Tuesday, 2012-05-08

*** vladdy has quit (*.net *.split)05:21
*** joevano has quit (*.net *.split)05:21
*** vladdy (~vladdy@194.242.5.47) has joined #wikid05:22
*** joevano (~joevano@bzflag/developer/JoeVano) has joined #wikid05:22
*** R\Peaceman has quit (Ping timeout: 250 seconds)13:19
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid14:17
*** autodata (cdcd1c11@gateway/web/freenode/ip.205.205.28.17) has joined #wikid15:46
autodatahi nowen, how are you?15:47
nowenfine15:47
nowenhow does it?15:47
nowenor goes it?15:47
autodataI installed the ISO, I still can't access to the WIKID admin page, again, it says it failed to connect to the DB..:(15:48
nowenok15:48
autodataSEVERE: Exception opening database connection15:48
autodataorg.postgresql.util.PSQLException: FATAL: role "tomcat" does not exist15:49
autodatabut tomcat is there15:49
nowenwhat version is this?15:49
autodatajava version "1.6.0"15:50
nowensorry- what version of WiKID?15:50
autodataHow I can tell?15:51
nowenrun 'rpm -qa | grep wikid15:51
nowen'15:51
nowenand it will tell you which version of enterprise you have installed15:52
autodatawikid-server-enterprise-3.4.87.b1216-115:52
nowenok cook15:52
nowencool15:52
autodatawikid-utilities-3.0.9-115:52
nowenrun 'wikidctl stop'15:52
nowenand then 'service postgresql start15:52
nowen'15:52
autodatait seems it starts OK15:53
nowendid you setup replication?15:54
autodatastart wikid again?15:54
autodatano15:54
nowenyes, go ahead and start wikid15:54
autodatayeap, it starts OK, let me try the admin page15:55
autodatahmm, it is still failed:15:55
autodataThe requested resource () is not available.15:55
nowenis that in catalina.out?15:56
autodatacheck15:56
nowencan you paste the whole error in http://pastebin.org15:56
autodataok15:56
autodatasummit the errors15:58
autodatacan you see it?15:58
nowenand then post the new url here15:58
autodatahttp://172.16.130.18/WiKIDAdmin/15:58
nowenno, I mean the pastebin url.  after you submit, it redirects you to a new url, where I can see it15:59
autodataI have changed the server's hostname to sth other than localhost15:59
nowendid you set it when you ran wikidctl setup?15:59
autodataI didn't run that16:00
nowenahh16:00
nowenthat's the issue16:00
autodataoh..16:00
autodataShall I stop all: wikid and DB, and run that?16:01
nowenrun that and re-run start16:01
nowensetup will stop everything16:01
autodataok16:01
autodataport 80 has no response from that server16:04
autodatawait, have to start the wikid16:05
autodatasame error, going to post that error to you16:07
nowenI can't even get to http://172.16.130.18/WiKIDAdmin/16:09
autodatahttp://pastebin.com/9NczzKq116:09
autodataabove is error report16:09
autodatano it is still on the LAN16:10
nowencan you run ' /opt/WiKID/conf/templates/wikid-firstboot.sh'16:11
autodatathis is for?16:12
nowenit sets up the server - copies files to right place, etc. It should have run when you rebooted after install16:13
autodataUpdating PostgreSQL configuration files for use with WiKID ...16:13
autodataI'll reboot now16:13
nowenyou don't have to16:13
nowenjust try to restart16:13
nowenwikid restart, that is16:13
autodataok16:13
autodatacatalina log still shows:16:15
autodataorg.postgresql.util.PSQLException: FATAL: role "tomcat" does not exist16:15
nowenhmm16:15
autodataI'll be back16:16
nowenok16:16
nowenautodata: I think the best bet is to start from scratch.  Something went wrong in the install and it would be best to have a clean base16:25
autodatamy question, 1. do you use apache, or only tomcat16:41
nowenonly tomcat16:41
autodata2. after clean install, can I setup the hostname, with kiwid serup?16:41
autodatain another word, setup the network setting through wikid setup?16:42
autodatainstead of setup from the Linux16:42
nowenyes16:42
autodata3. do I have to join this server to our domain controller?16:42
autodatathis is important one16:43
nowen3.  no16:43
autodataoh.. ok16:43
autodataso follow up the instruction of, sorry can you give me the link again?16:43
nowenjust stay here and let me walk you through it16:44
nowenhttp://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/referencemanual-all-pages16:45
autodatayes, but this is not for ISO16:45
nowenonce you reboot after the install, all you need to do is login with root/wikid and then follow these16:47
autodataok, give me a sec, I want to start, have to install the sperehost first16:47
autodatathx16:48
nowennp16:50
autodataok, start loading DVD for ISP now17:00
nowenok17:01
autodatahi nowen, what is Use interface sit0? I don't need it, right?17:13
nowencorrect, you don't need it. it is some virtual interface17:13
autodataoh, ok, thx17:14
autodatabasic setup is completed, I'll run wikid start now17:16
nowenok17:17
autodatait's done, then system prompts that thr DB is not configured, asking to run load_db.sh17:18
nowenhmm17:18
nowenthat may not be a problem17:19
nowendid wikid start?17:19
autodatait asks to run /opt/WiKID/sbin/load_db.sh17:19
autodatashall I run it?17:19
nowengo ahead and run it17:19
autodatayes. wikid starts successfully17:20
nowenif you can login as admin, then no need to run load_db17:20
nowenwhat type of environment is this?17:20
autodataVM17:20
nowenWMWare?17:20
autodatayes17:21
autodataI have run it already17:21
autodataHi nowen, I tried admin page, it edns up with the same error17:22
nowenok, stop WiKID and run the load_db script17:22
nowenwhen you setup the server in vmware, what OS did you specify?17:23
autodataCentos, it's our standard17:23
nowen32 bit?17:23
autodata64 bit17:24
nowenour iso is 32 bit17:24
autodatabut now is is rteplaced by ISO, right?17:24
nowenyou want centos/rhel 32 bit17:25
autodatawith ISO install, it erased all contents from the VMware17:25
nowenright, but then when you create the vm, you have to tell vmware what type of iso it is, right?17:25
autodatanow the bit length is17:26
autodataLinux ln-co-vpnauth1.london.autodata.net 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 EDT 2010 i686 i686 i386 GNU/Linux17:26
autodata32 bit17:26
autodatayes, but do you think it is matter?  32bit can be run on the 64 bit platform17:27
nowenI'm not sure what is going on.17:28
nowentry running the load_db.sh script17:28
autodatajust did it, and run wikid start again, now I check the catalina log17:28
autodataHey nowen, finally I can login to the admin page, there is no error in tomcat log17:32
nowennice!17:36
autodatahey nowen, sorry to bug you again, I generate the CSR, and paste it install the intermidiate cert. but once I click submit, there is no system prompt saying the cert is installed successfully17:59
autodatadid I do anything wrong?17:59
nowendid you get the pop up window?18:00
autodatano18:00
autodataI might need IE instead of FF18:00
nowenno18:00
nowenyou never, ever need IE!  ;)18:00
autodataok18:00
nowenthere is a link to a pop-up window on the page that has the CSR18:01
autodataGo to Install Intermediate Certificate function when you receive your cert.18:01
autodatathis is the link I get18:01
nowenabove the box18:01
autodatahttps://ca.wikidsystems.com/wikid/newcertreq.jsp18:01
nowenyes18:02
autodataso yes, the Wikid inter cert is generated, I will receive the email, I guess?18:03
nowenit should be presented in that same page18:03
nowenbut I can forward it to you too18:04
autodataok, saw that18:04
nowenon its way18:04
autodatathx, so that means I get the only inter cert?18:05
autodatathen what I shall do?18:05
nowenyou paste into the install page18:05
nowenInstall Intermediate Certificate18:05
autodataok18:06
nowenthen create the localhost cert18:07
autodataok, it's installed, now go for localhost18:08
autodatanowen, what is this?18:09
autodataClient PKCS12 Passphrase18:09
autodatais it something I need to make it?18:09
nowenit is the passphrase that protects the localhost cert18:10
nowenit is required18:10
autodataso it is different than the one for inter cert?18:10
nowenit is different, but you can use the same one if you like.18:10
autodataok, then what is this:Server Keystore Passphrase?18:11
nowenthat is the passphrase used to secure the intermediate CA18:11
nowenyou use that when you start the server18:11
autodataso this is the separate one18:11
nowencorrect18:12
noweni'm scheduled to go give blood.18:14
nowenI should be back in an hour18:14
*** nowen has quit (Quit: Leaving.)18:15
autodatasure, thx18:16
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid19:07
nowenautodata: how goes it?19:07
autodataHI nowen: I get the confusion at this point after install the cert.19:37
nowenok - so you installed the cert and created the localhost19:37
nowendid you enable radius as a protocol?19:38
autodataSo what shall I do for the next, I'd like to integrate our LDAP to the WIKID19:38
nowenwhy ldap?19:38
nowenor: what are you trying to add two-factor authentication to?19:39
autodatawell, this where I confused, how does this work? I know I will setup the authentication server, but I should also to integrate the ladap so that we can serve the users19:47
nowenare you protecting a VPN?\19:47
autodatayes for sure19:47
nowenso, you want to validate that the users are in AD and do two-factor auth.  The answer is to use radius.19:48
autodatayes, I have CIsco ACS as the Radius server, is that OK?19:49
nowensure19:49
nowenthe cisco ACS can probably do lots of cool stuff19:50
autodataSo WIKID only serve as the authentication server?19:50
nowencorrect19:50
autodataHow do I start then, I an in the clud ...19:51
nowenso, the way most people do this is to have the cisco talk radius to AD via the MS radius plugin, NPS19:51
nowenNPS then proxies the auth request to WiKID19:51
autodataI don't understand why we have to use NPS? ACS should do the all tasks?19:52
nowenit might19:52
nowenI don't know19:52
nowencan ACS check AD and then send a radius request to WiKID?19:52
autodatacheck...19:53
autodatanot 100% sure yet, but what is the authentication process, I want to make it clear so that I can check19:56
autodataso the client first try to login through VPN, then it gets through to the ACS for authentication?19:57
nowenyes, in my suggestion:   VPN >> ACS >> AD/NPS >> WiKDI19:58
nowenor if you can chain it, then VPN >> ACS >> AD >> ACS >> WiKID19:58
autodataso from NPS to WiKID, that is the second factor of authentication?19:58
nowenno, that is different.  That is possession of private key embedded in the token and knowledge of the PIN19:59
nowenthat process check occurs before login.  The user logs in with their username and a WiKID OTP20:00
autodataso first of all, user login VPN with username and OTP, and this get processed in WiKID20:01
nowenno, they log in with their username and OTP and the username is authorized by AD, then the username/OTP pair is authenticated by WiKDI20:02
autodatahow to get the OTP ?20:03
nowenvia one of our token clients20:03
autodataoh..20:03
autodataSo Wikid server has to be accessible through the Internet?20:05
nowenyes, port 8020:05
autodataDo you have the detail doc explainig hwo to setup the Radius proxy, so it can send the request to Wikid?20:06
nowenfor NPS, yes20:07
nowenit is not detailed, though. for details, you would need to talk to Cisco or MS20:07
autodataand the whole 2 factor process flow chart20:07
nowenI don't have a flowchart20:08
nowenother than: VPN >> ACS >> AD/NPS >> WiKID20:08
autodatasure, I'd like to know the work process for this 2 factor authentication, because now I have not that clear20:08
autodatafor example, what s the exact NPS does to Wikid?20:09
autodatasend username and OTP pair to Wikid?20:10
nowenNPS is a radius server like ACS.  It will validate that the user is active in AD and if so proxy the request to WiKID20:10
nowenyes20:10
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps20:10
autodataSo in your standard architect, it looks like this chain:20:15
autodataVPN --> NPS --> WiKid20:15
nowenthat is the way a lot of our customers do it20:16
nowenbut not all have an ACS20:16
autodataThis doc helps a bit, it says:20:16
autodatayour VPN or application is a RADIUS client to NPS and NPS is a RADIUS server to the VPN/application. In turn, WiKID is a RADIUS server to NPS and NPS is a Network Client to WiKID.20:16
autodataso that makes sense20:17
autodataI probably will use ACS to replce the NPS20:17
nowensure20:25
autodataHi nowen, with this architect, it seems I have to enable thr Redius in the Wikid server?20:31
nowencorrect20:31
autodataok, thx20:31
nowenI recommend you enable radius, but not ldap.  ldap uses a lot of memory20:31
autodataoh20:31
autodataany service should be always enabled on localhost, not the IP. right?20:39
nowenyou mean, like radius on the WiKID server?20:41
autodatayes20:45
nowenyes, those services run on the localhost20:45
autodataok20:45
autodatanowen, about the link you sent to me:How to add two-factor authentication to NPS20:47
nowenyes?20:47
autodatathere are 3 IPs appear:20:47
autodataone is the VPN server: 192.168.1.1020:47
autodatasecond one is WIKID server 192.168.1.20020:48
autodataI don't get the third one, what is that IP for? 192.168.1.100?20:48
autodatait says it is NASIPv4Address , why do we need this one, I thought Wikid address should be sufficient20:50
nowenI think that is a typo.  should be .1020:51
autodatahaha... that make sense then...20:52
autodataHey nowen, my last one for today, what proper token clients I should use?21:03
nowenyou can use any of them. if your server is on the lan, though, your smartphone tokens will need to be too21:03
autodataany reason I have to use smartphone token? This is just for VPN client21:05
nowenup to you.  some people like the fact that it is not on the same device as the vpn client21:05
autodataoh, OK, I guess that can be tested later on21:06
nowenthe PC token is quite nice for testing21:06
autodatais this the one you mentioned?21:08
autodatawikidtoken-3.1.21-bundle-installer.exe - Windows WiKID software token installer (28 meg)21:08
nowenyes21:08
autodatacool, I'll start from this one.21:08
autodatathnaks for the help today nowen. I will continuce on my ACS test first21:09
nowengood luck!21:09
autodatathanks again21:09
nowenno problem!21:09
*** autodata has quit (Ping timeout: 245 seconds)21:20
nowen time for me to check out.  later22:17
*** nowen has quit (Quit: Leaving.)22:17

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!