Monday, 2012-01-23

*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:23
*** Mo (d8390e7c@gateway/web/freenode/ip.216.57.14.124) has joined #wikid16:38
MoHi Nick16:38
nowenhey Mo16:38
*** Mo is now known as Guest5654316:38
Guest56543over the weeked we changed our firewalls16:39
Guest56543and now i can't seem to connect to wikid over port 80 to get the pin code16:40
Guest56543the server is http access logger16:40
Guest56543but not much information is there16:40
Guest56543i have telnet into port 8016:40
Guest56543so i know it works16:40
nowenso, you changed the firewall but made no changes WiKID?16:40
Guest56543right16:41
nowenwhat changes did you make to your firewall?16:41
*** _markh_ (~chatzilla@wish-hq3.gotadsl.co.uk) has joined #wikid16:41
Guest56543replaced the old ones with new ones; different type16:41
Guest56543the changes we made should not affect wikid server16:42
Guest56543however, i am seeing http access logger on wikid16:42
nowendid anything else change besides the firewall?16:42
Guest56543no16:42
Guest56543this is the message16:43
Guest5654368.196.208.94 - - "GET /Citrix/PNAgent/config.xml HTTP/1.1" 404 34416:43
nowenyeah, there is no Citrix data on the wikid server, so it should get a 404, right?16:43
nowenwhat do you see on the firewall logs?16:44
Guest56543what citrix data on wikid16:47
nowenyou just posted: 8.196.208.94 - - "GET /Citrix/PNAgent/config.xml HTTP/1.1" 404 34416:47
nowenthat is a request for a Citrix file of some kind16:48
nowenright?16:48
_markh_nowen: Just tried to renew our license online and Google Checkout blew up... Owing to my trigger happy impatience, I suspect we may have ordered multiple licenses :) Can you check for me?16:49
nowen_markh_: no, just the one I see.  and they usually come in right away16:50
_markh_Great - thanks. I don't know what happened, just kept getting a blank page when I hit the Proceed button....16:51
nowenhuh16:52
_markh_well, if you only have one purchase all must be OK now16:54
nowenyes, I think so.  I can easily cancel anything else that comes through16:55
_markh_Anyhow, we're using wikid-server-enterprise-3.3.2-b2427. Should/can we upgrade?16:55
nowenoh, yes16:55
_markh_How's the best way of doing that?16:55
nowengrab this rpm:  http://wikidsystems-dl.com/wikid-server-enterprise-3.4.87.b1171-1.noarch.rpm16:56
nowenand run 'rpm -Uvh wikid-server-enterprise-3.4.87.b1171-1.noarch.rpm'16:56
nowenon the terminal16:56
nowenhow do you do back-ups?16:56
_markh_we don't ... :-/16:57
nowenyou can quickly back up the db by running:  "tar -czvf dbbackup.tar.gz /var/lib/pgsql/data/*"16:57
_markh_Presumably we stop the server (wikidctl stop)...?16:58
nowenI don't think it will be an issue, but that is an older version.  just run that tar command16:58
nowenit is best to run wikidctl stop and then the tar command16:58
nowenthe rpm command will stop the server16:59
_markh_Backing up now...17:00
_markh_While it's doing that, when we last spoke I was asking about Iphone./Android tokens. The prob for us at the time was that they are locked to use your DNS servers and we need to do our own. Has that position changed?17:01
nowennot yet.  We're focused on addressing this in the Advanced server version17:04
_markh_OK. Well, it's something we'd love to see. Also, I was asked the other day about token security. We use USB sticks, so what's to stop someone briefly stealing someone's USB token and cloning it (thereby getting one part of the two factor auth - although they still need the passcode I guess)17:06
nowenwell, you can use secured USB drives if you want.17:06
_markh_Yes, but is there anything that could stop a disaffected employee from copying the token file to another unsecured device? I guess what I'd like to see is that a Token file is locked to some kind of serial number on the device somehow17:08
nowenif there's an API for that, we might be able to do it.17:10
_markh_It's not mission critical. The security in the Nat. Health Service is a bit paranoid. I was just wondering if you encoded the token agains the Filesystem UUID or something like it it would make Token copying more difficult...17:12
_markh_This download is taking ages... :(17:13
_markh_84% [====================================>        ] 48,926,891  48.2K/s  eta 2m 22s17:14
nowen I understand.  we do that for the Locked token using the mac addy or the cpu identifier etc.  We know that something should be there.17:14
nowenhuh17:14
nowenI just downloaded the iso way faster than that17:14
_markh_Must be our end ...17:14
_markh_Bah! Need to upgrade sudo. How do I upgrade that under Centos? (We use ubuntu)17:16
nowenyum update sudo17:16
nowenbut 'yum update' would be a good idea too17:16
_markh_... and that's going to take forever. I'll get on it tomorrow.17:21
nowenyeah17:21
_markh_thanks. Bye.17:22
nowenThank you!17:22
nowenGuest56543: did you get anything from the firewall logs?  If you request an OTP, you should see what it happening17:26
*** bhuffman (4614c8ba@gateway/web/freenode/ip.70.20.200.186) has joined #wikid17:29
bhuffmanHello - There's an issue that I've found with the java client on linux.  It looks for jWiKID.jar file, but the installed file is wikidtoken.jar.17:30
bhuffmanI've made a symlink and it works, but you may want to fix that.17:30
nowenhuh, thanks!17:31
nowendid you use the installer?17:32
bhuffmanyep17:32
bhuffman[bhuffman@polaris WiKID]$ java -jar wikidtoken-3.1.17-installer.jar17:33
Guest56543nic18:09
Guest56543nick18:09
Guest56543any idea18:09
Guest56543what could my issue b18:10
Guest56543should i restart18:10
nowenI asked what you saw in your firewall logs18:10
*** bhuffman has quit (Ping timeout: 264 seconds)18:47
nowenGuest56543:  did the IP of the firewall change?19:00
nowenGuest56543: did you check the fw logs?22:37
*** nowen has quit (Quit: Leaving.)23:07

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!