Wednesday, 2011-06-15

*** mick_laptop has quit (Ping timeout: 240 seconds)08:16
*** mick_laptop (~mick@mickweiss.com) has joined #wikid08:18
*** nowen (~nowen@adsl-98-66-165-233.asm.bellsouth.net) has joined #wikid12:52
perestrelkab13:43
perestrelkaHi Nowen13:44
nowenhi perestrelka13:44
perestrelkado you have a moment for a question?13:44
nowensure13:44
perestrelkaso we use wikid for VPN auth13:44
perestrelkavia Radius13:44
perestrelkathere is a user who gets disabled for a some reason in wikid13:45
perestrelkawhere can I find the info on what causes the disabling?13:45
nowenif you search the WiKIDAdmin  logs for his device, what comes up?13:46
perestrelkaif devices are not indentified by the username, I wonder what is the identificator?13:46
*** Lake_Lurker (~Just@h218.200.140.67.dynamic.ip.windstream.net) has joined #wikid13:46
nowenI'm sorry - I meant device id, first look in the user page for the user, then copy the deviceID13:47
perestrelkaaah just a moment13:47
perestrelkathere is nothing in files under /opt/WiKID/log13:48
perestrelkais it normal that the ID is a negative number?13:48
nowenI meant the WiKIDAdmin web ui logs13:48
perestrelkak13:48
nowenyes, negative numbers are ok13:49
perestrelkaif I search by the id in web interface13:50
perestrelkathe only message for the last 24 hours is "Issued passcode to device ..."13:50
perestrelkafor sure they were disabled within that period13:50
nowenis Log Level set to debug?13:50
perestrelkayep13:50
nowenhmm.  try 2 days13:51
perestrelkatwo messages "Issued passcode to device"13:51
nowenwhen i test disablement for bad PINs, I get: Recieved bad passcode request. Incrementing bad attempt counter on device 641730693699163838713:52
nowenand then Device 6417306936991638387 disabled due to bad passcode attempts.13:52
nowentry doing a search for 'disable'13:53
perestrelkak13:53
perestrelkahm... no results13:54
perestrelkamaybe I should change something for loggers?13:54
perestrelkalike increase their level13:54
nowenmine are on the default, but if you want you can set com.wikidsystems.client.wClient and com.wikidsystems to debug13:54
perestrelkak changed13:55
perestrelkaI'll get back to you tomorrow about that ;)13:55
nowenyou can test with your own token, if you like13:55
nowento make sure disablement is working.13:56
perestrelkait worked for me when I tested13:56
nowenso, did you re-enable the user in the WiKID server?13:56
perestrelkaI just wonder why that guy gets disabled13:56
perestrelkayeah13:56
perestrelkalike I reenable them each day13:56
perestrelkaand he tells he inputs the pin once13:56
perestrelkaget logged in13:56
perestrelkathen at some point it gets out of vpn and is not able to login anymore13:56
perestrelkatill I re-enable his account13:57
perestrelkabtw is 3.4.85-b758 the latest enterprise release?13:57
nowenhmm. I wonder if he is telling his vpn client to remember the password13:57
perestrelkano he doesn't13:57
perestrelkathat was the first thing I checked with him13:57
nowenwikid-server-enterprise-3.4.87.b839-1.noarch.rpm is the latest.   http://www.wikidsystems.com/downloads/changelogs/enterprise-changelog13:58
perestrelkarpm -U will work?14:02
nowenyes14:02
perestrelkak thanks for all your help14:02
*** esoteric (43840c45@gateway/web/freenode/ip.67.132.12.69) has joined #wikid14:02
nowennp14:02
nowenodd that it is not in the logs14:02
perestrelkaI'll get back to you tomorrow about those strange disablings14:02
nowenok14:02
perestrelkapossible something will be cought today14:02
perestrelka*caught14:03
esotericis there a time limit on reg codes?14:03
nowenyes,14:03
esoterichow long?14:03
esoterichour?14:03
nowenesoteric: RegCodeTTL14:03
nowenIt was, but then we upped the default to 24 hours14:03
nowenyou can change it in Configuration, Set Parameters and the restart14:04
esotericcool14:04
esotericalso14:04
esotericthe web interface seems to be vulnerable to atleast 1 XSS attack14:04
nowencan you email me details?14:05
esotericsure14:05
esotericwe are still running scans but when i have the full details I will send em over14:05
nowenof course, we recommend that the web interface only be available behind the fw14:05
esoteric:)14:05
nowenbut, I'm not sure everyone does that :)14:05
*** Lake_Lurker has parted #wikid (None)14:06
*** Lake_Lurker (~Just@h218.200.140.67.dynamic.ip.windstream.net) has joined #wikid14:12
*** Lake_Lurker has parted #wikid (None)14:12
esotericand when you say restart you just mean restart the services14:22
esotericthe whole box doesnt need to go down right?14:22
nowenyes, just the services14:22
esotericmerci14:22
nowenok - I'm looking for two more twitter followers @wikidsystems - then I will have 1337 followers and follow 1337.  who is in?14:23
*** Lake_Lurker (~Just@h218.200.140.67.dynamic.ip.windstream.net) has joined #wikid14:42
*** Lake_Lurker has parted #wikid (None)14:42
*** vp_ (40b3d246@gateway/web/freenode/ip.64.179.210.70) has joined #wikid14:52
vp_Is anyone here for a help?14:53
nowenyep14:53
vp_Hello, Nick. How are you today?14:53
nowengood, and you?14:53
vp_not too bad.14:53
vp_Nick, I am getting "AccessRejectException: Access Denied" 32 times in a row right after my user gets granted for an access.14:55
vp_and eventually, my user account gets disabled.14:55
nowensounds like your session cookie is not working14:55
nowenI'm guessing there are 32 elements on your first page14:55
vp_so can you tell me it in more details, please?14:56
vp_You the session cookie on the webserver? or wikid server?14:56
vp_*you mean the session cookie on the webserver or wikid server?14:57
vp_or you are talking about the session cookie on a browser? If you are referring to the one on a browser, yes I enabled it.14:59
nowenweb server15:03
nowenyour web server is attempting to authenticate each element on the page15:03
vp_ok. so you are saying we have to set a cookie for the session on the apache configuration?15:03
nowenyes15:04
esotericnowen: you want me to use the contact form on the page or do you have a direct email I can use for the xss info?15:04
nowenvp_: do you have AddRadiusCookieValid 60 set?15:04
nowenesoteric: nowen @ wikidsystems.com15:05
esotericmerci15:05
vp_you are talking about the apache configuration on the webserver, correct?15:05
nowenyes15:05
vp_PLUS we have to set a cookie for the session on the apache conf, correct?15:06
nowenhmm. I'm not sure about apache configs on debian.  you need a session cookie. I've done it on via " AddRadiusCookieValid 60 "  and via dbm on redhat15:07
vp_ok, let me check it on our end again. thx.15:08
nowennp15:09
*** vp_ has quit (Ping timeout: 252 seconds)15:17
*** perestrelka has quit (Ping timeout: 252 seconds)15:25
*** perestrelka (~vladdy@194.242.5.47) has joined #wikid15:26
esotericwhere are the logs located that you can view through the web util?15:31
nowenthey are in the db, but you can direct them to /opt/WiKID/log by changing /etc/WiKID/log4j.properties15:33
*** esoteric has quit (Ping timeout: 252 seconds)15:35
*** esoteric (43840c45@gateway/web/freenode/ip.67.132.12.69) has joined #wikid15:38
esotericirc web client fail15:38
esotericso ... what kind of database is this running?15:38
nowenpostgresql15:40
nowenchange it to http://pastebin.com/Zw5LDujg15:41
esotericpostgres15:42
esotericyea i dont want to redo the scans15:45
esotericI have all the data I need to get the info you need15:45
esotericI just have to get it from the db15:45
esotericwhich I am now in15:45
esoterici just haven't used postgres in years15:46
*** mick_laptop has quit (Changing host)15:53
*** mick_laptop (~mick@clamwin/admin/mickhome) has joined #wikid15:53
nowenbrb16:16
nowenb16:27
esotericyup yup16:55
esotericnowen: I sent you that email I am still working with the logs17:49
nowenk17:49
esotericill shoot you a reply when I have some better info17:49
nowenso, what are you trying to do with the logs?17:49
esoterici found a work around :P17:50
esotericarchive logs > download > extract17:50
esoteric:)17:50
nowenhehe17:50
nowenyou can also set up syslogging17:50
esoterici just wanted a txt file easier for me to work with17:50
esotericyea, which I will probably do later17:50
esotericsent the logs18:18
nowenthx18:18
esotericsure thing18:18
esotericnot sure as which one was triggering it those are just some of the tests the fuzzer runs18:19
esotericyou can write a simple script to loop through each line and replace it with unique value into the alert to figure out which was calling it18:19
*** nowen has quit (Read error: Connection reset by peer)21:16
*** nowen (~nowen@adsl-98-66-165-233.asm.bellsouth.net) has joined #wikid21:16
*** cdub_ (40fee8e2@gateway/web/freenode/ip.64.254.232.226) has joined #wikid21:16
cdub_I have a question about the registed url option on the domian management page on the wikid server21:18
nowencdub_: yes, it is rather undocumented :)21:18
nowenit is for mutual https authentication21:18
nowenleave it blank, unless you want the WiKID PC tokens to validate the SSL cert of a targeted website21:19
cdub_no matter what I put I get unable to validate the registered url. My guess is I am doing something wrong21:19
cdub_I would like to try an use the option21:19
nowenwhat are you entering?21:19
cdub_I have a test deployment setup for a customer and everything else works great21:19
cdub_I am putting the url for the ssl site21:19
cdub_https://vpn.customername.com21:20
nowenany https url that the client can reach should work - ahh, but try restarting the token21:20
cdub_I get the error on the server? I am not sure if this would cause an issue but the name resolves to the internal ip address from the LAN21:20
nowenis the token on the lan too?21:21
cdub_no, I am running the wireless token off of a Blackberry. I get the error when trying to save the url in the domain management page on the server21:22
nowenahh, I think I see21:22
nowenis the server able to get an ssl cert from that page?21:22
cdub_how would I test that?21:23
nowenwell, you could run 'wget https://vpn.customername.com' from the command line21:24
cdub_let me see21:24
cdub_is there any issue if the cert is self signed (using self signed for testing)21:25
nowennope, shouldn't be21:26
cdub_seems like my dns settings may have issues21:28
cdub_give me a sec I am not that familiar with linux21:29
nowenyou can put an entry in /etc/hosts21:29
nowenipaddress   fullyqualifieddomainname21:29
cdub_ok so just setup a static mapping then21:31
nowenfor now I think that is fine21:31
cdub_ok that was the issue21:33
cdub_thanks21:33
cdub_by the way this is a grate product21:33
nowenthe other thing to know is that the domain has to be configured for it before the token is reg'd21:33
nowenthanks!21:33
cdub_can I ask a question about licensing21:33
nowenyes21:33
cdub_my customer has about 50 users but only 10-15 will need tokens so I can just buy the 10 to 15 token licenses?21:34
nowenyes21:34
cdub_ok great21:34
cdub_I will get back to testing but so far everything has been fairly fast and simple. Thanks for the greate support21:35
nowenthey will have to buy 10 or 2021:35
nowenmy pleasure21:35
cdub_so they can only order in blocks of 10?21:35
nowenor 2521:35
cdub_ok. Have a great day21:35
nowenso, yes, effectively21:35
nowenyou too!21:35
*** cdub_ has quit (Quit: Page closed)21:36
*** esoteric has quit (Quit: Page closed)22:24
*** nowen has quit (Quit: Leaving.)22:33

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!