Monday, 2011-06-27

*** rodhajj (d465f2ea@gateway/web/freenode/ip.212.101.242.234) has joined #wikid12:06
rodhajjhi12:06
rodhajjI'm trying to install WiKID on Centos but I'm facing  a problem when starting wikidctl services12:07
rodhajjcan anybody help me12:07
*** rodhajj has quit (Ping timeout: 252 seconds)12:40
*** nowen (~nowen@adsl-98-66-165-16.asm.bellsouth.net) has joined #wikid12:45
*** WallyK (4004456e@gateway/web/freenode/ip.64.4.69.110) has joined #wikid14:11
WallyKHello14:12
nowenhi14:13
WallyKI am currently running wikid-server-enterprise-3.3.8-b2717 as a vertual machine.  I would like to upgrade to the newest version but keep my config14:14
WallyKcan you point me in the right direction to do this?14:14
nowenok, do you have any special files you have configured on the server?  like ADRegister.jsp or example.jsp?14:15
WallyKno it is a pretty standard install.  It is configured to talk to our fortigate14:15
nowenthat your users might be using to register, eg?14:15
nowenok - piece of cake14:16
WallyKno I just manualy validate my clients14:16
nowentake a look at the Upgrade instructions here: http://www.wikidsystems.com/downloads/download-the-wikid-enterprise-server-3.0-rpms14:16
nowenat the bottom of the page14:16
WallyKthat is exactally what I was looking for.  I was hoping the upgrade was that easy.  thanks I will give that a try.  If I have problems I will be back : )14:18
nowenok - I should be here - I do have to run out for one errand at some point14:18
WallyKcan I patch the back ground os as well or will this do that?14:20
nowenyou can run 'yum update' to update the od14:20
WallyKI am going to be make it internet and I want to make sure it is patched14:20
nowenyes14:21
WallyKin the past we have just used our BES to connect to it on blackberrys but now we have iphone and android devices that I need to configure14:21
nowenahh14:22
nowensome people have set up an apache server to proxy requests to the inside14:22
WallyKhmm that does sound more secure.  do you have any documentation on that?14:25
WallyKI was linking of putting it in a dmz14:25
WallyKthinking14:25
nowena lot of people put it in the dmz.  the server is running its own firewall and should be fine there14:26
nowenI don't have any documentation on the proxy setup, but I can get you close14:26
WallyKI am using it for authenticating an internal app as well so that might be a better choice than a dmz14:27
nowenwe use an apache rule to route token requests on our demo server: RewriteRule ^/wikid/(.*) http://localhost:8090/wikid/$1 [P]14:27
nowenall the token traffic goes to /wikid/14:27
nowenbut we are hosting it on the same server, so we don't use proxypass.14:28
WallyKhmm I am not an apache guru but I will take a look14:29
nowenok - gotta pop out for a bit b/c I bricked my phone ;).  be back in a bit15:16
*** nowen has quit (Quit: Leaving.)15:17
*** Martin____ (adb4ab2d@gateway/web/freenode/ip.173.180.171.45) has joined #wikid15:27
Martin____Can someone answer a general "how does it work" question for me?15:28
Martin____From what I read and saw on the Wikid website, I'm still not entirely sure whether the Authentication Server piece of the puzzle is something that I need to set up myself...15:29
Martin____of whether that is a something that's provided by Wikid as an external service to a customer setup15:29
*** WallyK has quit (Ping timeout: 252 seconds)16:04
drnezyou need to setup the authentication server yourself.16:06
drnezthe software provided by wikid runs on the server, and acts as a radius server for your login clients16:06
drnezwhen the token client requests a password from the server, the database is updated to allow that user to login to the system using the password for a predetermined amount of time, after which is will be voided16:07
*** nowen (~nowen@adsl-98-66-165-16.asm.bellsouth.net) has joined #wikid16:10
drnezhey Nick16:11
drnezgot a question for you16:11
drnezWe want to test the enterprise edition for about a week on a semi-production level16:12
drnezI have 5 people who will be beta testing16:12
drnezthe accounts keep flipping to "disable" after their first login. Is this a limitation of the un-purchased version?16:13
nowendrnez: no16:15
nowenare you testing on a web app?16:15
drnezno, a VPN16:16
nowenssl-vpn?16:16
drnezyeah16:16
nowentypically, this happens when a web-app doesn't have caching set, so the web server re-authenticates every element on the page.  which fails fast16:17
drnezwe're using a soft client, not authenticating on a webpage16:17
nowenhmm.16:18
nowenon the WiKIDAdmin logs, do you see multiple auth requests?16:18
drnezlet me check16:18
drnezwhich source would it be under16:19
nowenif you set it for None, they all show up. set log level to debug16:20
drnezyeah, I got some people hammering the admin interface with bogus requests16:21
nowenon the Configure loggers page, if you set the three middle loggers to debug and hit apply, you will also get more info16:21
drnezah, there we go16:21
drnezlets see16:21
drnezyeah, bunch of login failures16:22
drnezin quick succession.16:23
nowenwhat kind of vpn is this?16:23
drnezfortigate 200b16:23
nowenare you using radius between them?16:23
drnezyes16:23
drnez<153> Access-Request(1) LEN=164 10.10.10.1:1510 Access-Request by asoryan2 Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.16:24
drnezdunno why its trying MS-CHAP16:24
*** Martin____ has quit (Ping timeout: 252 seconds)16:27
drnezalso, where is the APi documentation on manually registering a client, and adding a new registration code to an existing client16:31
nowenhttp://www.wikidsystems.com/support/wikid-support-center/manual/wikid-network-client-wclient-api-manual16:32
nowenbut you might find /opt/WiKID/tomcat/webapps/WiKIDAdmin/example.jsp more useful16:32
nowenand probably more up-to-date16:33
drnezany idea why the login process would be trying multiple times like that with presumably varying protocols?16:33
nowenthere is only one new thing that is not in the api docs16:33
nowenhuh, so it starts with say pap, succeeds and then tries chap?16:33
drnezlet me see16:34
drnez2011-06-27 12:04:41.767INFOcom.wikidsystems.radius.access.WikidAccess4Access granted for asoryan2, domain code: 207210105098 client: /10.10.10.116:35
drnez2011-06-27 12:04:41.767INFOcom.wikidsystems.radius.log.DBSvrLogImpl<148> Access-Accept(2) LEN=106 10.10.10.1:1509 Access-Request by asoryan2 succeeded16:35
drnez2011-06-27 12:00:13.293INFOWiKIDAdmin.validatenewuser.jspUser manually validated: asoryan2with registration code: 6GQeXlQ216:35
drnezthat seems to work just fine16:35
drnezthen 2 minutes later, theres a bunch of failures16:35
drnez2011-06-27 12:06:26.834INFOcom.wikidsystems.radius.log.DBSvrLogImpl<153> Access-Request(1) LEN=164 10.10.10.1:1510 Access-Request by asoryan2 Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.16:35
drnez2011-06-27 12:06:26.827INFOcom.wikidsystems.radius.access.WikidAccess4Access denied for asoryan2, domain code: 207210105098 client: /10.10.10.116:36
drnez2011-06-27 12:06:26.827INFOcom.wikidsystems.radius.log.DBSvrLogImpl<152> Access-Request(1) LEN=106 10.10.10.1:1510 Access-Request by asoryan2 Failed: AccessRejectException: Access Denied16:36
nowenbut why is the user manually validated in the third step?16:36
drnezbunch of those in quick succession.16:36
drnezthats actually first16:36
nowenahh16:36
drnezi manually validated them16:36
nowendid you follow our guide? http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-wikid-two-factor-authentication-to-a-fortinet-vpn/?searchterm=fortigate?16:37
drnezlet me see if they have auto-reconnect enabled16:37
drnezyes, I wrote it remember :P16:37
nowenahh :)16:37
nowenlol16:37
drnezI'll bet they have auto-reconnect enabled16:38
drnezfor some reason the VPN client disconnected, and tried to reconnect using the last password16:38
drnezafter X amount of times, it gets blocked16:38
drnezquestion being, how do I modified X in that?16:38
drnezoh hey, I have another nick now. No wonder you didnt notice16:39
*** drnez is now known as asofrank16:39
nowenahh16:39
nowenmystery solved16:39
asofrankso is there a setting somewhere where I can define the number of login failures before it disables the account?16:40
nowenyes, on the domain page16:40
asofrankmax bad passcode attempts right?16:41
nowenyes.  I can't remember if it requires are restart.  I don't think so.16:41
asofrankk16:42
asofrankyeah, was set to 3 as default16:42
nowenstill, that should be fine.  the Fortigate is doing something wrong16:42
asofrankthats a bit too paranoid for our fat fingered staff16:42
asofranki'm willing to bet that its the client trying to autologin multiple times16:42
nowenhmm.16:42
nowenso, is it just this one user?16:43
asofrankits just weird that the MS-CHAP is coming through16:43
asofrank2 users right now16:43
asofrank2 out of 5 testing it16:43
noweni guess there is an option to remember the password16:43
asofrankyeah16:43
asofranka couple of them were complaining that the android app was crashing as well16:44
asofranki cant reproduce on my android device16:44
nowendo they have new phones?  the ui on the android app stinks, imo. we will be re-writing it eventually16:51
asofrankone is using the same phone as me, the HTC EVO16:55
asofrankand yeah, the UI/functionality stinks16:55
asofrankbut I havent had it crash on me16:55
asofrankthe "back" button should exit the program when you reach the top level menu16:56
asofrankand not just go back indefinately16:56
nowenyeah, the dev claimed that it was the standard. if so, no one else is following it16:56
asofrankDefinately not standard. :)17:01
*** nowen has parted #wikid (None)22:30

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!