Friday, 2012-08-17

*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid14:39
*** beckman68 (ada06522@gateway/web/freenode/ip.173.160.101.34) has joined #wikid14:51
nowenhowdy beckman6814:51
beckman68I am doing a PCI scan and it is failing do to SSL cert. 1 because it's "self signed" the other because it is expired. Any idea how to get around this or can I get a cert for am IP address, it does not have a domain name14:53
nowenIs this an internal scan?14:53
beckman68Good morning by the way.14:54
beckman68external14:54
nowenmorning ;)14:54
nowenDo you need the WiKIDAdmin to be exposed externally?  I recommend blocking it at your firewall14:54
beckman68I have even blocked HTTP and HTTPS from outside the network so I'm not sure how it is getting this info.14:55
nowenhmm, the tokens use port 80, so if you did that, the users should notice ;)14:55
beckman68What ports need to be opened?14:56
nowenexternally, just 8014:56
beckman68I'll need to look at that again then because I blocked it on the outside interface for inbound.14:57
nowenrun 'ifconfig' on the terminal to see what IPs are configured for the server. Could be there is more than the one you are expecting14:58
beckman68I'll check that now, thanks.14:59
beckman68OK the only port I have open is 80. So if that is open than I will need to have a cert because if you open a web page to the outside IP address it takes you to the HTTPS site. Anyway around that?15:32
nowenif you block 443, it will not redirect, right?15:33
beckman68OK I just blocked it and started another scan. This should take care of it, I think I had the order backwards.15:52
nowenok - and you can put your own cert in there if you want.  it is /opt/WiKID/conf/tomcatKeystore. it just needs to be usable by tomcat15:52
nowenbut not exposing your WiKID server admin interface to the internet is better ;)15:53
beckman68No I don't want access to the admin site at all so this should be blocking it fine now. The scan will be done soon.15:55
*** nowen has quit (Quit: Leaving.)21:51

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!