*** Withoutaname has quit (Quit: QUICK! Look up! You'll see the word gullible.) | 07:17 | |
*** nowen (~nowen@adsl-74-176-209-220.asm.bellsouth.net) has joined #wikid | 12:20 | |
nowen | good morning | 12:44 |
---|---|---|
*** Ian___ (5246e719@gateway/web/freenode/ip.82.70.231.25) has joined #wikid | 13:33 | |
Ian___ | Hi, just having a couple of problems with setting up a test account with Wikid & XenApp | 13:34 |
nowen | ok | 13:54 |
nowen | what's going on? | 13:54 |
Ian___ | hi sorry | 13:59 |
Ian___ | the passcode dialog shows up fine on the xenapp login | 13:59 |
nowen | np | 14:00 |
nowen | ok | 14:00 |
Ian___ | the passcode is generated from my iphone | 14:00 |
nowen | are you using radius? | 14:00 |
Ian___ | yes radius | 14:00 |
Ian___ | "An authentication error occurred. Contact your system administrator. Log ID: 2f30b874" | 14:01 |
nowen | that's on the xenapp side? | 14:01 |
Ian___ | the log on the wikid server is suggesting the result has returned falst. | 14:01 |
Ian___ | (false even) | 14:01 |
Ian___ | yes sorry | 14:01 |
nowen | what's the last entry in the WiKIDAdmin logs? be sure to set the log level to debug and hit the filter button | 14:02 |
Ian___ | Check returned false | 14:03 |
nowen | is the user enabled in WiKID? | 14:03 |
Ian___ | yes they're showing up as enabled | 14:03 |
nowen | hmm. and do you also see the passcode request in the WiKIDAdmin logs? | 14:04 |
Ian___ | yes | 14:04 |
Ian___ | ahh the NAS-IP-Address, should that point to our xenapp box? | 14:05 |
nowen | yes! | 14:05 |
Ian___ | hmm - strange, the first part of the log states the NAS-Identifier and NAS-IP-Address is 150.50 which is our wikid server, however | 14:06 |
Ian___ | NASip looks to be pointing to 150.72 which is the citrix server. | 14:06 |
nowen | this is all on the WiKID server? | 14:06 |
Ian___ | no, the xenapp server is 150.72, the wikid server is on 150.50. | 14:07 |
nowen | your WiKID network client is using 150.72, correct? | 14:07 |
Ian___ | (sorry when you said is it all on the wikid server do you mean the log output? if so yes) | 14:07 |
nowen | (yes) | 14:07 |
Ian___ | The network client is 150.72 yes. | 14:07 |
nowen | ok - on the Configure Loggers page, put the middle three loggers to debug and try again | 14:08 |
nowen | more data should help | 14:09 |
Ian___ | okay two seconds | 14:10 |
Ian___ | the output is similar, doesn't look like turning on the debug option has worked, I presume i just click log, make sure the drop downs are set to debug, click apply and try again? | 14:13 |
nowen | yes, be sure that the log level is still debug - you also have to attempt to log in again. | 14:14 |
Ian___ | hmm | 14:19 |
Ian___ | well | 14:19 |
Ian___ | I'm getting the following | 14:19 |
Ian___ | Message-Authenticator (80), Length: 18 Data: xxxxxxx,xxxxxxxxxx | 14:19 |
nowen | is there an error? | 14:21 |
Ian___ | no, just the same again, | 14:21 |
Ian___ | Check Returned false | 14:21 |
nowen | that's all that is there? the Message-Authenticator line? | 14:22 |
nowen | no xml info? | 14:22 |
Ian___ | Message-Autnenticator, then Username, Userpassword, Nas-Identifier, NAS-IP-Address, Nasip, then PAP Request, passcode, checking and the finally check returned false | 14:23 |
nowen | does all the info look correct? | 14:23 |
Ian___ | Just trying to figure out a way of posting hte output - the machine is virtual so there is no copy and paste from the machine. | 14:23 |
Ian___ | yes it does | 14:24 |
Ian___ | I've just checked the input twice. | 14:24 |
Ian___ | if i've specified a full email@domain.com | 14:24 |
Ian___ | should that appear in the checking section | 14:24 |
Ian___ | so for instance | 14:24 |
nowen | is that the user name in WiKID also? | 14:24 |
Ian___ | yes | 14:25 |
Ian___ | but it looks like its dropped off the @domain.com part in the log? | 14:25 |
nowen | yes, so you might have to specifically tell xenapp not to do that | 14:25 |
nowen | or change the username in wikid | 14:26 |
Ian___ | ahh okay | 14:26 |
nowen | while it depends on the system, I think stripping the domain is the default for radius | 14:28 |
Ian___ | will have a look at it and let you know how i get on | 14:29 |
nowen | yes, please do | 14:31 |
Ian___ | well | 15:03 |
Ian___ | we've recreated the user so within wikid the username is firstname.lastname | 15:04 |
Ian___ | the login via the citrix web frontend is firstname.lastname@domain.com | 15:04 |
Ian___ | which is passing through as ian.gibbons:passcode:serverid | 15:05 |
Ian___ | its returning Check returned true | 15:05 |
Ian___ | which is progress but we're still not being logged in from the citrix side of things | 15:05 |
nowen | hmm | 15:06 |
nowen | I'm not very familiar with citrix | 15:06 |
nowen | is there some authorization piece that is missing? | 15:06 |
Ian___ | I don't think so | 15:07 |
nowen | did it work before you set up WiKID? | 15:07 |
Ian___ | before radius was enabled we could login using our domain credentials | 15:07 |
Ian___ | yes it did | 15:07 |
nowen | any logging on the citrix side? | 15:08 |
Ian___ | just finding out now | 15:09 |
*** alamarca (~alamarca@201.246.110.33) has joined #wikid | 16:10 | |
*** alamarca has quit (Client Quit) | 16:11 | |
*** alamarca (~alamarca@201.246.110.33) has joined #wikid | 16:16 | |
*** alamarca has quit (Ping timeout: 246 seconds) | 19:57 | |
*** alamarca_ (~alamarca@201.246.110.33) has joined #wikid | 19:57 | |
*** alamarca_ has quit (Client Quit) | 20:01 | |
*** alamarca (~alamarca@201.246.110.33) has joined #wikid | 20:18 | |
*** alamarca has quit (Ping timeout: 260 seconds) | 20:26 | |
*** alamarca (~alamarca@201.246.110.33) has joined #wikid | 20:30 | |
*** Phil_ (1813cd83@gateway/web/freenode/ip.24.19.205.131) has joined #wikid | 20:59 | |
Phil_ | I am looking for a solution for 2 factor auth which integrates with Watchguard XTM. Can I use WIKID for this? | 20:59 |
nowen | yes | 21:00 |
nowen | via radius | 21:00 |
Phil_ | Is the setup difficult? I have done windows radius setups before? | 21:01 |
nowen | not too difficult. While the server is based on LInux, you don't need to know it to get it setup. it is really an "appliance" | 21:02 |
nowen | just you run it on your own hardware/vm | 21:02 |
Phil_ | So how does it basically work. Does the end user have something like a key or certificate? | 21:03 |
nowen | yes, they get a software token on their PC or wireless device | 21:03 |
Phil_ | And the pricing. Is that really more about support? 1 year vs 3 year ... | 21:05 |
nowen | yes, support, updates, feeding my children ;) | 21:06 |
Phil_ | Seems fair and I certainly don't want you children to starve. Thank you for you help. Phil. | 21:06 |
nowen | hehe, please feel free to download the iso and play with it | 21:07 |
Phil_ | Thank you. I will take a look at it. | 21:07 |
*** Phil_ has quit (Quit: Page closed) | 21:11 | |
nowen | hmm. just realized that I mis-answered Phil's question. I bet he was asking the difference b/t the two versions | 21:12 |
*** alamarca_ (~alamarca@201.246.65.162) has joined #wikid | 21:19 | |
*** alamarca has quit (Ping timeout: 240 seconds) | 21:21 | |
*** Dan__ (ada06522@gateway/web/freenode/ip.173.160.101.34) has joined #wikid | 21:33 | |
*** alamarca_ has quit () | 21:34 | |
Dan__ | Anyone up for a Wikid question? | 21:34 |
nowen | sure | 21:35 |
Dan__ | I'm installing behind a firewall. What ports do I need to open for the clients? | 21:35 |
nowen | 80 | 21:35 |
nowen | we use asymmetric encryption, so no need for 443 | 21:36 |
Dan__ | Simple enough | 21:36 |
*** alamarca (~alamarca@201.246.65.162) has joined #wikid | 21:36 | |
nowen | also, you can Nat the IP of the wikid server, but use the external IP for the domain identifier | 21:36 |
Dan__ | That brings me to my second question, is there a way to not use the IP as the domain id? The external IP will be changing in a few days. | 21:37 |
nowen | we can also create an entry in our dns system. Or, if you are using only PC tokens, you can set the default DNS in the jw.properties file | 21:38 |
Dan__ | How would I go about getting the entry in your dns system? That sounds like the solution. That way when the IP changes we can change it right? | 21:38 |
nowen | yes | 21:38 |
Dan__ | How do I do that? | 21:40 |
nowen | it might take a while for it to propogate | 21:40 |
nowen | give me the IP address and I will make the entry | 21:41 |
Dan__ | 173.160.101.36 | 21:41 |
*** alamarca has quit (Ping timeout: 264 seconds) | 21:43 | |
*** alamarca (~alamarca@201.246.65.162) has joined #wikid | 21:51 | |
*** Dan__ has quit (Quit: Page closed) | 21:52 | |
*** alamarca has quit (Ping timeout: 252 seconds) | 22:09 | |
nowen | uh oh, where did dan go? | 22:12 |
*** nowen has quit (Quit: Leaving.) | 22:30 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!