Tuesday, 2011-06-07

*** nowen (~nowen@adsl-98-66-165-233.asm.bellsouth.net) has joined #wikid12:32
asofrankHey Nick, I rewrote that Fortigate documentation. How do you want me to send it to you?13:15
nowenwow!  thanks!13:16
nowenyou can email if that works13:16
asofrankwhat format do you prefer?13:16
nowenwell, html is what it will be, but whatever is fine. I can pretty much open anything13:17
asofranki'll just paste it in a rich text email13:18
nowenexcellent13:18
asofranksent13:19
asofrankI only changed the fortigate specific stuff13:19
nowenthank you13:19
asofrankso it might be easiest just to transscribe the changes13:19
nowenyeah, that's what I did: http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-wikid-two-factor-authentication-to-a-fortinet-vpn13:37
nowenwas it all in the "Create or modify a user group in the Fortigate:" section?  that's all I noticed13:38
asofrankno, there was some changes in the section above that as well13:38
asofrankcouple lines13:39
nowenahh13:39
*** Lake_Lurker (~Just@h20.211.39.162.dynamic.ip.windstream.net) has joined #wikid13:44
*** Lake_Lurker has parted #wikid (None)13:44
*** SEJeff (~jeff__@209.160.81.1) has joined #wikid14:22
SEJeffnowen, You guys need to do some marketing: http://www.net-security.org/secworld.php?id=1112214:23
nowenSEJeff: howdy stranger14:23
nowenwe are *terrible* at marketing14:24
SEJeffIt is true14:24
SEJeffYou've got a great little product that would be even better if more people knew about it. I only knew about it because I turned down a job with pricegrabber14:24
nowenon the other hand, a lot of people are pissed at the vendors who seem to be piling on to RSA14:25
SEJeffBut this is something you guys really should capitalize on14:25
SEJeffBuy some adwords, shoot out some spam. You know, those annoying things14:25
nowenwe are in many ways.  amazingly analysts and infosec pros still don't see that RSA is shared secrets14:26
nowenwe never got anything worthwhile from google ads14:27
nowenwe've got a bunch of hits from this: http://www.howtoforge.com/securing-ssh-on-ubuntu-with-wikid-two-factor-authentication14:27
SEJeffPerhaps you're marketing for the wrong thing14:28
asofrankthought about hiring an SEO firm?14:29
nowenasofrank: not really, but we do a lot of that14:32
asofrankone of our brands specializes in SEO hosting :P14:32
nowenthe problem is that "two-factor authentication" is quite tough14:32
nowenhowever "open source two-factor authentication" is us: http://www.google.com/search?client=ubuntu&channel=fs&q=open+source+two-factor+authentication&ie=utf-8&oe=utf-814:33
asofrankmaybe think about pairing up with a hardware company and getting some hardware tokens14:33
nowenasofrank: maybe, but it would be a completely different protocol.14:34
nowenand we're doing quite well with the marketing we have14:34
asofrankI'd like to see hardware tokens. I suppose the "offline generation" code you have would do the trick14:36
nowenI think cloud-based services will be the next big growth area14:36
asofrankyou just need a device that is capable of running the code14:36
asofrankyeah, like what google offers14:36
nowenyou still need to be online to register for WiKID14:36
SEJeffWhat about the preregistration stuff?14:36
asofrankyeah, the hardware tokens would have to have a fixed registration code14:37
asofrankbut I really dont know how the backend works14:37
asofrankfor the cloud based system, that likely wouldnt be too difficult14:37
nowenhuh, hadn't thought about that.  we do support pre-registratino14:37
nowenof course, that is exactly the issue that RSA has14:38
SEJeffnowen, Yes, and it works quite well. Thats how we do it for nontechnical users14:38
nowenSEJeff: we have added some pre-reg code to the API.14:38
nowenyou can now generate pre-reg codes via the api.14:38
SEJeffOh thats really shiney14:39
asofrankyou could make the tokens USB sticks14:39
SEJeffI've been thinking of making a "reference implementation" django project and putting it on github14:39
nowenand multiple pre-reg domains per server14:39
asofrankand have them download the information they need14:39
nowendoo eeet!14:39
SEJeffFor the HTML5 token with some shiney built in registration functionality.14:39
nowenasofrank: yes, you can run them on usb drives.  I assume this is how ironkey uses wikid14:40
*** Dingofest2 (~Dingofest@208.124.228.2) has joined #wikid14:41
asofrankwhen the token client talks to wikid, it uses port 80 correct?14:41
nowenasofrank: yes14:42
asofrankI'd like to restrict access to /WiKIDAdmin if possible, but I need to know if the token client will need to access that14:42
SEJeffYes, but it is encrypted with asymetric encryption which makes it awesome14:42
nowenno 443 needed for the token b/c of the asymmetric encryption14:42
nowenhaha, just got a call from a Dow Jones reporter.  brb14:43
SEJeffNice14:43
asofrankis there any way to IP restrict the admin area?14:43
SEJeffasofrank, Perhaps you could just run wikid's tomcat server through apache14:43
SEJeffThen use apache's gauntlet of security options14:43
nowenasofrank: and probably via the tomcat settings14:43
SEJeffWe use apache + mod_proxy to make wikid public14:43
asofrankah14:43
asofranki havent messed with tomcat14:44
asofrankand this is my 2nd day looking at wikid14:44
SEJeffIt is pretty straight forward. When nowen is available, he is a really huge help.14:44
asofrankdont want to spend much more time on this until the boss OK's the purchase14:45
nowenleft her a message.  wanted to know if we were seeing an up tick in biz14:45
SEJeffAre you?14:46
asofrankafter the SecurID hack last month I'd expect you would14:46
nowenyes, but it is just an acceleration of what was already happenting14:46
SEJeffgood14:47
SEJeffSo we can expect that huge new release soon, right :)14:47
SEJeffWith the better web api and multimaster sync14:47
nowenhehe, yes, it is in alpha now14:47
asofrankadd the ability to IP restrict the admin area14:48
nowenoh, here she is14:48
SEJeffnowen, We're pretty stoked to get that and roll it out to 4 continents14:48
nowenand I look forward to charging you for that :)15:11
nowensadly, the reporter did not ask me to sit for a pixelated picture for the WSJ15:13
*** asofrank has quit (Quit: Lost terminal)15:37
SEJeffwell hurry up!15:47
nowenlol15:50
*** asofrank (~laszlof@wookie.tvog.net) has joined #wikid16:52
asofrankso I was looking for radius support in apache16:57
asofrankand ended up fidning another doc on your site for the first result in google16:57
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid16:59
*** CowboyPride has quit (Remote host closed the connection)17:02
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid17:04
SEJeffasofrank, Radius support is not available in the open source version17:59
SEJeffOnly the enterprise version17:59
SEJeffBut it works well17:59
nowenyes, we did a doc on apache mod-auth-radius,  a few18:01
nowenwe just did one on mod-ldap.  at least, that's what I used for the Seccubus integratio18:07
*** nowen has parted #wikid (None)22:48
asofrankSEJeff: I know. I'm using the enterprie version23:13

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!