Tuesday, 2012-08-14

*** Mark___ has quit (Quit: Page closed)08:36
*** Marky_ (50a99e82@gateway/web/freenode/ip.80.169.158.130) has joined #wikid09:57
Marky_Hello?09:58
joevanohi13:44
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid14:03
*** Jim_ (d578dc04@gateway/web/freenode/ip.213.120.220.4) has joined #wikid15:04
Jim_Hey Nick15:04
nowenHI15:07
Jim_hey dude15:08
Jim_I got a demo together for my boss, worked out well, thanks for the help yesterday15:08
nowengreat news!15:08
Jim_was wondering about licensing costs for initially around 200 seats15:09
nowen$24/per seat per year15:10
nowenhttp://www.wikidsystems.com/learn-more/financial15:10
Jim_can't argue with that15:11
nowenno, it's too low.  buy now before we raise it ;)15:11
Jim_haha15:15
Jim_totally15:15
*** Jim_ has quit (Quit: Page closed)15:42
*** nowen has quit (Quit: Leaving.)17:37
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid19:47
*** dystonic (~dystonic@199.255.83.50) has joined #wikid20:51
dystonicEllo20:51
nowenhowdy20:51
dystonicHow goes Nick?20:51
nowengood!20:51
dystonicawesome.  :)  I had a question around using wikid with capistrano20:52
dystonic(or knife, if you speak chef.)20:52
nowenI don't speak either :(20:52
dystonicit's a dual authentication issue.20:52
dystonicwikid = one time passcode.20:52
dystonicchef/cap are datacenter automation/deployment tools that can run as SUDO, with the same credential twice = but that doesn't work with wikid, obviously.20:53
nowenahh20:53
dystonic(so you enter your cred, but it then goes to use the cred to priv esc and no go.)20:53
dystonicDo you know of any way around it?  I don't want to give my admins local accounts if it's possibly avoidable, and what they've been doing is using a shared account to deploy, which my QSA would not love.20:53
dystoniccentos boxes.20:54
nowencan you create a 'jump' box that has 2fa on it from which you can run capistrano commands using keys?20:54
dystonickinda the same shared account issue there.20:55
nowenhmm, i guess not if you have to run sudo on each box20:55
dystonicyeah.  they have to enter a credential to use cap, they could use a keyed acconunt, but it'd have to be a local account either way20:55
dystonicpci says no shared, so that leaves me with individual accounts or a shared credential which is nogo20:55
nowenwe have a ruby package for the api, so you could require 2fa to run capistrano20:56
dystonicnod.  or do a (ugh) sudoers all all nopass.20:58
nowenit's a questions I bet we see a lot more20:58
dystonicyeah.  I love me some twofactor, I just have to keep my users happy.20:58
dystonici don't want my admins to not have to think before they sudo, so it's a catch 22.20:58
nowenyeah20:59
dystonicre: ruby 2factor, in terms of using it to access the application?20:59
nowennot thinking while running commands can be bad20:59
dystonicso no win here -- either sudoers all:all nopass (hey! maybe a SA_username (security admin) account for remote administration only.21:00
dystonicwhich is a secondary account with that elevated credential, but takes away my local accounts and allows me to segregate out normal admin tasks versus the remote administration.21:01
nowenyeah21:01
dystonici could probably lock down where that account can log in from.21:01
nowenright, only from the cap box21:01
dystonicso no individual accounts or local accounts, remote authentication works for datacenter automation, but they don't go running around as that.21:01
dystonicI"ll pitch it.21:01
dystonic:)21:01
nowenlet me know!21:02
dystoniclol.  Thank you!21:02
dystonictalking stuff through = goodtimes.21:02
nowenindeed!21:02
dystonicoh.  is there doc on assigning multiple tokens ot the same userid?21:05
dystonici know you mentioned there was an api.21:05
nowennot really, you just need to set up the example.jsp page: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly21:06
nowenthen look for "Add additional device to existing userid WITHOUT passcode"21:07
dystonick, I"ll play with it.21:07
dystonici need to deploy it at home so I've got something to muck about with.21:07
nowenthe ADRegister.jsp can do it too21:08
nowenyes, I encourage much mucking21:08
dystoniccool.  I'll play.  I'll circle back.  :)21:09
dystonicThanks Nick.  Till next time - gotta go harass folks.21:09
dystonicttys.  :)21:09
nowennp21:09
*** dystonic has parted #wikid (None)21:09
*** vladdy_ (~vladdy@194.242.5.47) has joined #wikid22:16
*** vladdy has quit (Read error: Connection reset by peer)22:18
*** nowen has quit (Quit: Leaving.)22:28

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!