Friday, 2012-01-13

*** mos`work (~swagimusm@38.122.21.70) has joined #wikid01:05
*** mos`work is now known as mos`01:05
mos`hello - anyone available to help?01:06
*** mos` has quit (Client Quit)01:07
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:16
*** gvidals (18f9cf04@gateway/web/freenode/ip.24.249.207.4) has joined #wikid15:44
gvidalsowne, my wikid instance 3.3.1 isn't saving my data. everything works the first time around, but when I try to use it again, the data is gone.15:46
gvidalsgalaxy nexus (google phone) ice cream sandwhich 4.0.2.  so i have to re-create each time i use it.15:47
nowenwhat version of the token?15:47
gvidalsmy android is running 3.3.115:51
gvidalsi just tried it again and confirmed the issue. setup domain, pass code, authorized user from wikid web interface, all good.15:52
gvidalsthen when i go back to use the token again, the domain is gone.15:52
gvidalsit doesn't seem to be saving it.15:52
nowenthere is a 3.4 available15:53
gvidalsyour QR code points to 3.1.1, so i downloaded it by clicking on the link16:04
nowenugh16:04
nowenI thought it would point to the latest16:05
gvidalsinstalled and now i'm on 3.4, but same issue. when i kill the program and restart it, the domain is gone.16:05
nowenok -16:05
nowenstart the program and add the domain16:05
nowenthen use the hardware back key to close out all the windows to exit16:05
prowlahfyi - i have the same phone, nexus with ics 4.0.2 running 3.1.1 and have not seen this issue..16:06
gvidalsthat seemed to do the trick! i'm rebooting the phone now and will try again.16:07
nowenok16:08
gvidalspaid my invoice by the way.16:08
nowenthanks!  via check?16:08
nowendidn't see the checkout email16:09
gvidalsyea, at end of year we use checks to back date to 12/31 for tax advantage.16:09
nowenlol16:09
gvidalsyup. it worked. for some reason the set up seems to require a back key. don't recall that being the case with gingerbreak.16:09
gvidalsanyway. thanks16:09
gvidalsi like the galaxy nexus, but one major flaw. L2TP VPN doesn't work :-( I confirmed this with other engineers... hopefully they will fix soon.16:13
*** gvidals has quit (Ping timeout: 258 seconds)16:45
*** Mo (d8390e7c@gateway/web/freenode/ip.216.57.14.124) has joined #wikid17:48
Mohello17:48
MoNick17:48
nowenhey Mo17:48
*** Mo is now known as Guest4427217:48
nowenwhat's up17:49
Guest44272i just upgraded my cag and everthing blew up17:51
Guest44272so i had put all the pieces back together17:51
nowendefine "blew up"17:51
Guest44272all works except wikid17:51
Guest44272i'm looking at the log file17:52
Guest44272and it shows access denied17:52
nowendoes it say why?17:52
Guest44272using wikid server as radius17:52
Guest44272i lost the type in field17:53
Guest44272got it back17:54
Guest44272any way17:54
Guest44272any ideas as to why17:54
Guest44272i'm thinking the radius password might be an issue17:54
nowendoes it say why access was denied?17:54
nowencould be17:54
Guest44272i reset it on both ends17:54
nowenand then did you restart WiKID?17:54
Guest44272nope17:55
Guest44272should i restart17:55
nowenyes17:55
noweneverything in radius is cachced17:55
nowencached17:55
nowenjust run 'wikidctl restart'17:55
Guest44272do i have to restart my17:56
Guest44272DC as well17:56
nowenwhat is a DC?17:56
nowendomain controller?17:56
Guest44272Domain Controller - hosting the radius17:56
nowenthat's a question for Microsoft, but I don't think so17:57
Guest44272rebooted17:57
Guest44272will try now17:57
nowenyou don't need to reboot!  just run 'wikidctl restart'17:58
Guest44272yes that is what i did17:58
nowenlol17:58
Guest44272no good17:59
Guest44272still authentication failed17:59
nowenwhat is the error?17:59
nowendid the ip address change any where?18:00
nowenset your logs to debug: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests  and try again18:00
Guest44272access denied for "userid", domain code: blah client: /my cag18:00
nowenwhat changed?18:01
Guest44272<0> access request(1)LEN=6218:01
nowenpost your logs to pastebin.org, please18:01
Guest44272CAG IP:31999 Access-request by "userid" failed: accessrejectException: Access Denied18:01
nowenyou will need to run the logs in debug to see the reason18:03
Guest44272i have setup in debug18:03
Guest44272which one should i put in debut18:03
Guest44272i set 3 of them18:03
nowenthe three loggers should be set in debug18:04
Guest44272i'm seeing these:18:06
Guest44272Check PAP bombed with AccessRejectException: Access Denied18:07
Guest44272Passcode is not a number.18:07
Guest44272passcode is ?218:07
Guest44272<0> Access-Request(1) LEN=62 ip:35771 Access-Request by user Failed: AccessRejectException: Access Denied18:08
nowensound like a bad shared secret18:08
Guest44272yup that was my guess; hence, i reset them18:09
Guest44272will try again18:09
Guest44272do i have to restart wikidctl18:09
nowenif you change the shared secret or anything in the Network client for a radius client, you have to restart wikid18:10
nowenso, you upgraded you CAG.  Did it change setting when you did that?18:18
Guest44272everything18:19
Guest44272i had to manually redo the whole thing18:19
nowenthat's not a very good upgrade process from Citrix.  Is that the standard for them?18:20
Guest44272yes18:22
Guest44272u can't upgrade certain firmware you have to wipe and install new version18:22
Guest44272then reload settings... which rarely works18:22
Guest44272anyway i got the same error18:22
nowenthe CAG is not sending the correct passowod:  passcode is ?218:24
nowenwhat does Citrix support say?18:24
Guest44272haven't called citrix yet18:25
nowenseems like they caused the problem18:26
Guest44272On the CAG, i pointed the radius server to 2nd wikidserver and it worked18:27
nowenwhat 2nd wikid server?18:27
Guest44272we have a second wikidserver18:28
Guest44272we have licensed for three18:28
nowenwhat is the difference between the network clients on the two servers?18:28
Guest44272two different network clients18:28
Guest44272must be a delay on windows side18:30
nowenhow are they different?18:30
Guest44272seems to be working now.18:30
Guest44272will keep an eye on it18:30
Guest44272office closes early today18:30
Guest44272thanks for your help18:30
Guest44272have to run out for a quick bite18:31
Guest44272before heading home18:31
Guest44272thanks18:31
nowennp18:31
*** Guest44272 has quit (Ping timeout: 258 seconds)19:05
prowlahnowen:  in the office now.. just attempted to configure it on my bosses windows machine, looks like same/similar problem as the others20:03
nowendo they all share some type of security software that might prevent it some installing?20:04
prowlahi was going to mention.. the install seems to hang on the creating shortcuts step 720:04
prowlahhowever when i had him just run the run.bat the client cameup.. got him registered, and appears to be functioning fine20:04
prowlah2012-01-13 19:59:38+0000 [-] WEB OUT: '2012-01-13 19:59:38+0000 [UDSProxyQueryProtocol,client] XMLRPCRelay: SESSION: Your session has expired, please reauthenticate (9007)'20:05
prowlahthat seems to be the common message20:05
nowenyou get that message from the installer?20:05
prowlahno, on login attempt20:05
prowlah2012-01-13 20:00:00+0000 [-] WEB OUT: '2012-01-13 20:00:00+0000 [UDSProxyQueryProtocol,client] Web login authentication failed: {'status': 1, 'reason': 'RADIUS access denied', 'user': 'kyoung'}'20:05
prowlahits what i get when i dont enter the correct pw20:06
nowenlet's stick to one issue at at time.20:06
nowenwhich one?20:06
prowlahthey are the same.. both of those are from 1 login attempt20:06
nowenwhat about the installer issue?20:07
prowlahit looks like the installer finishes copying all the files it needs to.. at that point they can use run.bat to launch20:07
prowlahit initially accepted his passcode / login20:08
nowenand WiKID authenticates the user?20:08
prowlahor it seemed to.. let me see if i have a success msg in the log20:09
prowlahhmm i dont see one, but his first attempt.. told him his acct was suspended, which made sense because i hadnt enabled his username in openvpn20:10
prowlahwhen i did that, it accepted his credentials20:10
nowenso, WiKID authenticates the user20:11
prowlahbut just to download the vpn client, trying to login after that fails radius login20:11
nowenI don't understand20:11
prowlahi cant confirm hes getting authenticated.. i dont see it in the log, but it seemed.. like it did to the point where he could grab the openvpn client20:11
nowenset the log level to debug on the WiKIDAdmin logs and hit filter20:12
nowen you should see his authentication20:12
prowlahyes20:13
prowlah012-01-13 20:01:22.746INFOcom.wikidsystems.radius.log.DBSvrLogImpl<158> Access-Accept(2) LEN=85 192.168.100.193:50837 Access-Request by kyoung succeeded20:13
prowlah2012-01-13 20:01:22.745INFOcom.wikidsystems.radius.access.WikidAccess4Access granted for kyoung, domain code: 173203191193 client: /192.168.100.19320:13
nowenyeah, so that is WiKID authenticating the user20:14
prowlahok yes20:15
prowlahjust had him do it again.. its authenticating20:15
prowlahopenvpn just doesnt like it20:16
prowlahits not saying radius is refusing.. (or succeeding) just that the session is expired and he needs to re authenticate20:16
nowenI can't help you with openvpn20:17
prowlahyeah.. thats ok.. what i dont understand is why i have no trouble20:17
prowlahhome machine, work machine.. it just works fine for me :)20:17
nowenI recommend #openvpn20:18
prowlahSESSION_ID only allowed to be used by client IP address that created it20:18
prowlahyeah.. ill hit them up, thanks20:19
*** nowen has quit (Quit: Leaving.)22:39

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!