Monday, 2011-09-12

*** Embalmed has quit (Remote host closed the connection)00:40
*** Embalmed (embalmed@204.188.217.2) has joined #wikid00:41
*** CowboyPride (~BartSimps@cpe-075-183-170-059.sc.res.rr.com) has joined #wikid04:31
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid12:17
*** Embalmed has quit (Quit: changing servers)13:05
*** Embalmed (embalmed@204.188.217.2) has joined #wikid13:10
*** Embalmed has quit (Max SendQ exceeded)13:11
*** Embalmed (embalmed@204.188.217.2) has joined #wikid13:13
*** Embalmed has quit (Max SendQ exceeded)13:13
*** Embalmed (embalmed@204.188.217.2) has joined #wikid13:14
*** Embalmed has quit (Remote host closed the connection)13:17
*** Embalmed (embalmed@204.188.217.2) has joined #wikid13:20
*** Lake_Lurker (~Just@h200.9.30.71.dynamic.ip.windstream.net) has joined #wikid13:43
*** Lake_Lurker has parted #wikid (None)14:09
*** bill_ (c6a56402@gateway/web/freenode/ip.198.165.100.2) has joined #wikid15:35
bill_any one here15:36
nowenyes15:36
bill_the soft token i have on the phone , does it a net connecting to gen codes15:36
nowenit encrypts the PIN and send it to the WiKID server behind your firewall15:37
nowenif all is ok, the server gens the passcode, encrypts is and returns it to the token15:37
bill_so its a little diffrent from the rsa tokens15:38
nowenyes, RSA is time-based15:38
nowenso, they have to keep track of drift, etc15:38
bill_what about if my phone does not have a net connection but the laptop does, how will i get a code15:39
bill_from the laptop its self i guess15:39
nowenwell, we support an offline-challenge response mode for that scenario15:40
nowenand yes, we have PC tokens too15:40
nowenand a user can have more than one token without a reduction in security15:40
bill_what big clients do you have15:40
nowenhaha15:40
bill_lol15:40
nowennone that will say they use us15:40
nowen:)15:40
nowenyou're in canada right?15:41
bill_yep15:41
nowenyour ISP15:41
bill_i got your email15:41
bill_give me a call15:41
nowenI don't think I have your phone number15:42
nowenwas it in your submission?15:42
bill_just emailed ya15:43
bill_do you have any gov that uses this15:43
nowenI'm not sure, they could be using the open source version and we wouldn't really know15:44
nowenwe tend to let people use the software and get comfortable with it.  we don't respond to RFPs and the like15:45
bill_k15:45
nowenmost of our customers do not want anyone knowing what forms of protection they are using15:45
bill_true enough15:46
bill_so u have a big isp in canada that uses this?15:47
nowenyes, but they only have a small number of seats15:48
bill_cool15:48
bill_ill give it a shot.15:48
bill_will be in touch take care15:49
*** bill_ has quit (Quit: Page closed)15:49
*** scranley_ (d839cdfa@gateway/web/freenode/ip.216.57.205.250) has joined #wikid16:40
scranley_Seems my radius process is dying on the wikid server, can't see anything in the logs but16:41
scranley_log4j:ERROR Could not connect to remote log4j server at [172.20.8.101]. We will try again later16:41
scranley_that shouldn't kill radius right16:41
nowenno I don't think so16:41
nowenhow do you know radius is dead?16:41
scranley_when I restart the server it says RADIUS protocol daemon already stopped.16:42
scranley_and I don't see anything listening on port 181216:42
nowenhow old are your certs?16:42
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid/?searchterm=valid%20certificate16:43
nowencheck your localhost in particular16:43
scranley_first one Valid from: Thu Jul 07 13:50:46 PDT 2011 until: Sun Jul 06 13:50:46 PDT 201416:44
scranley_2nd Valid from: Thu Jul 07 10:52:11 PDT 2011 until: Fri Jul 06 10:52:11 PDT 201216:45
scranley_that looks like they are still valid16:45
scranley_I recently rebooted the server16:45
nowenis the date on the server correct?16:46
scranley_yep16:46
nowenis selinux on?16:46
scranley_sorry whats that16:46
nowenare you running the ISO?16:47
nowenor did you set up your own linux server?16:47
scranley_yes from ISO16:47
scranley_WiKID Linux 3.4.87-b83916:47
nowenwhat version of WiKID?  rpm -qa | grep wikid  will tell you16:48
scranley_something went a little wierd with the network interfaces, they didn't connect when they came up16:48
scranley_but they are working now16:48
nowenhmm16:48
scranley_wikid-utilities-3.0.9-1 wikid-server-enterprise-3.4.87.b839-1 wikid-appliance-3.4.21.b126-116:48
scranley_Sep 12 09:37:06 wikid postgres[1384]: [1-1] ERROR:  relation "db_version" does not exist Sep 12 09:37:06 wikid postgres[1384]: [2-1] LOG:  unexpected EOF on client connection16:49
scranley_this is in messages16:49
nowenwhat do you mean the interfaces didn't come up?  how did you know?16:49
scranley_I couldn't ping it, so I went in the datacenter and moved it to the other interface, but it still has the same IP address16:50
nowenPing is blocked by the WiKID firewall16:50
scranley_getting a lot of these16:51
scranley_postgres[22135]: [1-1] ERROR:  relation "db_version" does not exist16:51
nowenI don't think that's the issue16:51
scranley_k16:51
nowenrun 'wikidctl stop'16:51
nowenand then 'killall -9 java'16:51
scranley_done16:52
nowenok. run 'wikidctl start'16:52
nowenand the 'cd /; ls -Rl'16:53
nowenthat will run a bunch of stuff16:53
scranley_ok theres this other problem now, wAuth sits there and takes forever to init16:53
scranley_Waiting for wAuth initialization to complete..................................................16:54
nowenhmm16:54
scranley_it's doing that right now16:54
scranley_This all happened after I remand the raidus client on friday16:54
scranley_remade*16:54
scranley_I doublechecked all the settings it looks good16:55
nowenwhat do you mean remade?  you reconfigured in WiKID?16:55
scranley_I deleted the old radius client16:55
scranley_and made a new one with attributes16:55
scranley_that didn't work16:56
scranley_so I deleted it again, and made it w/o attributes16:56
nowenhow did it not work?  did you restart the server after the changes?16:57
scranley_after I did that, I tried to login via two factor, and the token client would lock up on the android phone16:58
scranley_it works half the time, sometimes it locks up16:59
scranley_sometimes it returns a good login number, but then the login doesnt work16:59
nowenugh, that android token is a pain.  we really hopped on the android wagon fast. the coding on it shows :(17:01
nowendid wikid finally start?17:02
*** scranley__ (d839cdfa@gateway/web/freenode/ip.216.57.205.250) has joined #wikid17:03
scranley__hm got botted17:03
scranley__now theres 3 scranleys17:03
scranley__yeah it restarted17:03
nowenhehe17:03
scranley__but still no radius17:03
nowendid wikid finally start?17:03
scranley__yes17:03
nowenrun 'netstat -anp | grep 181217:03
scranley__radius not listen on port 181217:03
nowenrun 'cd /; ls -Rl'17:04
nowenthat will generate some data for the process17:04
nowenradius needs random info to start and a headless systems doesn't have much17:04
*** scranley has quit (Ping timeout: 252 seconds)17:05
nowenwhat are the specs on this box?17:05
*** scranley2 (d839cdfa@gateway/web/freenode/ip.216.57.205.250) has joined #wikid17:05
scranley2sorry back17:05
*** scranley_ has quit (Ping timeout: 252 seconds)17:05
nowenrun 'cd /; ls -Rl'17:06
scranley2maybe i wont get kicked again17:06
scranley2k17:06
scranley2ton of stuff17:06
nowenyeah17:06
nowenjust noise17:06
nowendon't worry about it17:06
scranley2k17:06
nowenradius needs random info to start and a headless systems doesn't have much17:06
scranley2its done17:07
nowenok, run 'netstat -anp | grep 1812' again17:07
scranley2nope17:08
nowenwhat are the specs on this box?17:08
scranley2it's a amd athlon 1u  server from like 200717:09
scranley2sata17:09
nowenhow much memory?17:09
nowenshould be fine17:09
scranley21 gig I think :(17:10
nowendidn't you set up some external logging?17:10
scranley2yes17:11
scranley2its not working17:11
scranley2I could shut that off17:11
scranley2it can't reach the logging server which I don't control right now17:11
scranley2so it's not on wikid17:11
nowencan you cd into /opt/WiKID/logs and run 'ls -ltr' and see if there is a log from today?17:13
scranley2yes, but all it says is log4j:ERROR Could not connect to remote log4j server at [172.20.8.101]. We will try again later17:13
scranley2I can shut that off17:14
nowenwhich log is that?17:14
scranley2raidus17:14
nowenwhat about wauth.log?17:14
scranley2same17:14
scranley2log4j:ERROR Could not connect to remote log4j server at [172.20.8.101]. We will try again later.17:14
nowenanything in /opt/WiKID/tomcat/logs/catalina.out  ?17:14
scranley2yeah just some stuff about the webserver starting17:15
scranley2INFO: Starting Coyote HTTP/1.1 on http-443 Sep 12, 2011 10:08:21 AM org.apache.catalina.startup.Catalina start INFO: Server startup in 1277 ms17:15
nowenand there's nothing in the WiKIDAdmin  logs either?17:15
scranley2not of interest17:16
scranley2I tried looking at those17:16
scranley2a little debug17:16
scranley2but nothing about radius17:16
scranley2which should probably be there17:16
nowenstill no radius listener on udp port 1812?17:16
scranley2sec17:17
scranley2ugh whats suppose to be in log4j.properties to log locally I think I screwed it up17:21
nowentry this: http://pastebin.com/kt3dmDMJ17:21
scranley2thanks!17:23
scranley2no radius yet though I'll keep checking17:23
nowenyou will have to restart wikid to get the new logging going17:23
scranley2ok I restarted it, logging looks like its working17:24
scranley2DEBUG com.wikidsystems.server.WikidIPCListener  - Starting IPC thread.17:24
scranley2Failed to create RADIUS  server socket on port 8388: java.net.BindException: Address already in use17:24
nowenwhat does 'netstat -anp | grep 8388' return?17:24
scranley2tcp        0      0 :::8388                     :::*                        LISTEN      12400/java           tcp        1      0 ::ffff:127.0.0.1:45212      ::ffff:127.0.0.1:8388       CLOSE_WAIT  28111/java           udp        0      0 :::8388                     :::*                                    28111/java17:25
nowenok, run 'wikidctl stop' again17:25
nowenand then 'killall -9 java'17:25
scranley2done17:25
nowen'netstat -anp | grep 8388' again17:26
nowenshould return nothing17:26
scranley2yes17:26
scranley2I returns nothing17:26
scranley2it17:26
nowenok, now run wikidctl start17:26
scranley2wauth seems to be starting quickly now17:27
scranley2ok this is all thats in the raidus log17:27
scranley20    [main] DEBUG com.wikidsystems.server.WikidIPCListener  - Starting IPC thread. 30   [main] DEBUG com.wikidsystems.radius.authserver.AuthServer  - Started IPC Listener. 31   [main] DEBUG com.wikidsystems.radius.authserver.AuthServer  - Registered callback for IPC.17:27
scranley2brb17:27
nowenok, do you see the listener?17:27
scranley2yes17:29
scranley2you talking about this guy?17:29
scranley2tcp        0      0 :::8388                     :::*                        LISTEN      29371/java17:29
scranley238765 [main] DEBUG com.wikidsystems.radius.authserver.AuthServer  - Can't get snmp manager address, disabling traps. 239150 [main] DEBUG com.wikidsystems.client.wClient  - wClient(127.0.0.1, 8388, /opt/WiKID/private/localhost.p12, sa1VAK24) called ... 239152 [main] DEBUG com.wikidsystems.client.wClient  - init() called ... 239178 [main] DEBUG com.wikidsystems.client.wClient  - creating keyFile object: /opt/WiKID/private/localhost.p17:31
scranley2240866 [main] INFO  com.wikidsystems.radius.log.DBSvrLogImpl  - RADIUS Receiver Started: listening on port 838817:32
nowenno, the 1812 guy :)17:34
scranley2not yet17:34
nowenhmm17:34
nowendid you make any changes to the radius protocol config via the WiKIDAdmin?17:42
scranley2let me check17:42
scranley2hostname: Wikid Radius Authentication17:45
scranley2ip address 127.0.0.117:45
scranley2port 181217:45
scranley2Multihomed on17:45
scranley2Normal17:45
scranley2181317:46
scranley2it's not a multihomed server though17:46
nowenthat's ok17:46
nowenand what do you have for the network client?17:46
scranley2pretty basic just the named and the ip address of the client protocol radius and domain.17:49
nowenwhat command are you using to check to see if radius is listening?17:50
nowenthe 'netstat -anp | grep 1812' command?17:51
scranley2yes17:52
nowendo you have ldap enabled?17:52
scranley2no17:52
scranley2I can see the radius client trying to connect17:52
nowenhow? via tcpdump?17:53
scranley2yes17:53
nowenif you run 'iptables -L -n' do you see the radius network client IP listed?17:53
scranley2yes its listed there for 181217:55
nowenhmm17:55
nowenis there anything in in the radius.log?17:55
scranley2240787 [main] DEBUG com.wikidsystems.client.wClient  - wClient connection to wAuth 3.0 ACCEPTED 240807 [main] INFO  com.wikidsystems.radius.accounting.PlainAccountingImpl  - Accounting logs set up. 240816 [main] DEBUG com.wikidsystems.radius.nas.UnknownNAS  - NASCallBack logs set up. 240866 [main] INFO  com.wikidsystems.radius.log.DBSvrLogImpl  - RADIUS Receiver Started: listening on port 838817:55
scranley2these are the last few lines17:56
nowenI'm restarting my test system, but because i have ldap on it is taking forever17:57
scranley2kk17:59
nowenblagh, I screwed up my own log4j.properties ;)18:02
scranley2I have to change my Wuath key now because I pasted it here18:03
nowenooh18:04
nowenyou will have to recreate the intermediate cert and localhost18:04
*** pa1 (451c7f02@gateway/web/freenode/ip.69.28.127.2) has joined #wikid18:07
*** pa1 has quit (Client Quit)18:09
scranley2ok I updated the certs18:10
nowenlet's go ahead and update the WiKID server too18:11
nowenrun 'wget http://wikidsystems-dl.com/wikid-server-enterprise-3.4.87.b952-1.noarch.rpm'18:12
nowenand 'rpm -Uvh wikid-server-enterprise-3.4.87.b952-1.noarch.rpm'18:12
scranley2k18:12
scranley__do I have to reboot?18:15
nowenno18:15
nowenjust start wikid again18:15
scranley__ok did that18:15
nowenrun 'tail -f radius.log' and see what comes up18:17
nowenthe last log made it sound like it was listening on 8388, not 181218:17
scranley2ok finally it worked18:22
scranley2!18:22
nowenmagic!18:24
nowenlol18:24
nowenso, maybe the upgrade?18:24
scranley2well I also redid the cert all that so I have to screw with radius client again to get the attributes working18:25
scranley2so i guess we'll see18:25
scranley2I know how to fix it now though I guess18:25
scranley2well ok 2 factor auth is working again too course18:27
nowenso, you can login to the vpn?18:29
scranley2yes18:29
scranley2but I need it to give me the attributes so that the firewall will hand it the ip I specify in LDAP18:29
scranley2thats what I started working on18:30
scranley2I need to remake the client in wikid to pass attributes right18:30
nowenok, you can do attributes two ways - in the network client or in groups18:30
nowenwhat attribute do you want it to pass?18:30
scranley2FramedIP and FramedNetmask18:31
scranley2for a start18:31
nowenso, if you go to the Network client page and hit modify, then modify again, select Framed-IP-Address, enter it in the box and hit Add. then Modify NC and restart the server18:32
scranley2thanks18:35
nowenit should work, I tested it recently18:35
scranley2The framed IP address seems to be coming back in some wierd value19:05
nowenwhat value did you enter?19:05
scranley2Framed-IP-Netmask = 0x7261646975734672616d656449504e65746d61736b19:05
nowenwhat what is coming back?19:06
scranley2radiusFramedIPAddress19:06
scranley2Framed-IP-Address radiusFreamedIPAddress are the two values19:06
scranley2radiusFramedIPAddress*19:06
nowenshould the netmask be something like 255.255.255.240?19:07
scranley2yeah19:10
scranley2I thought the IP and Netmask were dynamic assigned from the ldap server, through radius. ah im all confused I'll have to think about it19:17
nowenI don't know how you have it setup on the vpn side.19:17
nowenfor wikid, you set a value and it is returned via radius19:18
scranley2The firewall VPN talks to freeradius, freeradius uses openldap for authorization, then uses wikid for authentication19:18
scranley2Ldap passes the correct ip and netmask, but the firewallvpn doesn't seem to want to assign those to client.19:20
scranley2thats probably not anything to do with Wikid though19:20
scranley2I thought I would just try to pass something from wikid and see if it worked19:20
nowenhehe, no, sorry.  don't know much about that19:21
*** perestrelka has quit (*.net *.split)19:24
*** perestrelka (~vladdy@194.242.5.47) has joined #wikid19:24
*** scranley2 has quit (Ping timeout: 252 seconds)19:27
*** nowen has parted #wikid (None)21:42
*** scranley__ has quit (Quit: Page closed)23:00

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!