Tuesday, 2012-01-24

*** _markh__ (~chatzilla@wish-hq3.gotadsl.co.uk) has joined #wikid01:31
*** _markh_ has quit (Ping timeout: 240 seconds)01:31
*** _markh__ is now known as _markh_01:31
*** CowboyPride (~BartSimps@cpe-075-183-177-241.sc.res.rr.com) has joined #wikid03:12
*** CowboyPride has quit (Client Quit)03:13
*** CowboyPride (~BartSimps@cpe-075-183-177-241.sc.res.rr.com) has joined #wikid03:18
*** CowboyPride has parted #wikid (None)03:18
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:52
*** bhuffman (4614c8ba@gateway/web/freenode/ip.70.20.200.186) has joined #wikid15:09
bhuffmanI'd like to have the same user on multiple devices but that doesn't seem to be possible.  Am I missing something?16:14
nowenhave you seen example.jsp?16:14
nowenit is possible, but it is limited to the API currently16:14
bhuffmanI've seen it...16:15
nowenthere is an option to Add a Device Without a Passcode16:15
nowenyou can enter a registration code there to an existing username16:15
bhuffmanwhich section should I use to do this?16:24
nowenIt should say Add a Device Without a Passcode or similar16:25
bhuffmanExcellent - that works.16:26
nowencool16:26
bhuffmanAre there plans to add that to the standard config GUI?16:26
nowenif you take a look at ADRegister in /opt/WiKID/tomcat/webapps/wikid/ADRegister, you can see it in action16:27
nowenprobably at some point16:28
nowen:)16:28
*** bhuffman has quit (Quit: Page closed)16:32
*** CoolAcid has quit (Ping timeout: 252 seconds)17:25
*** CoolAcid (~Jason@2001:470:c025:f00d:8e89:a5ff:fe30:c728) has joined #wikid17:26
*** Guest56543 has quit (Quit: Page closed)18:08
*** prowlah has quit (Quit: leaving)18:39
*** jerquiaga (266bb9e2@gateway/web/freenode/ip.38.107.185.226) has joined #wikid18:54
jerquiagaMorning all. I'm trying to setup WiKID on CentOS 6.2, followed the install how-to for the enterprise RPMs, and it doesn't seem to be working. I can get the RPMs installed, run wikidctl setup, but can't get to the web page after that to finish the setup. It's almost like the webserver isn't starting, because there doesn't appear to be anything listening on port 80. Any thoughts?18:57
nowencan you run 'netstat -anp | grep java' and see if it returns anything18:57
jerquiagaDoesn't return anything18:58
nowendid you run "wikidctl start"?18:59
jerquiagaI did, and I get: Database already started. Starting Logger service...Success! Starting TimeCop service...Success! Starting Tomcat server ...Success!18:59
nowenhmm19:00
nowenand yet, nothing from netstat19:00
jerquiagaNope, nothing19:01
nowencan you look in /opt/WiKID/tomcat/logs/catalina.out for an error19:01
jerquiagais there a way that I can verify that those services are actually running?19:01
jerquiagayeah, let me check19:01
nowenyes, by running netstat :)19:01
jerquiagagot it... i have some no such file or directory errors19:02
nowencan you paste them into pastebin.com so I can see them?19:03
nowenwhat version of WiKID is this?19:03
jerquiagahttp://pastebin.com/C8cSFQiG19:04
jerquiagawikid-server-enterprise-3.4.87.b1074-1.noarch.rpm19:05
nowendid you install openjdk?19:05
jerquiagawhen i ran the yum install for open jdk, it said it was already installed19:06
nowenrun 'java -version'19:08
jerquiagajava version "1.6.0_22" OpenJDK Runtime Environment (IcedTea6 1.10.4) (rhel-1.42.1.10.4.el6_2-x86_64) OpenJDK 64-Bit Server VM (build 20.0-b11, mixed mode)19:08
nowendo you have /usr/lib/jvm/java-1.6.0-openjdk-1.6.0.0.x86_64/bin/java?19:10
nowenwhat happens when you run that command19:10
nowenhmm.19:11
nowenrun 'echo $JAVA_HOME'19:11
jerquiagalooks like the path i have is /usr/lib/jvm/java-1.6.0-openjdk-1.6.0.0.x86_64/jre/bin/java19:12
jerquiagaJAVA_HOME is /usr/lib/jvm/java-1.6.0-openjdk-1.6.0.0.x86_6419:12
nowenyou can reset java_home by running 'export JAVA_HOME= /usr/lib/jvm/java-1.6.0-openjdk-1.6.0.0.x86_64/jre/19:12
nowen'19:12
jerquiagalooks like i have an extra jre in there that WiKID isn't expecting for some reason19:13
nowendid you run the alternatives command?19:14
jerquiagaOK, i did the export19:14
jerquiagayeah, i did19:14
jerquiagawhen i ran the configure, it was set as the OpenJDK19:14
jerquiagalet me try starting it again after the export19:14
nowenhmm. I wonder.19:15
nowenI think that openjdk does one thing and sun's the other19:15
jerquiaganow i have java listening it looks like19:15
jerquiagaalthough, still no page19:17
nowentry going straight to https://ipaddress/WiKIDAdmin19:18
jerquiagaNo joy19:19
nowenare you on IE?19:19
jerquiagaChrome19:19
nowenis iptables open for those ports?19:19
jerquiagahow do i check? i admit that I'm not very proficient on the Linux side of the house19:20
nowen'iptables -L -n' will list what is open19:20
nowenyou might want to use our ISO.  it builds an appliance, essentially.  no linux needed, but helpful.  it handles the fw etc19:21
jerquiagahttp://pastebin.com/yvU212NN19:21
jerquiagaOK, maybe I will try that then19:22
nowenI have to say it is quite a breeze19:22
nowenare you using vmware or some such?19:22
jerquiagawe use Hyper-V19:22
nowenthat should be fine. the iso is based on centos 5 btw19:23
jerquiagaOK19:23
jerquiagaI'll grab the ISO then and give that a shot19:23
jerquiagathanks for the help!19:23
nowencool. come back here19:23
nowenfor anythin19:23
noweng19:23
jerquiagawill do19:23
*** jerquiaga has quit (Quit: Page closed)19:23
*** jmcmurry (266366aa@gateway/web/freenode/ip.38.99.102.170) has joined #wikid22:09
jmcmurrythanks for the links Nick22:09
nowenNP ;)22:09
nowendo your NAC devices support Radius?22:10
jmcmurryyes they do22:10
nowenintegration should be quite simple then22:11
jmcmurryshould be a no brainer -> will be more of a implementation whitepaper we will do first22:11
nowenlet me know and we'll give you some link love22:11
jmcmurryI had been meaning to get a couple of people on this in Nov '11 but we got busy and i dropped the ball22:12
jmcmurryso i thought i would do it to kickstart them :)22:12
nowen:)22:12
nowenthat's good to be busy at the end of the year22:13
jmcmurryit was the busiest december since we started in 200722:13
nowenyou know, our PC token can run on a USB drive.  There might be something with that and USBInformer22:13
jmcmurryoh, now there is a thought.  i like that idea22:13
nowenin fact _markh_ might have some thoughts on that if he is here22:15
jmcmurryWe just released (last week) USBInformer and have sold 30 copies so far (50 user licenses)22:21
nowennice22:21
jmcmurrynot a huge thing, but it was nice to see an immediate pop22:22
nowendefinitely22:22
jmcmurrywe are not a big company by any means <25 people22:22
jmcmurryour Edge line we sell on average 40 units per month22:23
nowensame here.  we use some reliable contractors for certain things.  windows native, apple22:23
jmcmurrydecember we did 65, so that was huge for us22:23
jmcmurrywe have a couple of guys in new mexico who contract on some things for us (not NAC related, thats all in house)22:24
jmcmurryour bread and butter is NAC of course.  but looking to expand in other areas.  two factor is going to be a big push for us in 2012 with our utility customers22:25
jmcmurry:)22:25
noweninteresting. I don't suppose you'll be at Shmoocon?22:25
jmcmurryunfortunately no, i am traveling between Northern california office, SoCal, Utah and Seattle in Jan / Feb22:26
nowenugh22:26
jmcmurryi never seem to get to go to conferences, but last year I tried hard and went to defcon/bh/bsidesvegas/interop/rsa22:27
nowenRSA is out for me this year - overlaps with a school break22:27
jmcmurryi don't know if i will do RSA this year, its become more hype and cramped spaces :)22:28
jmcmurryi really enjoy the besides/firetalks ideal22:28
nowenBsidesSF22:28
nowenwe have had two great ones here in Atlanta22:28
jmcmurryof course that doesn't exactly our real customer - so we go to utility conferences, education confs, etc22:29
nowenyeah, I feel the same way22:29
jmcmurryyeah we sponsored bsidesatlanta in 2011 (i think $750 )22:29
nowenoh yeaj/ LOL22:29
nowenFYI I still have to send that check in.  Still waiting on receipts from some peopel22:30
jmcmurryour goal this year is to sponsor every single bsides in the US22:30
nowenthat is great22:30
nowendid you have someone here?22:30
jmcmurrynope :(22:30
jmcmurrythis year though, i think either myself or Ethan will go to some of them in person, just to hang out22:31
nowenyeah.  the connections are great22:31
jmcmurrythe information passed is awesome, and the connections22:31
jmcmurryi don't think of sponsoring as a revenue generator at all22:32
nowenno22:32
jmcmurryour little way of giving back, to help the next group of people coming up22:32
jmcmurryits not much (the $750 per sponsor) but it is helpful for some of the locations22:32
nowenbig time22:32
jmcmurrywe meet our customers at JMUX conference, EDUCase, etc and of course word of mouth22:33
nowenwhat is jmux?22:35
jmcmurrythese guys (now a GE company)  http://www.gedigitalenergy.com/multilin/catalog/jmux.htm22:36
nowenhmm22:36
jmcmurryevery single utility out there uses something like this (most us JMUX, some intermix with other types)22:36
jmcmurryPG&E, SOCAL Edison, WAPA all use JMUX22:37
jmcmurryit is THE interconnect between substations22:37
jmcmurrySCADA rides on it :)22:37
jmcmurryMeters (revenue) ride on it for electric and water22:38
jmcmurrybetter link   http://www.gedigitalenergy.com/Communications/Multiplexers.asp22:38
jmcmurrywe have (and are) deploying our Edge devices in front of these systems to provide access control - hence the need for two factor :)22:39
nowenregulatory requirement?22:40
jmcmurryyes22:40
jmcmurryJMUX can be considered a Critical Asset by NERC, so it would fall under the CIP for access, admission, monitoring, etc22:40
jmcmurryhave you garnered any success in the utility vertical ?22:58
nowennot really22:58
nowenseems to be heating up tho22:59
jmcmurrymight be interesting if there was a good match with our product sets, to jointly go after that vertical22:59
nowendefinitely22:59
jmcmurrydo you have salespeople?23:07
nowenno23:07
nowenwe mostly do pre-sales support.  that gets them up and running. once it is up and running, it tends to stay that way23:07
nowenwe market mostly to techies, who then do the install and sell it up to mgmt23:08
jmcmurryi have 3 inside sales people, along with 2 pre-sales eng23:08
jmcmurryall inhouse23:08
nowenI would have thought that the utilities would want to see a body23:08
jmcmurrywhen we sell the systems, we can be onsite as well (have 1 more person outside eng support)23:09
jmcmurryand of course our staff moves between customers23:09
jmcmurrylocations23:09
jmcmurrysince each place is unique, our model is to sell the systems, then hold their hands through planing, deployment and long term support/maintenance23:10
jmcmurrya lot of places don't have real technical people on staff.  especially some of the Govt (Fed) agencies we deal with23:10
nowenyeah, that could be an issue for us.23:10
jmcmurrythey know they have problems, they just don't know how to fix23:11
nowenit's pretty simple to setup the appliance, but it helps to know networking, etc23:11
jmcmurrywell if it was integrated solution to a joint customer we could also be the first point of contact to assist with WiKid appliance23:11
jmcmurryand help (or do) the integration for the customer as part of the package23:12
nowenor run it on your box?23:12
jmcmurryhmm, didn't think of that23:12
nowenit might be best behind your box from a security standpoint, but I don't know much about your box.23:16
nowentime for me to head home23:17
jmcmurryit would sit on our control server23:18
jmcmurrywhich is above the edge itself23:18
jmcmurryminimum deployment is a control server and a edge (two sep appliances)23:18
jmcmurry1 CS can support up to 50 Edge devices23:18
nowenok23:19
jmcmurryos is based on freebsd23:20
jmcmurrystripped down23:20
nowenhmm, we're geared toward linux, but it shouldn't be too hard23:20
jmcmurryok u go home - i won't keep you23:20
nowenour server is written in java23:20
nowenok - I'll be back tomorrow23:21
jmcmurryshould be a prob23:21
jmcmurryshould not be23:21
nowen:)23:21
nowenlater!23:21
jmcmurrycy23:21
*** nowen has quit (Quit: Leaving.)23:21
*** jmcmurry has quit (Ping timeout: 264 seconds)23:54

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!