*** WiKIDLogbot (~WiKIDLogb@ec2-174-129-6-100.compute-1.amazonaws.com) has joined ##wikid | 14:37 | |
card.freenode.net | Users on ##wikid: @WiKIDLogbot | 14:37 |
---|---|---|
*** WiKIDLogbot (~WiKIDLogb@ec2-174-129-6-100.compute-1.amazonaws.com) has joined ##wikid | 14:47 | |
card.freenode.net | Users on ##wikid: @WiKIDLogbot | 14:47 |
*** WiKIDLogbot (~WiKIDLogb@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid | 15:03 | |
card.freenode.net | Topic for #wikid is: support for the WiKID Strong Authentication System. If no one is here, try the nabble forums: http://www.wikidsystems.com/support/support/wikid-forums | 15:03 |
card.freenode.net | Users on #wikid: WiKIDLogbot @nowen sakhi_ CowboyPride perestre1ka mick_laptop asofrank | 15:03 |
*** WiKIDLogbot (~WiKIDLogb@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid | 15:05 | |
card.freenode.net | Topic for #wikid is: support for the WiKID Strong Authentication System. If no one is here, try the nabble forums: http://www.wikidsystems.com/support/support/wikid-forums | 15:05 |
card.freenode.net | Users on #wikid: WiKIDLogbot @nowen sakhi_ CowboyPride perestre1ka mick_laptop asofrank | 15:05 |
nowen | hey look who it it is | 15:05 |
nowen | but are you logging WiKIDLogbot? | 15:07 |
*** Gibby13 (~Gibby@cpe-066-057-170-142.sc.res.rr.com) has joined #wikid | 15:22 | |
Gibby13 | A server code has to be a static routable internet IP correct? | 15:23 |
nowen | Gibby13: that's the idea, yes | 15:24 |
Gibby13 | hmmm, so no way to specify just a domain name? | 15:24 |
nowen | dns is not supported in this product | 15:24 |
nowen | you can nat the IP | 15:24 |
nowen | and we're coming out with a new product that supports dns | 15:25 |
Gibby13 | yeah just trying to figure out how i would update the server code when my routable IP changes | 15:25 |
nowen | we can put an entry into our dns system that would work | 15:25 |
nowen | that is how we do the 88888888888 domain, which is clearly not an ip | 15:26 |
Gibby13 | but i have a handful of services and domains running of this 1 IP... would that be an issue? | 15:26 |
nowen | also, the PC tokens support changing the default dns - but the smart phone tokens do not | 15:26 |
Gibby13 | right now i have all my domains pointing to a cname that i have with dyndns.org, then that is natted to an apache proxy server, and then it forwards to the correct internal apache server based on the domain name... if I registered my domain with your dns and have it point to my dyndns domain that would work? | 15:28 |
Gibby13 | well i guess it woudln't work b/c i still have to specify a zero-padded ip... | 15:29 |
nowen | I think so | 15:29 |
nowen | no, the tokens check the IP and the wikidsystems.net dns | 15:29 |
Gibby13 | so if i register my dns with you, i just put in a private ip for the server code? | 15:30 |
nowen | no. I would make an entry like 66666666666.wikidsystems.net and point it to your server server.dyndns.org. | 15:30 |
nowen | your domain id would be the 6666 number | 15:31 |
Gibby13 | ahhh ok | 15:31 |
Gibby13 | ok, can you make one for me and have it point to wikid.twoitguys.com ? | 15:31 |
nowen | host 000000000002.wikidsystems.net | 15:38 |
nowen | 000000000002.wikidsystems.net is an alias for wikid.twoitguys.com. | 15:38 |
nowen | wikid.twoitguys.com is an alias for mh13.dyndns.org. | 15:38 |
nowen | mh13.dyndns.org has address 66.57.170.142 | 15:38 |
Gibby13 | that should work | 15:39 |
Gibby13 | can i put anything in for the sign-out and change password url? | 15:48 |
Gibby13 | for GSSO? | 15:48 |
nowen | I just used the same as the sign in, iirc | 15:49 |
Gibby13 | uhoh | 15:51 |
Gibby13 | are the images broken on wikidsystems.com? | 15:54 |
nowen | could be - what page? | 15:55 |
nowen | also - hit shift-r to make sure it's not the cached version | 15:56 |
Gibby13 | http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/installing-the-wikid-strong-authentication-server-enterprise-edition-page-5 | 15:56 |
nowen | hit ctrl-shift-R and let me know if they pop up | 15:57 |
Gibby13 | that works for google chrome on linux? | 15:58 |
Gibby13 | ahh yep it is up | 15:58 |
nowen | yes, works for me | 15:58 |
Gibby13 | ty | 15:58 |
nowen | we updated the website and implemented some very aggressive caching. our google page speed went from 50 to 90 | 15:58 |
Gibby13 | awesome | 15:58 |
Gibby13 | broken link in that page | 15:58 |
nowen | but it's a hassle for doing edits | 15:59 |
Gibby13 | under figure 22, the link to WiKID software token | 15:59 |
nowen | thx | 16:03 |
Gibby13 | in the clients, getting unable to resolve server code | 16:12 |
*** CowboyPride has quit (Remote host closed the connection) | 16:22 | |
Gibby13 | is there a way i can test the server code you gave me? | 16:34 |
nowen | have you set it up on your server? | 16:38 |
Gibby13 | yes, what ports do i have to forward? | 16:40 |
Gibby13 | already doing 80 and 443 | 16:41 |
nowen | just 80 for the tokens | 16:41 |
Gibby13 | what gets pass over 80? does it put in the domain name or just the IP? | 17:15 |
nowen | all the token traffic goes over port 80. | 17:17 |
Gibby13 | yeah, but what does it look like... is it normal http requests? | 17:18 |
*** Will (601394ce@gateway/web/freenode/ip.96.19.148.206) has joined #wikid | 17:19 | |
Gibby13 | i need to figure out the header so i can put it in for my apache proxy pass | 17:19 |
nowen | ahh - everything will go to /wikid/ | 17:19 |
Gibby13 | ok... my proxypass server is not the same as the wikid server... just need to figure out the rewrite rule for that i guess | 17:21 |
nowen | yeah, I have a re-write rule for the same server, but not a proxy pass | 17:25 |
nowen | RewriteRule ^/wikid/(.*) http://localhost:8090/wikid/$1 [P] | 17:25 |
nowen | is that helps | 17:25 |
Gibby13 | why port 8090? | 17:27 |
nowen | that is for our demo wikid server - we are running on the same box as the webserver - which we do not recommend for a production server | 17:27 |
Will | silly question, just converted to fedora from the clutches of windows. I have d/l he client but not sure on how to do the install, anyone wanna do a quick walk thru | 17:28 |
nowen | you wouldn't want a web vuln resulting in someone owning your wikid server | 17:28 |
nowen | Will: you can try the install.jar | 17:28 |
Gibby13 | makes sense | 17:28 |
Will | k, | 17:29 |
Gibby13 | hmmm doesn't seem to be catching the rewrite rule | 17:29 |
nowen | Will: it should create menu items, etc | 17:29 |
nowen | Will: let me know if you see version 3.1.15 or 3.1.17 on the download page | 17:30 |
nowen | this page: http://www.wikidsystems.com/downloads/token-clients | 17:31 |
Will | 3.1.15 | 17:36 |
Gibby13 | did you put your rewrite in the .conf or a .htaccess file? | 17:36 |
nowen | it is in a .conf | 17:37 |
nowen | Will: hit ctrl-shift-R | 17:37 |
*** Will has quit (Quit: Page closed) | 17:38 | |
Gibby13 | hmmm ok, the rewrite rule is working but still no go | 17:49 |
Gibby13 | erk... maybe not | 17:51 |
Gibby13 | so i think i got it working, it goes see this in the logs now. POST /wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&CT=0&S=000000000002&lck=0 HTTP/1.1" 200 1 "-" "WiKID Android Token/3.0" | 18:01 |
Gibby13 | however, still get unable to add domain: unable to resolve server code on the client | 18:01 |
nowen | I recommend you run the j2se token in debug mode and see what is going on | 18:06 |
Gibby13 | how do i enable debug? | 18:08 |
Gibby13 | Could not connect to servercode: 000000000002 | 18:09 |
Gibby13 | And | 18:09 |
Gibby13 | Could not obtain configuration for: 000000000002 | 18:10 |
Gibby13 | if i run it on the local network it works fine | 18:10 |
Gibby13 | disregard those last 2 errors | 18:11 |
nowen | http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-run-the-token-in-debug-mode?searchterm=token+debug | 18:15 |
nowen | pretty handy | 18:15 |
nowen | something with the proxypass, I would assume - I'm guessing apache isn't sending the packets back to the token | 18:18 |
nowen | do you have a ProxyPassReverse line? | 18:20 |
Gibby13 | got it working | 18:22 |
nowen | what was it? | 18:22 |
Gibby13 | not sure, android client still not working | 18:23 |
Gibby13 | seeing this is the socks proxy logs at work | 18:23 |
Gibby13 | http://0.0.0.2/wikid/servlet/com.wikidsystems.server.WikidCode5AES?S=000000000002&D=8665944558249088114&withTTL=1&CT=1, service-http reports: CORE7740: unable to contact 0.0.0.2:80 (IO timeout error) | 18:23 |
nowen | the token will try both the IP and the dns | 18:24 |
Gibby13 | ProxyPass /wikid/ http://192.168.1.19/wikid/ | 18:25 |
Gibby13 | ProxyPassReverse /wikid/ http://192.168.1.19/wikid/ | 18:25 |
Gibby13 | those are my proxy lines | 18:25 |
Gibby13 | Google Apps - This account cannot be accessed because we could not parse the login request. | 18:26 |
Gibby13 | got that trying to login | 18:26 |
Gibby13 | well after i login | 18:26 |
nowen | anything in the WiKIDAdmin logs? | 18:27 |
Gibby13 | what source? | 18:28 |
nowen | none | 18:28 |
nowen | set the log level to debug | 18:29 |
nowen | could very well be no error, since I bet it is something google doesn't like | 18:29 |
nowen | good luck checking google's logs though | 18:29 |
Gibby13 | nothing in the logs | 18:30 |
Gibby13 | but i am able to bypass wikid and still get in to my google apps | 18:31 |
nowen | you should keep a browser window open so you can turn off sso if need be. | 18:32 |
Gibby13 | if i go to https://www.google.com/a/twoitguys.com i can login and bypass wikid..... | 18:32 |
nowen | did you upload the p12 as a verification cert? | 18:32 |
Gibby13 | yep | 18:32 |
nowen | so where do you go to login with wikid? | 18:33 |
Gibby13 | mail.twoitguys.com | 18:33 |
Gibby13 | that redirects to my wikid | 18:33 |
nowen | yeah, I don't think that will work - if the request is coming from mail.twoitguys and then going to google | 18:34 |
*** perestre1ka has quit (Read error: Connection reset by peer) | 18:34 | |
Gibby13 | how do you do it? | 18:35 |
nowen | you should get redirected to wikid from https://www.google.com/a/twoitguys.com | 18:35 |
nowen | or just https://www.google.com/a | 18:35 |
Gibby13 | it doesn't | 18:36 |
Gibby13 | Use a domain specific issuer | 18:36 |
nowen | try that last link | 18:36 |
Gibby13 | should i check that? | 18:37 |
nowen | https://www.google.com/a and then type in your domain | 18:37 |
nowen | still looks like something is wrong tho | 18:37 |
Gibby13 | same error | 18:39 |
Gibby13 | https://www.google.com/a/twoitguys.com/acs | 18:39 |
Gibby13 | that is the url | 18:39 |
nowen | is the user being authentication? | 18:39 |
Gibby13 | in wikid? | 18:40 |
nowen | authenticated, that is | 18:40 |
nowen | yes | 18:40 |
Gibby13 | yep | 18:40 |
Gibby13 | wait, how do you tie a user in wikid to a google apps user? | 18:40 |
*** perestrelka (~vladdy@194.242.5.47) has joined #wikid | 18:41 | |
nowen | you use the same username | 18:41 |
Gibby13 | ugh, i have like 6 accounts just for me | 18:42 |
Gibby13 | looks like i have to remove the /acs part | 18:44 |
Gibby13 | ahh wait read that wrong at google | 18:44 |
Gibby13 | looks like if you are a google app admin, you can bypass wikid | 18:44 |
Gibby13 | if needed | 18:44 |
nowen | how do you do that? just by adding the /acs? | 18:45 |
Gibby13 | With SSO implemented, domain end users will not be able to log in to Google directly. However, domain admins can still log in to the Google control panel (e.g http://www.google.com/a/yourdomain.com). | 18:45 |
*** nowen has parted #wikid (None) | 18:50 | |
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid | 18:50 | |
Gibby13 | got it working :) | 18:50 |
Gibby13 | didn't put in https when i configured google sso on the wikid server | 18:51 |
Gibby13 | no to figure out the android client issue | 18:51 |
nowen | nice | 18:51 |
Gibby13 | does the client on android keep logs? | 18:51 |
nowen | fraid not | 18:52 |
nowen | what is happening? | 18:52 |
nowen | I wonder if the dns hasn't propagated yes | 18:53 |
nowen | yet | 18:53 |
Gibby13 | hmm, now the android clients error is, unable to add domina: null | 18:53 |
nowen | can you add this domain: 888888888888? | 18:54 |
Gibby13 | aakkkkk | 18:54 |
Gibby13 | rm the wrong directory | 18:54 |
Gibby13 | :( | 18:54 |
Gibby13 | have to restore server now | 18:58 |
Gibby13 | will try later | 18:58 |
nowen | ugh | 19:01 |
*** fifa (18d5aaa2@gateway/web/freenode/ip.24.213.170.162) has joined #wikid | 19:13 | |
fifa | hello room | 19:13 |
fifa | i am new to this | 19:14 |
fifa | i need instructions on how to compile from source code | 19:14 |
nowen | fifa: it is java | 19:15 |
fifa | i figured | 19:15 |
fifa | so how do i get it installed ?? | 19:16 |
nowen | what os? and what version of wikid? | 19:17 |
nowen | we have both rpms and debs | 19:22 |
Gibby13 | sweet, extundelete works | 19:28 |
Gibby13 | ok, now back to the android client issue | 19:33 |
Gibby13 | 888888888888 works | 19:42 |
Gibby13 | they are showing up as unregistered devices | 19:45 |
Gibby13 | no results for domain key lookup! | 19:46 |
Gibby13 | that is in the wikidadmin logs | 19:46 |
nowen | they should not show up as unregistered unless the PIN gets set | 19:59 |
nowen | the 8888 domain is our demo domain. it just shows that it is something particular to your server | 19:59 |
nowen | are you on wifi or cell? | 19:59 |
Gibby13 | cell | 20:00 |
Gibby13 | when i run the java client remotely it is very laggy... if i run it locally it is very fast... so i would say it is probably something in my proxy pass | 20:01 |
Gibby13 | but still if java work remotely why doesn't android | 20:01 |
nowen | dunno. | 20:02 |
Gibby13 | here what happens in apache logs when i try the android client, http://pastebin.com/MPZciXMt | 20:02 |
Gibby13 | and 3 errors show up in the wikidadmin logs | 20:03 |
Gibby13 | no results for domain key lookup! | 20:03 |
Gibby13 | wkeyfactory is null!! | 20:03 |
Gibby13 | Exception while sending domain configuration | 20:03 |
Gibby13 | here is a trace of the last error http://pastebin.com/DNGfALMc | 20:04 |
nowen | this is the Enterprise version, correct? | 20:08 |
Gibby13 | nope | 20:08 |
nowen | http://www.wikidsystems.com/community-version/front-page/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release/?searchterm=what%20is%20the%20difference | 20:09 |
Gibby13 | i didn't think android was j2me..... | 20:11 |
nowen | lol. that page references our Palm version too | 20:13 |
nowen | maybe time for an update | 20:13 |
Gibby13 | yeah... so the android client is only for enterprise then? | 20:13 |
nowen | yes - all the wireless/smart phone tokens use the Ntru encryption libs | 20:13 |
Gibby13 | ah ok | 20:14 |
Gibby13 | so i can setup a page to use the html5 token tho right? | 20:14 |
nowen | yes | 20:14 |
Gibby13 | is there a howto for that one? | 20:17 |
nowen | http://www.howtoforge.com/installing-the-wikid-html5-token-client | 20:18 |
fifa | i am using arch linux | 20:19 |
Gibby13 | tomcat? | 20:19 |
fifa | and i need to use it for arch linux | 20:19 |
fifa | rpm and deb is not supported by arch linux | 20:20 |
fifa | my only option is to compile/install | 20:20 |
fifa | are there any docs out there to help me with this ???? | 20:20 |
nowen | fifa: sorry | 20:22 |
fifa | so my only option is RH/CentOS or Deb | 20:24 |
nowen | people have gotten it running on other flavors | 20:24 |
nowen | like slackware | 20:24 |
fifa | any docs on slackware ?? | 20:25 |
nowen | http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-install-the-wikid-enterprise-on-slackware | 20:26 |
Gibby13 | nowen, i can hit the tomcat server and the HTML5Token webapp... but it is not showing anything the html file | 21:03 |
nowen | what browser? | 21:05 |
Gibby13 | chrome | 21:06 |
Gibby13 | src="/HTML5Token/HTML5Token/HTML5Token.nocache.js" | 21:07 |
Gibby13 | do i need to change that to an absolute path? | 21:07 |
*** sakhi_ has quit (Ping timeout: 252 seconds) | 21:09 | |
*** sakhi (~sakhi@uwcfw.uwc.ac.za) has joined #wikid | 21:10 | |
Gibby13 | got it working, did the generate token, now getting a Communication with server failed | 21:16 |
Gibby13 | you can see the error if you go token.twoitguys.com | 21:19 |
nowen | I'm guessing it is the comms between your token server and the wikid server | 21:21 |
Gibby13 | almost the same error on the test one here | 21:25 |
Gibby13 | http://www.wikidsystems.com/downloads/html5-token | 21:25 |
Gibby13 | do i have to add it as a client? | 21:28 |
nowen | Gibby13: no, you shouldn't | 21:34 |
Gibby13 | nowen, hmmmm | 21:34 |
nowen | i see that error now | 21:36 |
nowen | must be my rewrite | 21:36 |
Gibby13 | how do i regenerate the token for html5? | 21:39 |
nowen | i just start a new incognito window. I think you can also clear your cache | 21:40 |
Gibby13 | ooo so each client generates its own key....hmmmm | 21:41 |
nowen | anything in your tomcat logs? | 21:41 |
Gibby13 | nope | 21:42 |
nowen | b/c I see java.io.IOException in catalina.out | 21:43 |
Gibby13 | cleared cache and redid it, have some stuff now | 21:44 |
Gibby13 | http://pastebin.com/hV96fNNK | 21:46 |
Gibby13 | http://code.google.com/webtoolkit/doc/latest/tutorial/RPC.html#serialize | 21:47 |
Gibby13 | where is com.wikidsystems.html5token.client.dto.ConfigurationDTO set at? | 21:57 |
Gibby13 | don't see anything in the forums about HTML5 yet.. :( | 22:09 |
nowen | either the js in the browser can't get to the tomcat server or the tomcat server can't get to the WiKID server | 22:24 |
Gibby13 | ewww... a users can have multi registered locations? | 22:28 |
*** Gibby13 has parted #wikid ("Leaving") | 22:36 | |
nowen | I guess Gibby13 doesn't understand how public keys work | 22:48 |
*** nowen has quit (Quit: Leaving.) | 23:09 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!