Tuesday, 2012-06-12

*** Roman__ has quit (Quit: Page closed)00:55
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid12:58
laszlofnowen: yeah, saw that article.. did you read the doc in there about the cpanel security policy plugins?13:03
laszlofshort answer, its completely undocumented13:04
laszlofand the "pluggable authentication" has been "in development" since 200813:04
nowenyeah, I glanced at the doc13:09
nowen"require a known IP address"13:09
nowenlol13:09
laszlofnot to mention I have to code in perl to make it work13:09
laszlofeither way, its something to look at when I get to that point13:09
laszloffunny no one mentioned it until now13:09
laszlofthe doc is dated 201013:10
nowenlol13:10
laszlofhowever, I've been pushing for this since at least that time, and never seen it13:10
laszlofincluding being in direct contact with their integration peoplee13:10
laszlofheh, i found your post on the cP forum. presumably when I originally told you about my plan to integrate cpanel with wikid13:13
laszlofhttp://forums.cpanel.net/f185/two-factor-authentication-admins-124141.html13:14
nowenHA13:14
nowenyes, and zero response13:15
laszlofyou dont have a cpanel partner tag13:15
laszlofthats why13:15
laszlofheh13:15
laszlofif I can ever gain access to my forum account again I planned on bumping all those 2FA threads13:15
nowendid you forgot your password?13:15
laszlofyes13:15
laszlofand its linked to my ASO email13:16
laszlofi use random passwords for everything13:16
laszloffor some reason that one wasnt in my password manager13:16
*** Bart_ (d57e804a@gateway/web/freenode/ip.213.126.128.74) has joined #wikid13:52
Bart_The Nabble forums are "over capacity" so it's essentially unavailable13:53
nowenoh13:54
Bart_But, I was wondering if I could store two different user keys on my iPhone13:54
nowenhmm13:54
laszlofi doubt it13:54
nowenI don't know.  it's possible on a system where you can store the keys in a different directory13:55
Bart_So did I (the doubting)13:55
nowenwhat's the use case?13:55
laszlofyeah, you cant do that on the iphone13:55
Bart_If there would be an option to select a differnt profile somewhere, it could be done.13:55
Bart_The case is that people are logging in with different "profiles". E.g. I can login as myself (Bart or as a Systems Administrator)13:56
nowenhmm, yeah, I was just wondering if two domains would work13:57
nowenbut I don't think so13:57
Bart_I tried that as well I believe (with a different IP, but ran into some trouble with somethng, can't remember clearly.13:57
Bart_Might be the radius server13:57
nowenyou can't use two domains for the same network client13:58
laszlofnowen: you guys still doing that meeting today?14:00
nowenyes, 2:0014:01
laszlofcool14:02
*** Bart_ has quit (Quit: Page closed)15:27
*** nowen has quit (Quit: Leaving.)16:57
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid20:01
laszlofnowen: how'd it go?20:09
nowengood, drafting you an email shortly20:10
laszlofcool20:10
laszlofgot your email. If I understand what you're saying, you're suggesting just posting to the HTTP admin interface for adding/removing domains?20:27
laszlofI've actually done this before to work around API limitations :)20:28
nowenyes - mainly to start simple and not make us into a bottleneck for you ;)20:28
laszlofyeah, thats totally understandable20:32
laszlofI should be able to build out a simple class to be able to handle that kind of thing20:32
laszlofthen just IP restrict the admin area to my server20:32
laszlofwhich, btw, you should build into wikid 4 :)20:33
laszlofhaving the ability to IP restrict admin logins would be useful20:33
nowenhmm, yeah, I assume this will be running on a box somewhere in the cloud20:33
laszlofyeah, I have a test server setup right now. The end box will obviously be firewalled and only allow external access for token clients20:33
laszlofI really wish the token clients authed on a separate port20:34
laszlofrather than 44320:34
nowentokens are on 8020:34
laszlofor 80, whatever20:34
laszlofhm, admin is on 44320:34
laszlofso I could technically restrict 443 to my network via firewall20:34
nowenyes.  you can easily change the admin port20:34
laszloffor some reason I thought tokens were on the same port as the admin20:35
nowenyou just can't rewrite the tokens do use a different port20:35
nowenI would restrict it to the localhost  and then connect via an ssh tunnel20:35
laszloffor the admin port?20:35
nowendepends on how you want to do it20:36
nowenI guess there is not much difference between ssh and ssl20:36
laszlofthe website/backend is going to be on a separate server from the wikid box20:36
laszlofthough, proxying the tokens through another server might be a good idea20:36
laszlofit would mask the real IP of the token box20:36
nowenyou can do that too20:37
laszlofi wouldnt want the token box open to any kind of potential ddos attack20:37
laszlofok. next thing, with the domain ID's. do those HAVE to be 12 digit numeric right now?20:38
nowenyes20:38
nowenbut we can give you a block20:38
laszlofright20:39
laszlofmight be worthwhile to have some kind of interface to allocate them dynamically.20:39
laszlofit'd have to be some kind of unused space though20:39
laszlofi suppose anything higher than 25500000000020:40
laszlofwont be usable space20:40
nowenyes20:40
laszlofcool. This gives me something to finish up the backend with. I'll get with you sometime soon to see what we can workout with the server codes. If its easier just to assign a block for now thats fine, I can store the acceptable range in a DB and assign them.20:43
nowenI just need to see what blocks are available20:44
laszlofdont need much to start with20:45
laszlofjust something for testing20:45
laszlofonce we go live you can give me like 100K of them or something :P20:45
nowenHA!20:46
nowenfine by me ;)20:46
laszlofand once all those are gone, we can do the happy dance20:46
nowenok - gotta run21:30
nowenlater peeps21:30
*** nowen has quit (Quit: Leaving.)21:30

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!