Wednesday, 2012-05-16

*** WiKIDLogbot (~WiKIDLogb@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid12:03
card.freenode.netTopic for #wikid is: support for the WiKID Strong Authentication System.  If no one is here, try the nabble forums: http://www.wikidsystems.com/support/support/wikid-forums12:03
card.freenode.netUsers on #wikid: WiKIDLogbot @nowen vladdy joevano12:03
nowenbad WiKIDLogbot12:04
joevanohehe...12:05
joevanoNetComnent couldn't login to his newly installed instance12:05
nowenso hard to get good spies these days12:05
nowenhmm, often that means the db isn't setup right12:06
joevanohe couldn't figure out the default password... I am guessing reading the manual isn't his strong suit ;-)12:06
nowenthat could be too. but if the db isn't setup, you can't login with the correct creds either, but you can try all you want12:07
joevanoi gave him the password and pointed him at the setup videos, he never responded when I asked if that helped him12:08
joevanohe left about 30 minutes later12:09
nowenhmm. oh well12:09
nowenI bet he returns12:09
joevanoSidetalker had issues with his TACAS+ integration, but figured it out... needed to add the -i flag so the tac_plus reloaded on every connection12:10
nowenwow, that's good stuff. tacacs is not used much12:11
joevanoyeah, luckily he knew quite a bit about it... I had no idea12:11
joevanobrb12:14
*** joevano has quit (Quit: leaving)12:14
*** joevano (~joevano@bzflag/developer/JoeVano) has joined #wikid12:20
nowenok - I've got a couple of off-site meetings. coffee now and lunch later.12:48
*** nowen has quit (Quit: Leaving.)12:49
*** sideone (~sideone@23.24.175.105) has joined #wikid12:59
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid14:17
*** nowen has quit (Quit: Leaving.)15:25
*** netcomnet (46b71922@gateway/web/freenode/ip.70.183.25.34) has joined #wikid16:31
netcomnetCan someone help me find th registration code?  I have the server up, but the AD web self registration asks for a registration code16:32
joevanonetcomnet: that is generated by the WiKID client when you add your domain, you supply that to the AD web self registration form and it associates the client with that user16:41
netcomnetW try to create new domain on client but it fails to obtain configuration.  I cannot figure out what is missing.  The documentation seems to skip this critical step16:43
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid17:12
nowenhi all17:12
nowennetcomnet: what is your domain identifier/12 digit code?17:13
netcomnet07018302503417:24
nowenhmm.17:25
nowenreturns no data17:25
nowendid you set up the network using wikidctl setup?17:25
netcomnetI already had an IP and dns so I answered no, should I do that?17:26
nowenyes, I think the gateway it not configured17:26
netcomnetIf I run all this is all my config gone?17:27
nowenno17:27
netcomnetOk, did that.  Now started up server.  Now doing AD self registration.  What is registration code and where do I get it17:32
nowenfrom the token17:32
nowenstill returns no data17:33
nowencan you ping www.google.com from the terminal?17:33
netcomnetI have the windows client and entered the IP in preferences.  Do I select new domain or preregister?  New domain asks for domain code and fails to get info.  Pre register stops at enter registration code17:34
nowenhere is the url the token is trying to access: http://70.183.25.34/wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=070183025034&CT=117:34
nowenis there something blocking port 80?17:34
netcomnetno, we scanned the server.  iptables off  port 80 is good17:35
netcomnetthat is the external IP17:36
netcomnetThat is not accessible from inside17:36
nowenwell, that would explain why you can't get to it, but not me ;)17:36
nowencan you ping www.google.com from the server?17:42
netcomnetchanged domain to internal IP and register is good now.17:45
netcomnetNow to test Cisco ASA17:45
nowencool17:45
netcomnetSo now I found a doc for vpn  3k  I have an ASA5520 same type device.  Setup Radius the same.  Should this be ok17:55
nowencool - needless to say, we can't doc every vpn device out there17:55
netcomnetnot a problem.  Just got the ASA configured.  It is similar.17:58
netcomnetCan the WikID server do the auth or do I need to pass thru to my microsoft IAS Server17:58
netcomnetI am getting Accesss Denied on the ASA to the WikID server.Radius configured correct IP address but the WikID still says Access Denied.18:49
nowendid you restart WiKID after adding the ASA as a network client?18:50
netcomnetyup18:50
nowengo to Configure Loggers18:51
netcomnetI know the doc says choose Radius server.  Would SDI also work?18:51
nowenwhat is SDI?18:51
nowenset com.wikidsystems and com.wikidsystems.wauth to debug18:52
netcomnetanother option like TACAS, LDA18:52
netcomnetLDAP18:52
nowenand addcom.wikidsystems.radius.log.DBSvrLogImpl and set it to debug as well18:52
nowendoubt it.  radius will work, just need to figure out what's going on18:52
nowenmake those logger changes and it will be clear18:53
*** autodata (cdcd1c11@gateway/web/freenode/ip.205.205.28.17) has joined #wikid18:56
autodatahi nick, how are you?18:56
nowengood18:56
autodataI lost my PIN number, any way to recover it?18:56
nowennope, you have to delete the domain and re-register18:57
autodataok, thanks18:57
autodatajust concern for the future, if my client forget his PIN, we will do the same way to delete the domain?18:58
nowenyes, and you will want to delete his device on the server18:58
autodataBut many users will use one domain, right?18:59
nowencorrect19:00
netcomnetSo I get a accept and then an deny19:08
netcomnetCan I paste a screenprint here?19:08
nowennetcomnet: use pastebin.com19:08
nowenjust paste the text into pastebin and submit, then post the new url here19:09
netcomnethttp://pastebin.com/ncZM8pGd19:11
nowenwhy is it trying twice?  if the one-time passcode is submitted twice, the 2nd will always fail :)19:11
netcomnetI do not know19:12
nowenhmm  - check the logs in the cisco19:13
netcomnetI got the login and enter username/passcode and enter19:13
netcomnetthe cisco logs show nothing even in debug19:13
netcomnetwhich is odd19:13
nowenthat can't be good19:16
netcomnetI forced some data, it says WikID Server not accessible19:24
netcomnetI can ping it from the Firewall ok19:24
netcomnetport 1812 on a scan does not respond19:24
nowenping is blocked by the firewall/19:24
netcomnetno19:24
nowenthe requests are clearly getting to the server19:25
netcomnetconnection is like this19:25
netcomnetFirewall >>Cisco switch no ACL's then WikID Server19:25
nowenthere is a fw on the wikid server19:25
netcomnetdisabled19:25
nowenthere are radius requests getting to the WiKID server - the logs show it19:25
nowenwhat do the logs show on the Cisco?19:26
netcomnet6May 16 201212:19:27113014AAA authentication server not accessible : server =  192.168.28.28 : user = sroman19:27
netcomnetThis is port 1812 correct?19:38
netcomnetTCP or UDP?19:38
nowencorrect - UDP19:38
netcomnetNetstat shows 1812 open19:38
netcomnetBut the Firewall says not accessible19:39
netcomnetThe are even on the same switch so no latency19:39
nowenare you asking if port 1812 is open on WiKID?19:39
netcomnetno I am saying it is open19:39
netcomnetudp19:40
netcomnetBut the FW seems to fail when trying to auth the user19:40
netcomnetIs the accounting port required?19:40
nowenahh so that is why it is trying twice?19:40
nowenno19:40
*** marcel_ (50417948@gateway/web/freenode/ip.80.65.121.72) has joined #wikid19:48
nowenwelcome marcel_19:49
marcel_hi there, if have visite the wikid website and have a question. hopefully you can help me. sorry for my bad english.19:49
nowenno problem, sorry for my bad... everything else ;)19:49
marcel_my situation is: I have a server in the datacenter and would like to run vm's on it. So I'm thinking to install wikid on the host for VPN connection from client PC and client smartphones to the server.19:51
marcel_After connection establishment the user get a page with the webservices which are for her of him accessible.19:51
nowenok19:51
marcel_and he/she could login to the desired webservices. the webservices are running in vm's. does that work because I read somehere the server needs 2 ethernetcards.19:52
marcel_hi nowen19:52
nowenwe recommend two ethernet cards, but it isn't required - depends on the setup19:53
nowendo you do authentication at the VPN or at the webservices?19:53
marcel_at VPN, but after that the user has to use a username and pw for each webservices (only 2 webservices) and probably something like a rsync share for backup data on pc's to server location.19:56
nowenand where do you want them to use two-factor auth?19:59
marcel_A user first makes an vpn connection and uses wikid. After access granted, the user has access to some links like a link to webmail or rsync share. User can click on the desired link to get access after typed username  and pw.20:01
nowenok - so WiKID and the VPN need to communicate. that's very standard20:02
*** autodata has quit (Ping timeout: 245 seconds)20:05
marcel_the idea is that there can be no access to webmail or rsync share without first an vpn connection. Must be not really difficult I think. Because I work with other people together, I think wikid is easy admin to give people access and also revoke access when needed.20:07
netcomnetsince this keeps trying on port 1812 udp.  The firewall just will not connect on that port.  Is there a spot I can see the udp port being used?20:07
nowennetcomnet: on the WiKID server terminal, run 'tcpdump port radius'20:08
nowenthat will show you the traffic20:08
marcel_If I install wikid on the dedicated server and use ldap, then users can connect to the webmail vm and rsync share vm. Is that idea correct?20:09
nowenmarcel_: I recommend radius if you are going to use the Enterprise version.  If you're going Community, ldap might work.20:10
marcel_community version is 3 users? enterprise version as much as you almost want? Can I use freeradius for Ubuntu 12.04 in stead of radius?20:12
nowenmarcel_: http://www.wikidsystems.com/community-version/front-page/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release/?searchterm=what%20is%20the%20difference20:13
netcomnetIt shows nothing but Acecss request.  Nothing going back to the Firewall20:13
nowenhmm20:16
marcel_Nowen, you are fast. I checked the url. Radius is included, perfect. So installing Enterprise version (with 25 users for 3 years) so described on the wikid website and that's it? And I can also us it from the smartphone. That's easy!!20:18
nowenmarcel_: ;) we aim to please20:18
nowenhere's my recommendation: standardize on radius, and then see how your can all your services to support radius20:19
marcel_I get lazy because of this. By the way, in the meantime I was finding out what the software and hardware requirements are for the Enterprise version. Can you please help me to find that webpage again?20:20
nowen1 1 gig of ram, 100gig of hd20:21
nowennot much20:21
marcel_sorry Nowen, I found it. bad news again, ;-) The require software will also be installed.20:22
nowenno problem20:22
nowennetcomnet: can you get to the cisco from WiKID?20:23
marcel_Nowen, thx for the info. Over here in the Netherlands it is almost 22:30 hours. I can not wait to do the test the anonimous client and to work out the global design included wikid. Cheers Marcel20:25
nowencheers!20:25
*** marcel_ has quit (Quit: Page closed)20:25
nowennetcomnet: what does tcpdump show?20:46
*** nowen has quit (Quit: Leaving.)22:08
joevano /n22:19
*** sideone has quit ()22:31

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!