Friday, 2012-06-01

wtfnomweb proxy?00:14
wtfnomis it standard http protocol?00:14
wtfnomim assuming so since http requests redirect to 443?00:15
joevanowtfnom: redirect to 443?00:45
joevanoyou only need port 80 and it is just standard http requests00:46
nowen_awaywtfnom: yes, you can use apache or squid, for example, if you want that in your dmz instead of your WiKID server.01:05
*** nowen_away has quit (Quit: Leaving.)01:05
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid12:04
*** Troy (4b47ae94@gateway/web/freenode/ip.75.71.174.148) has joined #wikid14:30
nowenmorning Troy14:31
nowentesting a few things for you14:31
Troygood morning Nick14:31
Troyok.. so far we are still up this morning14:31
nowenhow many users do you have so far?14:32
Troylet me check.. hold a sec14:32
*** Mark_ (470e15da@gateway/web/freenode/ip.71.14.21.218) has joined #wikid14:34
Mark_Any updates?14:34
nowenmorning Mark_14:34
nowentesting some things for you14:35
Mark_good morning14:35
TroyWe are up to 150 users this morning14:35
Troywe expect that number to grow quite a bit the next few weeks14:35
Mark_Nick on the admin console14:53
Mark_is it all or nothing14:53
nowenMark_: what do you mean?14:53
Mark_on the admin console is there a way to limit the admin accounts?14:54
nowenoh, no, not really. you can create management consoles using the api with the example.jsp as a base14:54
Mark_ok14:54
laszlofACL's would be useful for the admin area, IMO14:56
laszlofthat being said, I'd rather you guys make more API functions :)14:57
nowenhehe14:57
*** Mark_ has quit (Ping timeout: 245 seconds)15:05
nowenTroy: email on the way - I have to head out for my daughter's 8th grade graduation.  email me if you need me ;)15:11
Troyok.. thank you15:12
nowengot to tar up the file.  your gateway bounced15:13
Troyok15:13
nowenso, just untar that file and drop it into /opt/WiKID/bin replacing the existing one15:14
*** nowen has quit (Quit: Leaving.)15:14
Troyok..15:14
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid15:17
nowenTroy:15:17
nowendownload the file from here: http://www.wikidsystems.com/webdemo/usogres15:17
nowenand drop it into /opt/WiKID/bin15:18
*** nowen has quit (Client Quit)15:19
*** Troy has quit (Ping timeout: 245 seconds)16:15
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid18:13
*** Troy_ (4b47ae94@gateway/web/freenode/ip.75.71.174.148) has joined #wikid19:10
Troy_@nowen - I just updated both servers with the new replication file, usogres and restarted19:20
Troy_so far so good19:20
nowenTroy_: ok  - good to know19:28
nowenwe will keep banging on it next week.  Let us do a bit more testing before you roll anything out, ok?19:29
Troy_i noticed the file was quite a bit smaller than the previous version19:29
Troy_ok.. let us know what you find19:30
nowenok - will do.  Gotta go guys!19:30
nowenhave a great weekend!19:31
*** nowen has quit (Quit: Leaving.)19:31
*** Troy_ has parted #wikid (None)19:37
*** SEJeff (~jeff__@209.160.81.1) has joined #wikid21:35
SEJeffAnyone around who can help with a wikid q?21:35
wtfnomhey21:55
wtfnomwhats the Q21:55
SEJeffI recently just rebooted the VM running my wikid server22:00
SEJeffwhich has ran for a year or two flawlessly22:00
*** wtfnom has quit ()22:00
*** wtfnom (~wtfnom@66.150.156.1) has joined #wikid22:00
wtfnomhey22:00
SEJeffNow when my users try to go to the ADRegister.jsp page to register their own new tokens, they get...22:00
SEJeffhttps://2fa.madisontyler.com/wikid/ADRegister/ADRegister2.jsp22:00
wtfnomyou started to finally write something as i left.22:00
SEJeffha22:00
SEJeff<SEJeff> I recently just rebooted the VM running my wikid server22:01
SEJeff<SEJeff> which has ran for a year or two flawlessly22:01
SEJeff* wtfnom has quit ()22:01
SEJeff* wtfnom (~wtfnom@66.150.156.1) has joined #wikid22:01
SEJeff<wtfnom> hey22:01
SEJeff<SEJeff> Now when my users try to go to the ADRegister.jsp page to register their own new tokens, they get...22:01
SEJeff<SEJeff> https://2fa.madisontyler.com/wikid/ADRegister/ADRegister2.jsp22:01
SEJeff<wtfnom> you started to finally write something as i left.22:01
SEJeff<SEJeff> ha22:01
SEJeffThere you go :)22:01
SEJeffGah, didn't mean to post the url22:01
SEJeffbut I think it is internal anyways22:01
wtfnomit isnt22:02
wtfnomttps://2fa.madisontyler.com/wikid/ADRegister/ADRegister2.jsp22:02
wtfnomThe wClient connection to the server was NOT successfully established22:02
wtfnomlol22:02
wtfnombut its irrelevant.22:02
wtfnomso is that error they receive?22:02
SEJeffYes22:02
SEJeffSo how do I troubleshoot that?22:03
wtfnomand all of a sudden it started to cause you problems?22:04
SEJeffAfter the vm was rebooted, yes22:04
wtfnomdid you update the wikid code, or the server modules?22:04
SEJeffI ran wikidctl start and users can get token22:04
SEJeff*s22:04
SEJeffI just rebooted the vm22:04
SEJeffand had to manually start wikid via wikidctl start22:04
wtfnomwhat os are you running22:05
SEJeffCentOS 522:05
SEJefffor the wikid vm22:05
wtfnomand do you have autoupdates enabled for centos?22:05
wtfnomdo a uname -a22:05
SEJeffNope22:05
wtfnomoh22:05
wtfnomhmm22:05
wtfnomsounds suspicious enough.22:05
SEJeff2.6.18-194.3.1.el5xen22:05
SEJeffI think this is a config or wikid problem22:05
SEJeffI just don't know how/where to troubleshoot it22:05
wtfnomhang on,  theres a debug page to hit up for some testing....  nick mentioned it to me once.22:06
SEJeffThanks22:06
SEJeffActually I just found wauth.log22:06
SEJefftailed it, hit that page, and got this: http://hastebin.com/sesuqarucu.vbs22:06
wtfnomah ha.22:07
wtfnomhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly22:07
wtfnomyou seen this one?22:07
SEJeffWell I can get tokens from it no problem22:07
SEJeffOh nice22:07
SEJeffI'll check that out22:07
wtfnomyeah buddy.22:07
wtfnomtry that out22:07
wtfnomsorry, i dont work for wikid22:08
wtfnomlol22:08
wtfnomjust another lost guy like yourself.22:08
wtfnombut that seems similar to your prob22:08
wtfnomgluck!22:08
SEJeffI appreciate it :)22:09
SEJeffThe wClient connection to the server was NOT successfully established22:09
SEJeffThats what example.jsp says22:09
SEJeffOh but it isn't setup right, let me try22:10
wtfnomyeah ;-)22:11
*** mark_ (470e15da@gateway/web/freenode/ip.71.14.21.218) has joined #wikid22:21
*** mark_ has quit (Ping timeout: 245 seconds)22:25
SEJeffwtfnom, nowen responded to an email and asked me to check the cert validity with keytool22:44
SEJeffsure enough, it is expired. Luckily, that is easy to re-create from the webui22:44
SEJeffUsing this page to troubleshoot: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid22:46
wtfnomcool23:25
wtfnomglad you figured it out.23:25
wtfnombtw, im assuming that the server test link would have eventually pointed you to the cert issue as well23:25
wtfnomif cert is expired then the server test is going to be expired as well23:25
wtfnombtw, why did you open 443 up to the internet?23:25
wtfnomseems like a possible exploit waiting to happen23:26
wtfnomnick was telling me only port 80 was req23:26
joevanoyeah, everything for wikid happens on 80 only23:26
SEJeffwtfnom, So users can register their tokens at starbucks23:27
SEJeffand not worry about them being compromised23:27
SEJeffvia open wifi23:27
SEJeffA sourcefire IPS sits in front of it though, so if it sees any malicious traffic, it will just drop the packets on the floor23:28
SEJeffAnd we'll know about it :)23:28
wtfnomyou went with sourcefire?23:32
wtfnomhehe23:32
wtfnomi guess i see why23:32
wtfnomthe entire ips market right now is pseudo lame.23:32
wtfnomwhy would you allow users to randomly register their tokens at starbucks though?23:33
SEJeffwtfnom, If our CEO gets a new laptop / phone and wants to vpn into work23:36
SEJeffWe hacked up that page though, so we get emails when users do that and can check to make sure it is legit23:36
SEJeffSo long as it is audited, which it is heavily... we don't mind23:36
SEJeffOh and secure23:36
SEJeffBut in IPS, you can't go wrong with snort aka sourcefire23:37
SEJeffI mean they were one of the first real IPSs out there23:37
wtfnomheh .. i think ISS/IBM might disagree with that comment :-P23:40
wtfnomyou headed over to blackhat this year?23:41
SEJeffVery likely23:41

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!