
simplehometechthen they vpn in17:50
simplehometechwe are looking to streamline that process17:51
simplehometechso that the wireless would be internal17:51
simplehometechbut it needs to be secure17:51
simplehometechthis company is treated like a bank17:51
simplehometechand have to follow PCI17:51
nowenwhen you move it to "internal" how will authentication handled?17:51
nowen^ be handled17:51
simplehometecheveryone is on a 2003 active directory domain17:52
simplehometechbut we need to use 2 factor17:52
simplehometechso im looking to get the second factor17:52
nowenso, you will need to implement radius on top of 200317:52
simplehometechright17:53
simplehometechso wifi -> radius -> wikid?17:53
nowenyes17:53
simplehometechwhen the wikid phase is reached - does wikid open up a web site on the users computer?17:53
simplehometechor do they have to have a client installed17:53
nowenunprotected wifi >> radius >> IAS/2003AD >> wikid >> IAS/2003 >> protected wifi17:53
noweninstalled client17:54
simplehometechwhat OS's do you support17:54
simplehometechand how would it work for something like an iphone/android17:54
nowenwindows, mac, linux, iphone, bb, android, html517:54
simplehometechfor html5 you dont need to install the client?17:54
nowenwell, technically, it is just an easier install.  the private keys are still on the local machine17:55
simplehometechah17:55
nowenand the token is 'tied' to the browser17:55
simplehometechwhat windows versions do you support?17:55
nowenbut if you are using some type of web gateway that would be coo17:55
nowenl17:55
nowenxp, 7, vista17:55
simplehometech32 and 64 bit?17:56
nowenyes, it is a java app17:56
simplehometechhow does IAS pass authentication to wikid?17:56
nowenradius.  wikid is configured as the radius server in ias17:56
simplehometechah17:57
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-configure-ias-to-support-two-factor-authentication/?searchterm=ias17:57
simplehometechgotcha17:57
simplehometechvery cool17:57
simplehometechyou've been a big help17:57
simplehometechthanks17:57
nowennp17:57
simplehometechone more question18:01
nowenok18:01
simplehometechwhat do i loose with the community version of wikid18:01
simplehometechwould it work for what I need?18:01
nowenhttp://www.wikidsystems.com/community-version/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release/18:01
nowenno18:02
nowenbecause windows server has no mechanism to proxy an ldap auth, to my knowledge18:02
simplehometechso ... i would need to use the enterprise version?18:07
nowenthat would be my guess18:08
simplehometechok18:08
nowenor write a plugin for freeradius or somesuch18:08
*** simplehometech has quit (Ping timeout: 252 seconds)20:46
*** nowen has quit (Quit: Leaving.)22:25

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!