Monday, 2012-08-13

*** Livemark (50a99e82@gateway/web/freenode/ip.80.169.158.130) has joined #wikid09:31
LivemarkHello09:32
LivemarkI need some help getting Wikid working?09:32
LivemarkAnyone there?09:33
Livemarkhello?10:19
*** Livemark has quit (Quit: Page closed)10:22
*** Mark___ (50a99e82@gateway/web/freenode/ip.80.169.158.130) has joined #wikid11:09
Mark___hello - anyone there?11:09
joevanoyep12:02
Mark___hello12:03
joevanoso what seems to be the issue... ill see if I can help out12:03
Mark___I'm trying to get the Wikid 2FA working with a Windows 7 computer connected to a port on a cisco switch12:04
Mark___I'm almost there - I think I just need help with a final part of the puzzle12:05
Mark___I am using NPS12:05
joevanoyour going to have to wait for 'nowen' on that one.. I've got no experience on that12:05
Mark___okay12:05
Mark___do you think nowen will be around today?12:06
joevanohe usually shows up between 9 and 10:30... (in 1 to 1.5 hours)12:06
joevanoI think he may... i think he was out on vacation lately but I get the feeling from his twitter that things are getting back to normal12:07
Mark___okay - forgetting NPS12:07
Mark___Have you any experience of using 802.1x on a windows computer and Wikid12:08
joevanonope... we use Wikid for 2FA on our VPN appliance12:09
Mark___okay12:09
Mark___Any idea why I'm getting this: <20> Access-Challenge(11) LEN=186 10.1.10.6:60122 PACKET SUCCESSFULLY SENT12:10
Mark___after the log says:12:10
Mark___Access granted for ddb-europe\marklong, domain code: 010001010009 client: /10.1.10.612:10
Mark___if it's granted me access, why is it sending another challenge12:11
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid12:22
nowenMark___:12:25
nowengood morning12:25
nowenthe  PACKET SUCCESSFULLY SENT message doesn't mean anything except just that, the packets were sent12:26
Mark___hi12:26
Mark___okay - i'll explain what I'm doing...12:26
Mark___I have a windows 7 computer connected to a port on a cisco switch12:27
Mark___the switch is set up for 801.1x on the port12:27
Mark___the radius server is windows nps12:27
Mark___and it is set to forward radius messages to the wikid server12:28
Mark___if I set the nps server to deal with the radius requests itself, without the wikid server based on membership of an active directory group for example12:28
Mark___then the port on the cisco switch allows me access to the network12:29
Mark___if I forward the request to the wikid radius server then I do not get access12:29
Mark___the cisco switch says the radius server is not respoding12:29
Mark___however, in the wikid logs, I can see that a conversation has started12:30
nowendo you see the request getting back to the NPS?12:30
Mark___no - there's nothing in the NPS logs12:31
Mark___not even the request being forwarded on12:31
Mark___but I know it is being forwarded on because i can see the request in the nps log12:32
Mark___sorry - the wikid log12:32
nowenyeah, sounds like NPS is dropping it somehow12:33
nowenNPS is using port 1812, correct?12:34
Mark___is it normal for the wikid log to say access-challenge packet sent after it says that access has been given12:34
Mark___yes - 181212:34
nowenyes12:34
nowendo you have you wikid logs set to debug?12:36
Mark___i have apolicy set in connection request policies for the forwarding to wikid12:37
Mark___yes - debug12:37
nowenand you added the radius logger?12:37
Mark___should I also have a "network policy" set?12:37
nowenin nps? yes, I think so12:37
Mark___OKay - I don't have a network policy.  I'm not sure what it would need to say.  I followed the document on the wikid website12:38
Mark___and it didn;t mention a network policy12:39
nowensee "Adding a Network Policy" on http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps12:40
Mark___I set everything to debug in the configure loggers section12:40
Mark___that's the doc12:40
Mark___I think the problem might be that my windows 7 computer doesn;t understand that access has been granted12:42
nowenI think you need to add a network policy to nps12:43
Mark___okay - any idea how I tie that in to the wikid server though?  What does the rule need to say?12:44
Mark___If you get access aloowed from wikid then allow access to the network?12:44
nowenin the example on that page, we used the IP address of the VPN server12:44
nowenit's more like: "which requests get sent to wikid instead of processed locally"12:45
Mark___Okay - so I have that already.  That's under connection policies, and I've said "if you get a request from this radius client (the cisco switch) then forward to wikid12:46
Mark___and that works - the requests get forwarded.  My understanding is that when a response comes back it is automatically sent to the client that requested access12:46
Mark___without any further rules12:46
nowenhmm12:47
nowenand you set the user to use NPS?12:47
nowenI assume so, since it worked without wikid12:47
Mark___on windows 7, when it says "you need to enter additional info to get access" it asks for a username and password12:47
Mark___what username and password should I be using?12:48
Mark___I have been using the userid of the user setup on the wikid server, and the OTP12:48
nowenyour AD username, which should also be your WiKID username and the the OTP12:48
Mark___The wikid server logs say Access granted for ddb-europe\marklong, domain code: 010001010009 client: /10.1.10.612:49
Mark___which indicates to me that it is correct12:49
nowenseems likely12:49
Mark___however, I've just tested typing a random username and password, and it still says access-granted12:50
nowenon WiKID?12:51
nowenis the time correct on the logs?12:51
Mark___yes12:51
Mark___yes12:52
nowenI mean, those are new entries in the logs12:52
Mark___yes - it mentions the random username I used12:53
nowencan you post the logs to pastebin.org for me to see?12:53
nowendo you see  "Access-Request by xxxxx succeeded"?12:56
nowenbrb, coffee time!12:56
Mark___wikid_nowen12:56
Mark___no access-request by xxx succeeded messages12:57
Mark___pasted to wikid_nowen12:57
Mark___Back in 20 mins12:58
nowenhmm, not sure what pasted to wikid_nowen means ;)13:09
Mark___http://pastebin.com/zj67SmBh13:17
Mark___sorry - not used it before13:18
Mark___hold on - it has expired13:18
nowennp ;)13:18
Mark___http://pastebin.com/kYUZUiSd13:19
nowendo you have com.wikidsystems.radius.log.DBSvrLogImpl enabled and set to debug in the Configure loggers page?13:21
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests13:28
nowensomething odd is going on here13:29
Mark___http://pastebin.com/sTHPHTaa13:30
nowenhmm13:31
nowenok13:31
noweni wonder if the Access-Challenge means that something is not right.  It could be trying to process a challenge-response instead of an OTP13:32
Mark___maybe it just doesn't work with windows 802.1x or cisco switches13:34
nowenit's possible, but it should13:35
nowenit's recognizing that it is an eapmd5 request13:35
nowencan you re-run the auth, starting with an OTP request?13:35
nowenand re-post it for me?13:36
Mark___okay13:36
Mark___on the wondows computer, when it says "additional info is required" and prompts for a username and password, what should I type?13:36
nowenthe windows/wikid username and the WiKID OTP.13:37
*** Jim_ (d578dc04@gateway/web/freenode/ip.213.120.220.4) has joined #wikid13:37
Jim_hey13:38
Jim_anyone home?13:38
nowenhi13:38
Jim_hi nick13:38
nowenhi13:38
Jim_can you help me out please? I'm trying to logon to my new WiKID server over SSH and root/wikid doesn't seem to be working13:39
nowenis this the iso?13:39
Jim_yep13:39
Mark___http://pastebin.com/Ed7Yq1D713:40
nowenhmm13:40
nowenMark___: hmm, still not seeing "Issued passcode to device xxx"  can you set com.wikidsystems and com.wikidsystems.client.wClient and com.wikidsystems.server.wAuth to debug also and try again?13:42
nowenJim_: is this the latest iso?13:43
Jim_i downloaded this copy last week13:43
nowenand at the install prompt, you just hit enter?13:43
Jim_i think so13:44
nowenwell, the only thing I can think of is to re-install.  did you verify the md5sum of the download?13:45
Jim_not at the time13:45
Jim_it's cool, i'll just reinstall from the iso13:46
*** Jim_ has quit (Quit: Page closed)13:46
Mark___I have set to debug but I cannot see the individual logs to filter against13:54
nowenlook on the Configure Loggers page13:55
Mark___5 listed - all set to debug13:56
nowendo you have  Source set to None on the log page?13:56
Mark___no - source is set to one of the filters13:56
Mark___okay13:57
nowenok, try it with none13:57
Mark___now set to none13:57
Mark___pasting log13:57
Mark___http://pastebin.com/FMV19EJU13:58
nowenhmm14:00
nowenĀ Length: 10, Data: 0x0A010A0600000088 State (24), Length: 7, Data: 0x01DCD1BAEE EAP-Message Information: Error displaying EAP-Message: EAP Packet's physical size (36) doesn't match packet's stated length (23) <25>14:00
nowendid you check the box for "Request must contain the message authenticator attribute".14:01
nowenon NPS?14:01
Mark___yes14:02
nowenmaybe try unchecking it?14:03
Mark___same error14:05
nowenhmm14:06
Mark___do i need any additional software on the windows machine to get it working14:07
nowenno, I don't think so. It should only be between the cisco, nps and wikid14:07
nowenso, this is for a wifi connection?14:08
nowendoes the response die after the error about the stated packet length?14:09
Mark___no - wired14:09
Mark___the box on the computer pops up a couple more times14:10
Mark___then gives up and the port on the switch falls back to the guest vlan14:10
nowenso that seems to be the issue?14:11
Mark___yes - it should authorise the port via 802.1x and allow access to the specified vlan14:12
nowenhmm14:27
Mark___do i need to install any certificates on the windows PC?14:34
nowenwell, not for WiKID, but perhaps for eap?14:34
nowenI may have to set up an environment to test this, but I won't be able to mimic yours exactly14:47
Mark___okay - there's nothing special about my env.  Just windows 7 --> Cisco switch --> NPS --> Wikid14:48
nowenwhat are the radius options on the cisco switch?  eap, leap, peap?14:55
Mark___I think that part of it comes from the windows box15:26
Mark___the cisco switch just passes the requst on15:26
nowenmakes sense, what are the options on the win7 box?15:27
Mark___is there a way I can test the windows side of things against wikid?15:27
nowenyou can try pointing the cisco directly to WiKID15:27
Mark___but then I won;t have an interface to input the OTP15:28
nowen?15:28
Mark___but I get the same error15:29
Mark___I have told the cisco switch to use wikid as the radius server instead onf the NPS15:29
nowenah - that's what i meant15:29
Mark___sorry - I thought you meant to take the windows 7 machine out of the equation15:30
nowen;)15:30
Mark___is there a way to test wikid from the windows box, taking the nps and switch out of the equation?15:30
nowenI'm wondering if there is a bug with one our eap implementations.  so I wanted to see if we could test some other options15:30
nowennot really, as it isn't a radius client.   You can test to make sure that you have installed the server correctly via the example.jsp page15:31
Mark___On windows, I am using PEAP15:33
Mark___on the next box it says authentication method: secured password(EAP-MSCHAP v2)15:34
Mark___the other option is smart card or certificate15:35
nowenI'm sorry - back up a bit.  are you setting up a new network connection or VPN?15:45
Mark___new connection15:46
nowenand under Choose a Connection option, which do you choose?15:46
Mark___Sorry - I mean it's on the existing NIC connection.  If I enable the "wired auto config" service, I get 802.1x options on the NIC15:47
nowenhmm, I don't see that15:51
Mark___You don't see the service?15:51
nowenno15:52
nowenis it under Local Are Connections?15:53
*** Jim (d578dc04@gateway/web/freenode/ip.213.120.220.4) has joined #wikid15:53
*** Jim is now known as Guest8479715:53
Guest84797Hi15:53
nowenHi, any luck?15:53
Guest84797yeah no probs, all set up now15:53
Guest84797well almost, i'm trying to set up for connecting to my new CAG15:54
Guest84797but the access interface is not prompting for a one time code15:54
nowenjust put it into the password box15:55
Guest84797where does my AD password go then?15:55
nowenno where! ;)  AD will do the authorization based on the username and then proxy the creds to WiKID for authentication15:58
Mark___hi - are you talking to me?16:00
nowenMark___: no, sorry, to Guest8479716:01
Guest84797my CAG is a RADIUS client of the ADDS16:01
nowenwhat is ADDS?16:01
Guest84797WiKID is its own RADIUS server and the CAG is a client of that16:01
Guest84797sorry, active directory16:01
nowenGuest84797: typically, the way this is setup is CAG >> AD/NPS>> WiKID16:02
Guest84797so the WiKID server is a RADIUS client of AD/NPS?16:02
nowenother way around.  the NPS is client to WiKID16:03
Guest84797so my cag stays a RADIUS client of NPS/AD?16:04
nowenyes16:04
Guest84797the docs describe it differently is all, I did wonder16:04
nowenwhich docs?16:04
Guest84797the ones on your site16:04
nowencheck out this one: http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps16:05
Guest84797k dude16:05
Guest84797sec16:05
Guest84797ok that makes a lot more sense, i was looking here: http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-a-citrix-access-gateway16:07
nowenyeah, we need to have a better guide to our guides16:07
Guest84797it's ok, i got a domain set up and got my test client to communicate using that16:08
Guest84797so half the job done there16:08
Guest84797i did wonder how it was expected to know about the account16:08
Guest84797anyway, brb16:08
nowenok16:08
Guest84797so if my users don't have to enter an AD password, how does this satisfy the requirements to be a two factor system?16:10
Guest84797if they can access from a non-domain joined machine, which is my intention16:10
Guest84797I can add that separately to Xenapp I guess, but had hoped to keep the extra authentication looking at seamless as possible16:11
nowenthe two factors are knowledge of the PIN and possession of the (private key embedded in) the software token16:11
Guest84797I'd have to use the locked down software token16:11
nowenI would argue that it is more secure to not use your LAN password outside of the LAN16:12
nowenis this for PCI?16:12
Guest84797so would I! I'm just thinking from a PCI complaince point of view16:12
Guest84797yeah, ah, you beat me to it16:12
nowenwe have a ton of PCI customers16:12
Guest84797and they have this system in place?16:12
nowenoh yeah, we see a lot of citrix for pci too16:13
Guest84797our current PCI "compliant" solution is utter shit, so I'd actually be interested in introducing WiKID instead16:13
nowenI hope we would be better ;)16:13
Guest84797it can't be any worse, the second factor can be circumvented too easily16:13
Guest84797yep, this sounds like it's a go-er pal, let me get back to you in a few when I've set the RADIUS server up again.16:14
nowenok16:14
Mark___I'm now trying to get this to work with a juniper vpn16:29
Mark___and still no luck16:30
nowenMark___: ok, good idea16:30
nowensame error?16:30
Mark___no - it says access-rejected16:30
nowenis the user enabled still?16:30
Mark___http://pastebin.com/TLExv4bJ16:31
nowencheck your user, they often get disabled during testing16:32
Mark___checked - it's enabled16:34
Mark___aaarrrrggggghhhhh16:34
nowen?16:34
Mark___Sorry - any other ideas why it's not working16:35
nowenlet's make sure it is working without radius: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly16:36
nowenthe example.jsp page will allow you to login without radius16:36
Guest84797Hi Nick16:38
nowenhi16:38
Guest84797What's the "Device Domain Name" on Domain Setup in WiKID?16:38
nowenthat is what shows up on the token client16:39
Guest84797Oh so I can call it anything?16:39
nowenyes, but know that your users may eventually get more than one domain,  though it is unlikely16:40
Guest84797No worries16:40
Guest84797ah shit, Nick how can I change the time on the WiKID server manually? I don't have an NTP server to synch to17:01
nowenthe date command17:02
Guest84797cheers17:02
nowendate 0813130217:02
nowenmmddtttt17:02
Guest84797do i have to do anything special with certificates?17:08
nowendid you create the intermediate ca and localhost  cert?17:08
Guest84797yes17:08
nowenthat's it for wikid17:09
Guest84797ok cool17:09
Guest84797I'm getting a lot of packet dropped - message authenticator is incorrect errors, any idea what these indicate?17:13
nowenhmm17:13
nowennot sure.17:13
nowenbrb - gotta grab some lunch17:14
nowenback17:24
Guest84797hey there17:25
Guest84797just working through some troubleshooting, think im getting closer now17:26
nowenknow that sometimes users get disabled during testing, typically for excessive bad passcode attempts17:32
Guest84797What I'm getting currently is that the RADIUS server is not responding to the proxy17:34
nowendid you restart WiKID after adding it as a network client?17:34
Guest84797yeah, let me do it again i have made a couple of changes.17:35
nowenthe ip address is the important piece. if that is wrong, no go17:36
Guest84797which IP address?17:36
nowenthe ip address of the radius proxy17:37
Guest84797that's what I have set up as the Network client, just to confirm?17:38
nowenyes17:38
Guest84797ok that's correct17:38
nowenyou can turn on radius debugging: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests17:38
Guest84797Aaah, ok got it lol17:41
Guest84797working now, was my fault I didn't format the username correctly17:41
Guest84797stupid error, been here too long17:41
Guest84797tired17:42
nowen;)17:42
Guest84797gave me a chance to go over some stuff and correct it as I went, so good enough for me17:42
Guest84797bah my boss just went home 5 mins ago as well17:42
nowenoh well, you can always buy tomorrow ;)17:45
Guest84797lol yeah17:49
Guest84797just got to work a couple of bugs out and I'll get a demo on for tomorrow17:50
Guest84797thanks for your help today Nick, i gotta go before they throw me out of here17:51
nowenno problem17:51
nowenlater17:51
*** Guest84797 has quit (Quit: Page closed)17:59
*** nowen has quit (Quit: Leaving.)22:27

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!