Thursday, 2012-01-26

*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid13:53
*** nowen has quit (Remote host closed the connection)15:14
*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid15:17
*** cdub_ (40fee8e2@gateway/web/freenode/ip.64.254.232.226) has joined #wikid15:18
cdub_What is the best way to run the token off of a usn key so that they token can easliy by used on different PCs?15:18
cdub_I mean usb key15:19
nowenall you have to do is put the jar on the usb key15:19
nowenif you are using the non-locked token, you can also copy the WiKIDToken.wkd file and move your domains, etc15:19
cdub_and all the information will be stored on the USB key then, nothing will need to be stored on the PC?15:19
nowencorrect15:19
cdub_so the only requirement would be to have java installed on the PC15:20
nowenhmm, I suppose so. The bundled token installer includes it's own jre.  but I haven't tried to use it on a usb on a computer without java15:20
cdub_perfect, thanks for the help15:21
*** cdub_ has quit (Client Quit)15:21
*** jhall (53f185c1@gateway/web/freenode/ip.83.241.133.193) has joined #wikid15:32
*** jhall is now known as johall15:32
johallhi.. anyone alive?15:32
nowenmostly15:32
johall;)15:32
johallwill wikid work with built-in windows 7 vpn client?15:32
nowen the vpn client has nothing to do with it really. it depends on the vpn server - does it support Radius?15:33
*** cdub_ (40fee8e2@gateway/web/freenode/ip.64.254.232.226) has joined #wikid15:33
johallit's a 2008r2 nps15:33
johallso yeah15:33
cdub_I had previously run the token non-insaller exe on a PC. Now when15:34
johallbut i'm interested in knowing how the end user will actually connect15:34
nowenjohall: have you seen our nps doc?15:34
cdub_Now I run the the JAR file token of of a usb key on the same PC it is pulling the info from when the exe was run15:34
nowenjohall: they will enter their username and OTP into the vpn client, after getting the otp from the WiKID token15:35
johallnowen: yeah, or at least I think we're referring to the same one... on the one i mean there's some java app where you can request a otp15:35
nowenjohall: http://www.wikidsystems.com/downloads15:35
nowencdub_: you might need to use a new token.  one that doesn't have an installer15:35
nowenjohall: I meant: http://www.wikidsystems.com/downloads/token-clients15:35
cdub_Just re-writing so it is altogether - I had previously run the token non-insaller exe on a PC. Now when I run the the JAR file token off of a usb key on the same PC it is pulling the info from when the exe was run. Requesting previously cofigure passphrase.15:37
cdub_Where is it pulling the data from?15:37
nowenlook for WiKIDToken.wkd15:38
johallnowen: I guess that's some internal user database? Is it possible to integrate with Active Directory?15:38
nowenif you create an empty WiKIDToken.wkd in the same directory as jar/exe file on the usb drive, it should use that15:39
nowenjohall: you can allow users to register their own tokens based on their AD creds,  Radius handles the authz integration wtih AD.15:39
cdub_how do I go about creating an empty wkd file. Just use a text file and save as .wkd?15:40
nowenyeah, that should do it15:41
cdub_ok, thx15:41
nowennp15:41
nowenjohall: does that make sense?15:41
johallnowen: trying to wrap my head around it..15:42
johallnowen: so what's the procedure? end user -> wikid-token -> otp -> ???15:42
nowenthe process goes VPN >> NPS >> AD >> NPS >> WiKID15:42
nowenor WiKID >> OTP >> VPN >> NPS/AD >> WiKID >> NPS >> VPN15:43
nowenNPS validates that the user has permissions based on their username, if so, it checks the creds with WiKID, if that passes too, the NPS allows access15:44
johallnowen: and by VPN you mean, or, it could be, Windows 7 built-in VPN Client?15:44
nowenby VPN, I really mean the VPN server.  The connection request comes from the client to the VPN server/concentrator, which talks to NPS for authorization and authentication.15:45
johalland by client you mean wikid-token?15:45
nowenin that example, I mean VPN client.15:46
nowen:)15:46
johallhmmm15:46
nowenlots of clients and servers involved :)15:46
johallif i ask you this15:46
nowenthe user has two clients, WiKID & VPN15:46
johallis it possible to combine otp with windows 7 built-in vpn client?15:46
johallotp/wikid15:46
nowenNot sure.15:47
nowencan the windows VPN be launched via a command line with a username and password?15:47
johallrasdial.exe <vpn_connection_name> <username> <password>15:49
noweninteresting15:49
nowenwe can look into it15:49
johalli was told nps has no support for radius challenge response15:51
johalldo you know if that's true?15:51
nowenwe only use that as a fall-back if a wireless token is out of coverage15:51
johallok15:52
johalldo you get what i'm after?15:52
johalli want users to be able to authenticate with ad username and password along with the otp from wkid-token using windows 7 built-in vpn client15:53
johallalso, it shoud work with OS X Lion, but that's the next bump to handle ;)15:55
nowenthat depends on the options for windows VPN client and your VPN15:55
nowenI recommend against it.15:55
johallwhy's that?15:56
nowenit is best to not use your LAN password outside of the LAN.  it's a major security benefit of using two-factor authentication15:56
johallok, i understand... let me rephrase15:57
johalli want users to be able to authenticate with ad username along with the otp from wkid-token using windows 7 built-in vpn client...15:58
johalland users should be "imported" to wikid automatically15:58
johallwhere's the security in sending out the otp?15:58
nowenThat's what we've been covering.  However,users cannot be imported automatically.  WIKID uses public private keys that are generated on the devices and exchanged with the server15:59
nowenhttp://www.wikidsystems.com/learn-more/technology/overview might help16:00
johallok, i guess i will have to keep looking, thanks for your time16:00
nowenany system that "imports" users will use shared secrets and you will face the RSA issue16:01
*** johall has quit ()16:03
*** cdub_ has quit (Quit: Page closed)16:59
*** nowen has parted #wikid (None)22:56

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!