Thursday, 2011-12-08

*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:17
*** pam_ (50046092@gateway/web/freenode/ip.80.4.96.146) has joined #wikid14:26
nowengood morning :)14:27
pam_Hi could someone inform me of the default admin password for apacheDS used by Wikid?17:20
nowenI'll have to check with someone17:22
pam_Thank You17:22
nowenwhat's the context?17:23
pam_Oh Im playing around with Apache Directory Studio and was trying to connect as uid=admin,ou=system.17:26
nowendid you try the default?  I feel like there is a warning if you don't change it17:27
pam_Dont know what the default password is.17:28
nowenI think it is "secret"17:28
pam_It must have been changed...17:29
nowentry 'changeme'17:30
pam_changeme did not work either getting the ldap 49 error.17:32
nowenhow about "wikidone"17:32
* nowen hates ldap17:32
pam_Nope same error. Nowen I'm with you on that! BTW can wikid use an external ldap such as 389DS rather than the internal default apacheds?17:34
nowenpam_: we use a portion of apacheds to be able to talk ldap.17:35
nowenso, the idea is that you would use an external ldap server and it would proxy the auth to WiKID17:36
nowentry "2Factor"17:36
*** pam_ has quit (Ping timeout: 265 seconds)17:38
*** pam_ (50046092@gateway/web/freenode/ip.80.4.96.146) has joined #wikid17:40
pam_Mmm not sure if you got my last message nowen as the irc client appeared to lock.17:40
nowen try "2Factor"17:48
pam_No 2factor didnt work either. Nowen not to worry it was only to play with, but thanks for your help!17:50
nowenok, sorry17:51
pam_No problem Nowen :-)17:52
pam_Oh would it be the password that was used on the ldap configuration page which asks "LDAP_wauth_pass Passphrase for the Network Client cert above"17:54
nowenhmm. possibly, but I don't think so, that should be the localhost passphrase.   no harm in trying17:54
pam_Nope.. no good... Oh well, Thanks again for your help Nowen!17:56
pam_Bye17:57
nowenbye17:57
*** pam_ has quit (Quit: Page closed)17:57
*** pam_ (50046092@gateway/web/freenode/ip.80.4.96.146) has joined #wikid21:30
pam_nowen: We were speaking earlier about apachds admin password. The password I think I need is for Directory Manager would you happen to know what it is set too?21:32
nowenno, 'fraid not21:33
nowentypically, we only support anonymous binds21:33
nowenis it one of the three I mentioned? I assume not21:34
pam_Ok NP thanks anyway nowen! (secret, changeit and 2Factor did not work)21:35
nowenwhat about wikidone?21:35
pam_nope not that either... oh well.21:36
nowenyou probably need to set it somehow21:36
pam_I think your right. Being google'in but haven't found any info as yet. I'll keep on searching.21:37
pam_nowen: I'm in. For your reference the password is 2Factor after all. I decided to try to logon vi /opt/WiKID/directory/bin/control-panel and it connected. Thanks for your assistance.21:43
nowennice!21:43
*** Flexyz (5551950e@gateway/web/freenode/ip.85.81.149.14) has joined #wikid23:09
FlexyzHi23:09
nowenhi23:09
FlexyzHave a quick one - which interface is for the external?23:10
nowenwell, you just want one interface for port 80 for the tokens, the internal traffic should have the 443 WiKIDAdmin web ui, radius, etc23:11
FlexyzOki so I should stop admin access by my firewall - and only allow 80 from outside23:13
nowenyes, that's the best23:14
nowenthe tokens use public key encryption, so no need for ssl there23:14
Flexyzoki - and when my token create the domain is has to be the external ip zero'ed or can I use xxxx.yyyy.zz dns23:15
nowenyou have to use your IP.  You can use your own dns for the PC tokens, if you create a custom jw.properties file23:16
nowenthe smart phone tokens use IPs or an entry in wikidsystems.net dns, which  we can create for you23:16
Flexyzoki so a customer can get a number ? how many digits23:18
nowen12 digits23:19
nowenwe have a demo domain:  8888888888823:19
nowenit resolves to 8888888888.wikidsystems.net23:19
Flexyzoki - just currious why dont the token accets23:19
Flexyzsorry23:19
Flexyzaccepts a fqdn23:20
nowenwell, when we started, we didn't have PC tokens and their weren't smart phones with keyboards. :)23:20
nowenit was all java cell phones23:20
nowenwe're working on a new product that will use fqdns23:21
Flexyzok so be easy right - only the tokens should support it - just much easier to rember and type a fqdn (know it is only first time though)23:22
nowenyes, I agree23:22
Flexyzanother thing the second "interface" when setup what is that for - on a box with only one eth23:23
nowenare you using the ISO or the vmware image?23:23
Flexyziso23:23
Flexyzon virtualbox23:24
nowenI think it just assumes you have two23:24
Flexyzhmm - also on the demos w823:24
nowensorry?23:25
Flexyzsit0123:25
nowenjust select N when prompted to configure it23:26
nowenI think it is a virtualbox thing23:26
Flexyzbut what is it?23:26
Flexyzok23:26
Flexyzdemo is showing eth0 and eth1 - when the box has two is eth1 for external ip?23:27
nowenthat is up to you23:27
Flexyzbut that is the case then?23:28
nowenyou can assign any IP you want to to any eth23:28
Flexyzbut will admin site listen to all interfaces?23:28
nowenahh - the assumption  is that you will control that at your firewall - that the server will be in the dmz23:29
nowenso, yes, it will23:29
Flexyzok so no real use for it then - the internal firewall what is that used for? only network clients or23:30
nowenyes - network clients23:30
Flexyzoki would make sense if two interfaces are configured one of then could be for tokens only - so eth0 lan/dmz eth1 ext and ONLY for tokens23:32
Flexyzjust a though23:32
nowenyes, depending on your setup23:32
Flexyzbut that is not the case right - I have to control it by my firewall right23:33
nowenyes, or we can tell you how to do it in tomcat, but your firewall is the best place for it23:33
Flexyzbut is it also firewalled internally between eth0 and eth1?23:35
nowenno23:36
Flexyzoki, sorry for all the stupid quesions, just dont feel to happy to let the whole internet get direct access to the same interface with the admin site - I know only port 80 should be opened - but still23:38
nowendo you have a firewall in front of the WiKID server?23:38
Flexyzwell there is no option :) so sure23:38
nowendefense in depth...23:39
nowenyou can lock ports to specific IPs in tomcat23:41
Flexyzis the token request straight http?23:41
nowenyes23:41
Flexyzso if it proxyed it will still work23:41
nowenthe tokens use public key encryption, so no need for ssl there23:41
nowenyes23:41
Flexyzok23:41
nowenyou can put apache or something and proxy it23:41
nowenall token requests will go to /wikid/23:42
Flexyzalright23:42
nowenI'm about to head home - got any more questions?23:47
Flexyzno thx23:49
nowenok  - I will be back tomorrow. If you post something to the forums, we can respond there any time (mostly)23:50
nowenbye!23:50
*** nowen has quit (Quit: Leaving.)23:50
*** Flexyz has quit (Quit: Page closed)23:52

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!