Thursday, 2012-04-12

*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid13:00
*** Barry_ (561ca72c@gateway/web/freenode/ip.86.28.167.44) has joined #wikid15:25
Barry_Hi15:25
nowenhi15:25
Barry_I'm trying to put 2FA in place for Windows Server 2008 R2. Can Wikid do this?15:26
nowenhow do you connect to it?15:26
Barry_Filezilla currently but I can use IIS FTP.15:27
nowenas long as you can get your FTP server (which I hope is using SFTP) to support radius, you should be fine15:27
Barry_I think I can get it working with SFTP; both seem to support that. Is there a "how-to" on this?15:28
nowenI don't think so.15:28
nowenwe have some on using NPS15:29
nowenwhich is the MS radius plugin for AD15:29
Barry_Not familar with that. Any docs on what this is and how to set it up?15:30
nowenwell, now that I think about it, it's probably not what you need at least directly15:30
nowenCould you run the ftp connections through ISA or whatever it is called now?15:30
Barry_What is that?15:31
nowenhttp://technet.microsoft.com/en-us/forefront/bb75889515:31
nowennow called Forefront15:31
Barry_Not sure what that is. Looks like it could be a way to go. So there's nothing that drops straight into a Windows Server?15:34
nowenwell, it is your FTP server that needs to support it15:34
nowenso, if you can get IIS FTP server to talk radius to WiKID, then it should be no problem15:35
Barry_Assuming I can get it talking to radius, and I'm sure I can, what's the install process?15:36
nowenwell, WiKID is a stand-alone system, you install it on it's own hardware or virtually15:36
*** SEJeff has parted #wikid ("Leaving")15:36
Barry_This would be for deployment from the outside of data centers so virtual is the only option.15:37
nowenSo, the WiKID server ISO is a software appliance based on Centos linux.  You don't need to know linux, but it can help15:39
Barry_Ok, so the virtual implementation only runs under linux?15:40
nowencorrect.  All of our software runs on linux.  The virtual Appliance is set up so you do not have to know linux to use it.15:41
Barry_Ok, so that would mean I'd have to setup VMWare on the server to run this, or use seperate hardware?15:42
nowencorrect15:42
Barry_Ok, well I guess I'd have to go that way in the long term.15:43
Barry_Thanks for your help.15:43
nowennp15:43
nowenthanks for your interest15:43
*** Barry_ has quit (Quit: Page closed)15:44
joevanonowen: trying to get challenge/response to work with our F5 Firepass, normal mode works great16:24
nowendoes it issue a challenge?16:24
joevanoaccording to F5 no additional config is required.  Can you confirm that this is what WiKID does? http://support.f5.com/kb/en-us/solutions/public/9000/600/sol9630.html16:25
joevanoit does not16:25
nowenare your users having issues being out of network?16:25
joevanonot currently... but I don't want to find out it doesn't work when they need it16:26
nowengood point16:26
joevanoI am thinking of some users possibly with an iPod and the client on it with an aircard or something16:27
joevanoand no wifi16:27
nowenjust so you know, our ability to do c/r comes up frequently in pre-sales.  but it has never come up in production. for what that's worth.16:31
nowenso how do you get the F5 to give you a challenge?16:32
joevanoyeah, I ddn't think of it and it isn't a huge deal... just a nice to have16:32
nowenI'm curious now16:32
joevanoi asssumed a blank password, but that is a good question16:33
nowenthat's what I would have thought16:33
joevanoha... known f5 issue, if you have 2 radius auths services configured it may send it to the wrong one16:35
joevanoguess how we are configured16:35
nowenhehe16:35
joevanoguess I'll call to see where they are at on that16:36
joevanonowen: is it possible for the same user id to have multiple device tokens in the same domain? my guess is no20:05
nowenyes, but you have to add them via the api.  check out the example.jsp page20:06
joevanoah... awesome! thanks20:06
nowenAdd a Device without a Passcode is the method you want20:06
joevanocool thanks20:08
joevanoooooh a Ruby gem... this gets better and better20:54
nowenhehe20:54
*** nowen has quit (Quit: Leaving.)22:42

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!