Monday, 2011-08-22

*** Embalmed has quit (Remote host closed the connection)03:47
*** Embalmed (embalmed@204.188.217.2) has joined #wikid03:48
*** Embalmed has quit (Remote host closed the connection)03:48
*** Embalmed (embalmed@204.188.217.2) has joined #wikid03:51
*** Embalmed has quit (Remote host closed the connection)03:51
*** Embalmed (embalmed@204.188.217.2) has joined #wikid03:52
*** Embalmed has quit (Remote host closed the connection)04:16
*** Embalmed (embalmed@204.188.217.2) has joined #wikid04:19
*** Lake_Lurker (~Just@h22.164.17.98.dynamic.ip.windstream.net) has joined #wikid11:10
*** Lake_Lurker has parted #wikid (None)11:10
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid12:13
*** perestrelka has quit (Quit: Computer has gone to sleep)14:42
*** nowen has parted #wikid (None)16:06
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid16:13
*** mick_laptop has quit (Changing host)18:03
*** mick_laptop (~mick@clamwin/admin/mickhome) has joined #wikid18:03
*** Luudes (42df3895@gateway/web/freenode/ip.66.223.56.149) has joined #wikid18:16
Luudeshola!18:17
Luudesor hello, whatever works18:17
nowenhi18:17
Luudeswanna chat about wikid18:18
Luudesspecifically.. authorization while using radius18:18
nowengood place for that :)18:18
nowenok18:18
Luudesi am trying to forklift ourselves away from another soluition while building up a PCI compliance product18:19
Luudesone of the goals is to simplify management of whatever we intend to use18:20
nowenok18:20
Luudesfor a unix/windows environment, is there anyway to use Active Directory to authorization while using RADIUS and WiKID for authentication?18:21
LuudesI am not very deep in RADIUS, so there might some power there...18:21
Luudesbut... in our current solution, we need to bind the unix boxes to LDAP (winbind) for group auth18:22
Luudesand then strong authententication using what we have now...18:22
nowenyes, use the windows radius plugin18:22
nowenIAS/NPS18:22
Luudesit is user provisioning and deprovisioning that is the real issue.. the manual process..18:23
nowenyou can set up a script to allow users to add their own tokens based on the AD creds too18:23
Luudesyeah, I was reading about that on the support site, but didn't find anything about authorization, espeically around SSH access to the unix hosts18:24
nowenso, for ssh, you want to use pam_radius18:24
Luudesoh, that is what I like about WiKID, welcome package will come with teh 360 about setting up a software token18:24
Luudesso no IT support required :D18:24
nowenpoint them to IAS/NPS and then have IAS/NPS proxy to wikid18:24
Luudesfor the authorization piece then....18:25
Luudessay, I have an unix host and we are trying to authorize levels of access using sudo...18:25
LuudesAD group 1 = sysadmin18:26
LuudesAD group 2 = not so much sysadmin18:26
LuudesAD group 3 = you can only run 'ls' from your home directory...18:26
Luudesi am trying to figure out how to make that work without queryring LDAP (AD) for group memberships18:27
nowenok, that's moving beyond my knowledge.  I mainly to authn, not authz18:27
nowenplus I hate ldap :)18:28
Luudesunix hates AD LDAP :)18:28
Luudesunix hates winbind18:28
Luudes:)18:28
nowenhehe18:28
Luudesactually redhat ES 6 hates all of it18:28
Luudeswhich is kind of fun18:28
Luudesanyway...18:28
nowenbut it should be doable, have the auth line in /etc/pam.d/sudo point to radius and the account line point to ldap, right?18:29
LuudesLDAP is fine... getting people to stop using '*' in attribute queries is a huge thing in performance :D18:29
Luudesthat could work...18:30
Luudesi probably need to get a little deeper into RADIUS to see what I can do18:31
nowenpam_radius is pretty easy18:32
nowenare you on windows 2003 or 8?18:32
Luudesit would be awesome if RADIUS from WiKID could say.. "hey, this dude is good to go for authn, and is part of the this group in WiKID which returns an attribute value pair back to the client...)18:33
Luudes2008 NPS18:33
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps/?searchterm=nps18:34
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/pam-radius-how-to/?searchterm=pam%20radius18:34
Luudesoh man, i didn't see that one!18:34
Luudes<- thumbs down for not looking hard enough!18:34
nowenhehe.  for the record, our search tool works pretty well18:35
nowenwe have a lot of stuff on the site.  it's hard to see it all18:35
nowenyou will have to compile pam_radius from source, but the .so can then be used on all your rhel systems, I think18:36
Luudesfor sure!  let me digest that document and see what i can do!18:36
Luudesthanks for the heads up!18:36
Luudesyou guys in ATL?18:36
nowenyes18:36
Luudesme too..  Marietta St18:37
nowenahh18:37
Luudesmight need to buy ya a beer if this works out :)18:37
nowenhehe18:37
Luudesalright, outta here, thanks for the help!18:38
nowenlater!18:38
*** Luudes has quit (Quit: Page closed)18:38
nowenasofrank: you there?19:46
*** nowen has parted #wikid (None)21:56

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!