Tuesday, 2011-12-13

*** Flexyz (3e74c0c6@gateway/web/freenode/ip.62.116.192.198) has joined #wikid09:49
*** Flexyz has quit (Ping timeout: 258 seconds)10:14
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:15
*** XaaS (ad498917@gateway/web/freenode/ip.173.73.137.23) has joined #wikid13:38
XaaS@nowen - couple of questions for you... 1) do you have a license for home users (5 or so license) - something I can set a lab up at home with? 2) can the tokens use something other than port 80 if your ISP blocks it?13:40
nowenXaaS: yes, on our buy online page you will see a home license option13:41
nowenthe tokens cannot use anything other than port 80, so if your ISP won't allow you to host a server on 80, you are out of luck13:41
nowendo you have comcast?13:41
XaaSVerizon FiOS13:42
XaaSVerizon blocks Port 80 on all residential services - either FiOS or DSL13:42
nowenthe java token can be configured to use a proxy13:44
nowenmaybe that would help?13:44
XaaSI don't think its my browser - your Purchase On-line page doesn't seem to go anywhere13:44
XaaSyes - that could work13:44
nowentrying to think about that.  you setup a proxy on your home network and connect to it remotely?13:44
XaaSThe only way it could work is to have proxying going on both the client and the server to redirect traffic - or a VPN tunnel13:49
XaaSbut most probably the phone tokens won't work13:49
nowennope13:50
XaaSmaybe something to think about for future development13:50
*** XaaS has quit (Quit: Page closed)13:54
*** FlexyZ (3e74c0c6@gateway/web/freenode/ip.62.116.192.198) has joined #wikid15:17
nowenFlexyZ: how's it going?15:37
FlexyZwell I am strugeling a little :(15:59
FlexyZsome times it works and some times it dont :( - from a palo alto firewall15:59
FlexyZI am getting crazy :)16:00
FlexyZbtw. your frontpage links where bad today - but is fixed now16:00
nowenyeah - my bad, borked the cms16:00
nowenwhat do you see in the WiKIDAdmin logs when it fails?16:01
FlexyZnothing :( -I can see I got a OTP on my token, but login page on palo alto just states invalid user16:02
FlexyZso maybe not related to wikid16:02
FlexyZbut wierd16:02
nowenhmm - if the last thing you see is the OTP, then WiKID isn't getting the radius request16:02
nowencould it be coming from more than one ip?16:03
FlexyZyes maybe - can I see somewhere if something is denied16:03
FlexyZon the wikid server16:03
nowenyou can also run tcpdump on the radius port16:03
FlexyZwhat is the params16:04
FlexyZif have them around :)16:04
nowentcpdump -p radius16:04
nowenshould do it16:04
nowennope16:04
nowen tcpdump port 181216:05
nowenor tcpdump port radius16:06
FlexyZof course it worked now - but cool, will watch the dump16:07
nowenlol16:07
FlexyZthx16:10
FlexyZif i restarted the wikied - i see the radius requets, but not login16:12
FlexyZlooks like 3-4 retried in the tcpdump16:14
FlexyZbut no login16:14
FlexyZwhat does this mean16:16
FlexyZA C3P0Registry mbean is already registered. This probably means that an application using c3p0 was undeployed, but not all PooledDataSources were closed prior to undeployment. This may lead to resource leaks over time. Please take care to close all PooledDataSources.16:16
FlexyZdamn have to leave now - what could it be?16:17
nowenI'll have to check16:17
FlexyZthx16:19
nowenok - so you see the radius requests from the palo alto but you don't see an accept or reject?16:28
FlexyZwhen I submit login, I can see 3-4 radius requets in the tcpdump - but PA return invalid login16:30
FlexyZand it seems to happend after a wikidctl restart16:31
FlexyZthen if I wait 2-3 minutes it seems start working16:31
nowenwhat do you see in the WiKIDAdmin logs?  when the PA rejects?16:34
FlexyZtried 4 times now and no problems - let me try and restart again - is there any special requirements for the vm? 1gb mem, one cpu16:35
nowenthat should be plenty16:35
FlexyZwarn logs?16:36
nowenif you set the level to Debug and hit Filter, you should see more16:37
FlexyZnot much16:38
FlexyZtrace com.mchange.v2.resourcepool.BasicResourcePool@191e4c [managed: 3, unused: 2, excluded: 0] (e.g. com.mchange.v2.c3p0.impl.NewPooledConnection@12549c4)16:38
nowendid you set the radius logger to debug? http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests16:39
FlexyZlooks like maybe the radius is slow to start16:39
FlexyZRADIUS Receiver Started: listening on port 181216:39
FlexyZlong after restart16:39
FlexyZin debug16:39
FlexyZlog16:39
FlexyZand now login works16:40
FlexyZbut it takes a while :(16:40
nowenok - that is the radius server.  it needs random info to start.16:40
FlexyZ?16:41
nowenhowever, you can make it start faster by running 'rngd -r /dev/urandom'16:41
nowenhat tip to asofrank16:42
FlexyZoki so this is normal?16:42
nowenyes - there is not a lot of entropy on a headless system16:42
nowenbut this only happens on restart - in production you will not be restarting much16:42
FlexyZ:( been fighting this a long time - no but is testing stuff now, so lots of restart etc16:43
nowensorry16:43
FlexyZnp - now I know :)16:43
FlexyZseems to work now - time on client and wikid server should be the same right16:44
nowenyes16:44
FlexyZgood16:44
FlexyZrngd -r /dev/urandom seems to kickstart it faster :) thx!16:51
nowenwe'll be backing that in soon16:51
FlexyZc.u17:00
nowenlater!17:00
*** FlexyZ has quit (Ping timeout: 258 seconds)17:05
*** Pirkka (54f8812f@gateway/web/freenode/ip.84.248.129.47) has joined #wikid19:10
PirkkaHi. Is there available token client for Windows Phone 7.5 (Nokia Lumia 800) ?19:11
nowenalmost - still trying to get through the cert process19:12
PirkkaSo, somebody is working and it's expected to come out "soon"?19:17
nowenyeah. MS only rejects you for one thing at a time19:17
nowenso it takes a while19:18
PirkkaOk. Thanks. I can survive with my old phone for a moment (Nokia X6).19:20
nowenwhich token are you using?19:20
PirkkaJME client running on Symbian phone.19:20
PirkkaBut I just got a new Windows Phone and I don't think the java client runs on it.19:21
nowenprobably not19:21
*** Pirkka has parted #wikid (None)19:26
*** FlexyZ (5551950e@gateway/web/freenode/ip.85.81.149.14) has joined #wikid21:32
FlexyZnowen, how do I assign multiple token to the same user in same domain21:35
FlexyZUserID xxxxx is already registered in this domain21:35
nowenFlexyZ: you need to use the example.jsp page or some other network client-based app21:35
FlexyZoki how do I enable the example.jsp - need to do something right21:37
nowenthis is the best doc for that: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly21:38
nowenit's pretty basic - just change "passprhase" and the default domain21:38
*** mo (d8390e7c@gateway/web/freenode/ip.216.57.14.124) has joined #wikid21:49
*** mo is now known as Guest3156521:49
Guest31565hi21:50
Guest31565quick question21:50
nowenok21:50
Guest31565on a shared pc how do you distinguish the users21:51
Guest31565that is can you set this up on a shared pc21:51
nowenAre the users sharing a login? or just a PC with multiple accounts?21:51
Guest31565sharing a login21:52
nowenhmm.  then what the point of distinguishing the user?21:52
Guest31565you are right21:53
nowenlo21:53
nowenl21:53
nowenif you own the box, you  can own the network21:53
nowenif the users login separately, then whatever mechanism secures their space, secures the WiKID token21:54
nowenyou can run more than one wikid token on a machine21:54
nowenyou can't use the installer21:54
nowenfor boty21:54
nowenboth21:54
nowenFlexyZ: I assume you don't need help editing the example.jsp page, but if you do. let me know21:55
FlexyZno but not sure what pass to use where :)21:56
nowenhehe - use the localhost.p12 passphrase21:57
FlexyZClient PKCS12 Passphrase21:57
FlexyZin admin right21:57
nowennot necessarily21:57
nowenyou can use keytool on the localhost p12 to check it21:58
FlexyZhow :)21:58
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid21:58
nowenby searching the site, my friend!  :)21:58
FlexyZseem to have pass right on both22:02
FlexyZbut still no go22:03
FlexyZdomain also changed22:03
Guest31565thanks22:03
nowenGuest31565: welcome22:04
nowenFlexyZ: try giving wikid a restart22:04
nowenthe old one may be cached22:04
Guest31565can you help with this22:05
Guest31565a user is getting url changed22:06
Guest31565did it change on the server itself22:06
nowenthe URL changed message is from when their a Registered URL in the domain settings.  did you set one up?22:06
Guest31565yes22:07
Guest31565has been tested and working22:07
nowenok - in that case it could be an MiTM attack22:07
nowenis it just that user?22:07
FlexyZrestart did it22:08
Guest31565nope all users to that domain22:08
nowenok - what is the URL?22:08
Guest31565gts2.globetax.com22:08
nowenit should be https://22:09
Guest31565yes22:10
nowenoh - it is? or it will be?22:10
Guest31565it is22:11
nowenwhat's the domain id?22:11
Guest31565i know its public22:12
Guest31565but i still feel uncomfortable putting this in a chat22:12
nowenhave one of your users kill and restart their token and see if that works22:12
nowenhehe22:12
nowenI'm usre22:12
nowensure22:12
FlexyZ:)22:12
nowenSo you changed the URL in the domain and restarted WiKID?22:16
Guest31565hi22:24
nowenGuest31565: any luck?22:24
Guest31565still trying22:25
nowendid you restart the token?22:26
Guest31565yes22:26
nowenstill no go?22:27
nowenhow many users have you rolled this out to?22:27
Guest31565422:27
Guest31565so far22:27
Guest31565i was hoping to roll out to most this week22:27
nowenwhy did you change the URL?22:27
Guest31565same client works for two ohter domain22:27
Guest31565i did not change anything22:27
nowenoh, I thought you said you did.22:28
Guest31565url would be the last thing i change22:28
Guest31565nope that was the error22:28
nowendid the site's SSL cert change?22:29
Guest31565nope22:29
Guest31565i changed the domain registered url on wikid server22:29
Guest31565saved; then changed it back22:30
nowenyeah - that is what I meant when I asked why you changed the URL22:30
Guest31565it seems to be working now22:30
Guest31565yes22:30
Guest31565that is why i did it22:30
Guest31565but why do i have to do this22:30
Guest31565if this was the only wikid sever then i would not be able to login at all22:31
nowenwhy did you change it in the first place?22:31
Guest31565without some sort of backdoor22:31
Guest31565i never changed anything22:31
Guest31565it just stopped working22:31
nowen"05:29:50 PM) Guest31565: i changed the domain registered url on wikid server"22:31
Guest31565yes as per your suggestion; then i changed it back22:32
Guest31565so then it started working22:32
Guest31565thanks though22:33
Guest31565hopefully its more stable with future updates ;-)22:33
nowenI'm not sure what happened.  it  could have been an attack or who knows22:33
nowendid you see anything in the WiKIDAdmin logs>22:34
nowen?22:34
Guest31565no22:34
Guest31565 i will double check tomorrow22:34
Guest31565i have to go now22:34
Guest31565thanks again22:34
nowennp22:34
FlexyZnowen what is the best way to auto start wikid if server is rebooted - I have the pass in tje security file22:46
nowenthere's a script in /opt/WiKID/conf/templates22:46
nowenyou can drop it into /etc/init.d22:47
FlexyZcool22:47
*** FlexyZ has quit (Ping timeout: 258 seconds)23:10
*** nowen has quit (Quit: Leaving.)23:31

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!