Wednesday, 2012-07-18

*** progma has quit (*.net *.split)01:40
*** vladdy has quit (*.net *.split)01:40
*** joevano has quit (*.net *.split)01:40
*** vladdy (~vladdy@194.242.5.47) has joined #wikid01:46
*** joevano (~joevano@bzflag/developer/JoeVano) has joined #wikid01:46
*** progma (~progma@98-129-220-119.slicehost.net) has joined #wikid01:46
*** atomey (d8037522@gateway/web/freenode/ip.216.3.117.34) has joined #wikid15:06
atomeyAnyone around?15:07
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid15:33
*** nowen has quit (Remote host closed the connection)15:35
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid15:37
nowenAtomey, got a question?15:40
atomeyyeah i e-mailed the other day about my setup15:41
atomeyi was having an accessdenied exception error in my radius log15:41
atomeyi'm able to generate a passcode now15:42
atomeybut i can't authenticate with it15:42
atomeyi'm trying to setup two-factor authentication for a windows 2003 VPN15:42
atomeyright now when i attempt to connect to my Windows VPN, which is configured to use radius through wikid, it will basically say that the server didn't respond in a timely fashion15:43
atomeybut after having connected, there is an entry in the radius.log on the wikid server15:43
atomeythat says pap bombed with accessrejectexception: access denied15:43
nowenAnything in the wikid logs?15:43
atomeyi enabled debugging for radius15:43
atomeyyeah i didn't see thos naserrors you pointed to15:44
atomeyand it does show the OTP (passcode right?) being generated15:44
atomeyin the log15:44
nowenHmm15:45
atomeysimply says access denied for user adam15:45
atomeyyou said this is typically because the shared secret is wrong15:45
atomeyi've triple-checked it and retyped it15:45
atomeyi'm using the same shared secret password for everything for the sake of getting things working15:45
atomey<44> Access-Request(1) LEN=197 192.168.100.81:2593 Access-Request by adam Failed: AccessRejectException: Access Denied15:45
nowenAre seeing the otp as a number now?15:45
atomeyyeah15:45
atomeyit's a 6 digit number that expires in 60 seconds15:46
atomeyand i should be using that to authenticate with the VPN, using the same username i'm assuming15:46
nowenI mean in the logs15:46
atomeyoh15:46
nowenYes15:46
atomeyi see this in the logs: Issued passcode to device -914044781132469809415:47
atomeyis that what you're referring to?15:47
atomeyi don't see the actual number for the passcode in the log15:48
nowenNo, remember how the logs said "passcode is not a number"15:48
atomeyoh yeah, in the radius log15:48
nowenYeah15:49
atomeyi do see something there15:49
atomeyRADIUS client supplied passcode is and then it's a bunch of gibberish15:49
atomeylike ^^^X U+Ff8283515:49
nowenYeah, that should be the 6 digit otp15:49
atomeyso it should be actually displaying the 6 digit otp as plaintext in the log?15:50
nowenIf debug isenabled15:50
nowenYes15:50
atomeyhmm let me see15:50
atomeyyou know what i think i had it set but it was removed15:51
nowenLogging will revert on a restart unless you tell it not to15:53
atomeyok that makes sense since i've restarted wikid a few times, i'm going to try to get the same passcode in the log as in the token client15:53
nowenYeah, that's what's odd.  If it isn't the shared secret, i dont know what it is15:55
atomeyand you're referring to the shared secret for the network client, correct?15:56
atomeyi have com.wikidsystems and com.wikidsystems.radius.log.DBSvrLogImpl on debug, should i be able to see the OTP now in the radius log?15:58
atomeyi saw something different in the log as the passcode when generating a new one15:58
atomeybut it wasn't the plaintext number15:58
nowenSet the other loggers to debug too16:00
atomeyok16:00
atomeyi mean at this point it seems like my Windows VPN is somehow modifying the passcode before it actually gets to the WiKID server, does that seem inaccurate?16:04
atomeythe loggs are showing the same kind of passcode, like the Web logger shows this16:05
nowenIt is possible, i suppose16:05
atomeyRADIUS client supplied passcode is ??F? ?U? ?s*???%16:05
atomeybut i've configured it to not use encryption, PAP, etc16:06
*** nowen has quit (Remote host closed the connection)16:07
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid16:08
nowenErp16:08
atomeydefinitely looks like a problem on the windows side, ive got some errors there i need to look at16:08
atomey"An invalid response was received from radius server <WIKID IP here> authenticator does not match in packet from radius server16:08
nowenIs there a checkbox for message autheb16:09
nowenAuthenticator?16:09
atomeyin the VPN connect dialogue? i can look16:09
nowenOn nps16:09
atomeyoh, i'm using IAS but i'll check16:09
atomeyyes there is16:10
atomeylet's see16:10
atomeythere's a request must contain message authenticator check box for the radius client configured on the windows IAS service16:12
atomeyi enabled that but i still seem to have the same problem16:12
nowenHmm16:12
atomeyshould i enable always use message authenticator16:13
atomeyfor the radius server authentication in IAS?16:13
atomeyi'll try it16:13
*** nowen has quit (Remote host closed the connection)16:14
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid16:15
atomeyholy shit it worked16:19
atomeyi can see the passcode in the log now too16:20
nowenWoot16:21
nowenWhat was it?16:21
atomeyyou know maybe it was the secret for the servers? i retyped my secret password for the authentication on the server16:21
atomeybut i'm really confused by the secrets because i have them for the network clients16:22
atomeybut also for the radius server itself?16:22
atomeylike when you use IAS you select your authentication provider and accounting provider16:22
atomeyunder the server configuration for authentcation i typed secret and made it always use message authenticator16:23
atomeythat seemed to make it work16:23
nowenOk, good to kn otp16:23
*** nowen has quit (Remote host closed the connection)16:24
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid16:25
atomeynick thanks for your help i'm gonna play around with it some more and see if this is what we want16:26
nowenOk, later!16:27
atomeybye!16:27
*** atomey has quit (Quit: Page closed)16:27
*** nowen has quit (Remote host closed the connection)16:54
*** nowen (~androirc@mbd2436d0.tmodns.net) has joined #wikid17:13
*** nowen has quit (Remote host closed the connection)17:27
*** GregM (42bab9be@gateway/web/freenode/ip.66.186.185.190) has joined #wikid19:05
GregMHello19:05
joevanohi19:07
GregMHey Joe, do you know if I need to run yum update to keep the server up to date? How about the wikid system itself? Is there a command to update it?19:10
GregMsorry I work more with debian so I get a little nervy when working with RHEL based distros like CentOS19:12
joevanothe wikid system has an update facility in the software itself on the 'Configuration' tab19:16
joevanotells you if there are updates available, etc19:16
joevanoi work with debian/ubuntu as well, so the whole yum thing is a challenge for me as well19:17
joevanofor the server itself I believe it would be: su -c 'yum update'19:19
joevanobut don't quote me on that ;-)19:19
GregMok thanks, and do you guys recomend us to run the yum updates as needed, I just don't want to break the system19:20
joevanoI'm just an end user like you... nick stepped out a bit ago, not sure when/if he is coming back today19:20
joevanodid you look at the wikid documents online?19:20
GregMok sorry man19:21
GregMI though you were with the company19:21
joevanono problem, just trying to fill in and help out19:21
joevanoI really can't see any harm in doing a system update though... would hardly be secure if you couldn't do that19:23
GregMyeah I looked online for docs but didn't find anything that said do X then Y then Z to update19:24
joevanoyeah, me either19:24
GregMI just want to run apt-get update and have it be done lol, anyway thanks Joe, take care...19:25
joevanono problem... have a good one19:26
*** GregM has quit (Quit: Page closed)19:28

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!