Thursday, 2012-09-13

*** Skelroy_afk is now known as Skelroy03:40
*** Skelroy is now known as Skelroy_afk05:26
*** Skelroy_afk is now known as Skelroy05:30
*** vladdy (~vladdy@194.242.5.47) has joined #wikid05:31
*** vladdy has quit (Quit: Get MacIrssi - http://www.sysctl.co.uk/projects/macirssi/)05:44
*** vladdy (~vladdy@194.242.5.47) has joined #wikid05:59
*** Skelroy is now known as Skelroy_afk08:24
*** donny (~joevano@c-71-193-108-171.hsd1.in.comcast.net) has joined #wikid11:37
*** donny has quit (Changing host)11:37
*** donny (~joevano@bzflag/developer/JoeVano) has joined #wikid11:37
*** joevano has quit (*.net *.split)11:42
*** Guest26394 has quit (Ping timeout: 245 seconds)11:52
*** donny has quit (Quit: leaving)11:58
*** joevano (~joevano@bzflag/developer/JoeVano) has joined #wikid12:00
*** joevano has quit (Client Quit)12:01
*** joevano (~joevano@bzflag/developer/JoeVano) has joined #wikid12:01
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid12:14
*** Skelroy_afk is now known as Skelroy13:57
*** troy_ (6b02a614@gateway/web/freenode/ip.107.2.166.20) has joined #wikid14:21
*** nowen has quit (Remote host closed the connection)16:04
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid16:06
*** nowen has quit (Remote host closed the connection)16:14
*** nowen (~nowen@adsl-98-66-183-205.asm.bellsouth.net) has joined #wikid16:15
*** mo (4084d7c2@gateway/web/freenode/ip.64.132.215.194) has joined #wikid18:22
mohi nick18:22
nowenhi18:22
*** mo is now known as Guest3559018:22
Guest35590i got another problme18:22
Guest35590:-(18:23
nowenwhat?18:23
Guest35590couple of weeks ago you helped me to upgrade wikid18:23
nowenyes18:23
Guest35590it worked for a while18:23
Guest35590but now i get this error 'url changed. please try again'18:23
nowenare you using mutual https authentication?18:24
Guest35590what is that?18:24
nowenif you put an URL in the 'Registered URL' box on the domain page, it sets it up18:24
nowenhttp://www.wikidsystems.com/learn-more/technology/mutual_authentication18:25
nowendo you have an url  in the 'Registered URL' box on the domain page?18:25
nowenif so, delete it and restart the token18:28
Guest35590yes18:28
nowenalso, I am able to add a domain to our token under android 4.0.418:29
Guest35590great i will ask teh user to retry... what carrier do you have for your android 4.0.418:30
nowent-mobile18:30
nowenperhaps you can get your hands on the phone yourself and see?18:31
Guest35590i did18:31
Guest35590but today am wokring form home18:31
nowenalso, you can try to add this domain: 88888888888 it is our test domain18:31
Guest35590ok when you say restart token do you mean server18:32
Guest35590or client18:32
nowenclient18:32
Guest35590i tried that... got same18:33
Guest35590error18:33
nowendid you recently add the url to the domain page?18:34
Guest35590i get this from pc's only18:34
Guest35590nope domain was there al the time even before updgarde18:34
nowenmutual https is only for pc tokens18:34
nowenwhat url was in it?18:34
Guest35590https://drgts.globetax.com18:35
nowendid the cert on that url change?18:35
Guest35590no18:36
nowenis this only your pc token?18:36
Guest35590no18:37
Guest35590all others dont work18:37
Guest35590however i can get pin from iphone18:37
nowenok - here is how mutual https auth works.  You put an https url in the registered url box.  The server grabs the cert and hashes it and stores the hash18:38
nowenwhen a pc token asks for an OTP, the hash is also sent to the token18:38
nowenbefore the user gets the OTP, the token goes to the url, grabs the cert and hashes it and compares it to the hash from the sever18:39
nowenservr18:39
nowenserver18:39
nowen;)18:39
nowenif they match, the OTP is presented, and the browser is launched18:39
nowenif they do not match, you get the error you got18:40
nowenso, if the cert didn't change, it is possible that there is a mitm attack against you18:40
nowenbut the cert looks ok to me18:41
nowenthe fact that it is all your PC users makes me think that it is a configuration error18:41
Guest35590it must be in that file that you have me go to usually18:42
Guest35590i forget what its called18:42
nowenhmm, I don't know what file you mean.  also, there really isn't a file involved here18:43
Guest35590if i remove the url form there it should work... but that is not working either18:46
nowenand you restarted the token client?19:07
nowenwhat is your domain identifier?19:07
Guest3559006413218223019:35
nowenok - works for me.19:35
nowentry putting the URL back in19:36
Guest35590i get same 'url changed. pelase tray again'19:37
nowenhmm, well something must have changed.  can you think of what it might have been?19:39
nowenwhen you browse to that site from your computer, do you get your cert?19:40
Guest35590we've upgraded our cag; but it was working after that; then we upgraded linux; worked after that; then we upgraded wikid; it worked after that for a while; then broke19:45
Guest35590so obviously a lot changed19:45
nowenyes19:46
Guest35590hoever, when i use my phone i get the pin19:46
nowenwhen you upgrade your CAG did you get a new cert for it?19:46
Guest35590its only conencting via a pc19:46
nowenthe smartphone tokens do not support mutual https19:46
nowenthat's why they are not affected19:47
nowenso, clearly the issue is the cert19:47
Guest35590can i turn that off and try19:48
nowenwhen you remove the url, you turn it off.19:50
nowenbut you might need to re-register the tokens.19:51
nowendid you cag get a new IP or domain name?  what is always drgts?19:51
Guest35590cag was upgraded but everything else remained the same espcially the cert19:55
nowenI wonder if you restart wikid if that would clear it out19:55
nowenmaybe the cert is cached in tomcat19:56
Guest35590the cert had no issues19:56
Guest35590already rebooted wikid too19:56
nowenbefore removing the url or after?19:56
Guest35590after19:57
nowentry registering a new token, mine is working19:58
Guest35590can i register different token on teh sam epc19:59
Guest35590same pc19:59
nowenyes, you just need to put it in a different folder.  You might have to create a WiKIDToken.wkd file in there too. it can just be an empty file20:00
Guest35590i use the no installer wikid20:01
nowenyes20:01
nowenhmm20:02
nowenok - I added your url to one of my servers and got the same error20:03
Guest35590interesting... works from my laptop20:03
Guest35590my desktop is on vpn let my try disconnecting vpn and try20:04
Guest35590from the desktop i get url changed20:05
nowenfrom the desktop on a new token?20:07
*** Guest35590 has quit (Ping timeout: 245 seconds)20:10
*** mo (d8390e7c@gateway/web/freenode/ip.216.57.14.124) has joined #wikid20:11
mohello20:11
nowenhi20:11
*** mo is now known as Guest2769320:11
Guest27693got disconnected20:12
Guest27693anyway it works from my laptop20:12
nowenand is that a new client?20:12
Guest27693no20:12
nowenhmm20:13
noweninteresting20:13
Guest27693yup... phone works... laptop works... PCs don't work20:18
nowentry adding the url back into the domain20:19
Guest27693same thign20:39
Guest27693what if the certificate changes?20:44
Guest27693i am about to upgrade one of our CAGs to v.5; this one requires a new cert20:44
Guest27693I will use a new cert on this one20:44
Guest27693should i change anything on wikid?20:45
nowenhold on a sec, doing some testing here20:47
nowenok - this may be a bug21:04
nowenit's possible we could fix it without you having to re-reg your customers. let me keep doing some testing21:04
Guest27693great21:10
nowennot sure though. something odd has definitely occured21:10
Guest27693i will stepping out; maybe we can try tomorrow; is this in the new version21:10
nowenwe'll be taking a look at, not sure if we'll have a fix tomorrow21:11
Guest27693is this on the new version of wikid because i plan on upgrading another cag21:14
Guest27693this one will change the certificate21:14
nowennot sure I understand the question21:14
Guest27693the issue you are seeing is this on the new version of wikid?21:15
nowenyes21:15
Guest27693ok21:15
nowenI'm going back through to older versions21:15
Guest27693i will upgrade my cag but not wikid21:15
Guest27693the cag has some issues and need to be upgraded21:16
*** troy_ has parted #wikid (None)21:19
Guest27693ok thanks21:21
*** nowen has quit (Quit: Leaving.)21:42
*** Guest27693 has quit (Quit: Page closed)22:30
*** entrans (be50c42c@gateway/web/freenode/ip.190.80.196.44) has joined #wikid22:33
entransHello all22:35
entransI hate to break in my first time to this IRC with a problem but here goes...22:35
entransI have a client who had Wikid Server running on a physical machine that bit the dust22:35
entransthe somehow copied it to a VMware instance but are having problems getting the service up22:36
entransI know that's not enough information to identify the problem but can you give me a clue on how to look for the problem (i.e. specific log files to pull and examine)?22:36
entransThanks!22:36
entransi'm reaching out to the client to give me what they can on the log files - right now i'm directing them to send me the messages file to see what shows up there22:49
entranslet me know if there's a wikid specific log file i should be looking for - thanks22:51
entransi'm waiting on the client to get back to me - this may take a while - i'll keep updating here in case someone becomes available to see how i'm progressing - thanks!22:58
entransjust for future reference what files would I look to backup on the wikid server so I could rebuild easily from scratch without re-entering all the site specific details?  Thanks!22:59
*** Skelroy is now known as Skelroy_afk23:00
entranswell the client has managed to get the server up but still have problems getting the web interface up something about a 403 error which tells me the web instance is not running - i'm waiting on more details23:16

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!