Thursday, 2012-10-18

*** Skelroy (~Skelroy@71-85-217-74.dhcp.stls.mo.charter.com) has joined #wikid02:43
*** Dacosta (750352da@gateway/web/freenode/ip.117.3.82.218) has joined #wikid06:44
DacostaHi joe,07:06
DacostaI cannot run WiKID client software on Mac OS X 10.807:06
DacostaHow we make the wikidctl auto start when the wikid server is restart?07:07
*** Dacosta has quit (Quit: Page closed)09:47
*** Dacosta (71a56292@gateway/web/freenode/ip.113.165.98.146) has joined #wikid10:40
Dacostahi all10:40
DacostaI cannot use wikid client on iOS, i always get invalid domain code10:41
joevanoDacosta: are you using the "Domain Identifier" for your domain on your WiKIDAdmin/domainAdmin.jsp page11:43
joevanoand is port 80 open to the server that wikid is instaled on?11:44
joevanoDacosta: if you want wikidctl to autostart: If you would like to avoid entering a passphrase each time, you can create a file called /etc/WiKID/security with one line: WAUTH_PASSPHRASE=yourpassphrase.11:47
joevanoDacosta: what kind of error do you get when trying to run the client on OSX 10.8? is it the one about not being from a trusted developer?11:49
joevanoif that is the case, you browse to the location of the downloaded file, right click on it and select open. You only need to do this once. after that your mac will trust it.11:51
joevanothis is part of 10.8s new more secure application model12:05
DacostaHi Joe12:50
Dacostathank you very much for your reply12:50
DacostaI download http://www.wikidsystems.com/webdemo/tokens/j2se/3.1.19-locked/wikidtoken-3.1.19-bundle-installer.jar for mac os12:50
Dacostai know the trusted developer and change it before installation wikid client12:51
Dacostafirstly, i install java on mac os12:52
Dacostathen when i double-click on wikidtoken-3.1.19-bundle-installer.jar, it only show the installer java on the doc and automaticaly disappear12:56
DacostaI run the wikid client ok on windows12:56
Dacostafor example, on windows i enter the server code like 192168001001 and it working properly12:58
*** nowen (~nowen@67.211.17.2) has joined #wikid12:58
Dacostathe same wifi network on iPhone, when i enter that server code, i get invalid code12:59
DacostaHi Mr. Nick12:59
nowenmorning12:59
nowenDacosta: are you using the Community Edition?13:00
Dacostayes13:00
nowenthe smart phone tokens are not supported13:00
nowenwe use a 3rd party encryption library on them13:01
nowenor are you saying the token doesn't work on a mac?13:01
DacostaI test both on mac os and iphone13:02
DacostaI cannot install wikid client on mac os13:02
nowenare you using the installer or the jar file?13:03
Dacostayes, wikidtoken-3.1.19-bundle-installer.jar13:04
nowentry using just the jar file. Also, I think there's a more recent token13:04
DacostaI test both wikidtoken-3.1.19-bundle-installer.jar and wikidtoken-3.1.19.jar13:05
nowenand when you run the jar file from the command line, what error do you get?13:06
DacostaI got this error: JW quit unexpectedly while using the libjvm.dylib plug-in13:06
nowenwhat version of java?13:07
Dacostaversion 7 update 713:11
Dacostado you have license package for 10 or 20 mobile users, other users use community edition?13:13
nowenno, it's all or nothing.  you can set up two servers13:14
nowenplease try http://www.wikidsystems.com/webdemo/tokens/j2se/3.1.22/wikidtoken-3.1.22.jar13:14
nowenit's probably not the token client, but best to use the latest13:15
Dacostaok, nice suggestion about the license13:16
nowenare you in a directory that the token can write to?13:18
Dacostayes13:18
nowencan you run any java program?13:20
nowenhttp://lists.apple.com/archives/java-dev/2012/Aug/msg00170.html13:20
nowenbrb13:21
Dacostai always get the error: JW quit unexpectedly while using the libjvm.dylib plug-in13:22
Dacostaon mac os 10.813:22
nowenwith any jar? or just ours?13:34
Dacostai will update mac os x to 10.8.2 and update java13:37
Dacostathen i will try13:37
Dacostawikid doesn't suppor sms?13:37
nowenno, there's no way to secure it13:38
Dacostawhen i run the wikid client first time, i get a registration code13:38
nowenon the mac?13:39
Dacostaon windows13:39
Dacostawhere the registration code store?13:39
Dacostacan a hacker hacks to use this code in his computer?13:39
nowenno, an attacker would need the private keys in the token.  the reg code is used to associate the key pair exchange with a username on the server13:41
nowen did you validate the registration code on the server?13:41
Dacostayes13:45
Dacostait means when i install wikid client and authentication with server13:46
Dacostacan a hacker to get this registration code and user on his computer for fraund authenticaiton13:47
Dacostacan a hacker to get this registration code and use on his computer for fraund authenticaiton13:47
nowenthe security rests not on whether an attacker gets the registration code - but whether YOU validate it for him13:49
Dacostawhere the registration code store?13:50
nowenin the server, you can see it on the WiKIDAdmin/Users/Manually Validate a user13:50
Dacostahave it save on client?13:51
nowenno13:51
Dacostahow the wikid server know this registration code is on my pc or not?13:53
Dacostai means how the server know code for authentication if it doesn't store on client13:54
nowenthe token and the server exchange public keys.  the server sends the registration code the token where it is hashed by the token and presented to the users as an alpha-numeric.13:55
nowenin order for the user's keys to be valid, the registration code needs to be validated13:55
*** nowen has quit (Quit: Leaving.)13:59
*** nowen1 (~nowen@67.211.17.2) has joined #wikid13:59
*** nowen1 is now known as nowen14:01
*** Dacosta has quit (Ping timeout: 245 seconds)14:05
*** nowen has quit (Ping timeout: 246 seconds)14:16
*** nowen (~nowen@67.211.17.2) has joined #wikid14:19
*** Dacosta (71a56292@gateway/web/freenode/ip.113.165.98.146) has joined #wikid14:26
DacostaHi mr. nick14:26
Dacostawhere is the public key?14:26
nowenin the token14:27
Dacostathe token is a software14:29
Dacostait will store on a folder in program files?14:29
Dacostaor registry of windows14:29
nowenin a pks12 file protected by the token passphrase14:30
nowenwould you like a copy of the white paper?14:30
Dacostai we dont use passphrase, only use PIN14:31
Dacostaif we dont use passphrase, only use PIN14:31
nowenthere is a passphrase on the token.  are you prompted for a password when you start the token?14:31
Dacostayes14:32
nowenthat's the password on the pks12 file14:32
*** Dacosta has quit (Ping timeout: 245 seconds)14:36
*** Dacosta (71a56292@gateway/web/freenode/ip.113.165.98.146) has joined #wikid14:37
Dacostawhen we run the token at first time, we have registe code14:38
nowenyes14:38
Dacostathe register code is stored on the token or not?14:38
Dacostaif not, how the server know token14:38
nowenno14:38
Dacostahow can the server know a register code is for token A or token B?14:39
nowenthe server and token exchange encryption keys, the server creates the account, but it is not active or valid14:39
nowenbecause the user tells you "I have this registration code"14:40
Dacostayou mean the token tell the server "I have this registration code", right?14:41
nowenno, the user has to tell you14:41
Dacostayes, i know14:42
Dacostai pay attention to how to trust the wikid security14:42
nowenso, the key trust piece is the registration code14:43
Dacostai mean, a hacker knows my registration code14:43
Dacostacan he use this registration code on his token or not?14:43
nowenhow does he register it on the server?14:44
Dacostabecause this register code is mine and it is registered already14:45
nowenonce a registration code is used it can no longer be used again14:46
Dacostafor example, if the registration code store some where in the PC where the token running14:48
Dacostathe hacker can change that code on his PC if he know my registration code?14:48
nowenni14:48
nowenno14:49
Dacostait means the registration code doesn't store on the PC running token?14:52
nowencorrect - the registration code is not stored on the token14:53
*** Dacosta has quit (Quit: Page closed)14:56
*** Dacosta (71a56292@gateway/web/freenode/ip.113.165.98.146) has joined #wikid14:57
Dacostacreate /etc/WiKID/security with one line: WAUTH_PASSPHRASE=yourpassphrase14:58
Dacostaif i create this file, when i restart wikid server14:58
Dacostai need run wikidctl start or it will start automatically?14:59
joevanoit starts automatically14:59
Dacostathanks Joe15:00
nowenyou will need to run the command or configure it as a service.  There is an example script in /opt/WIKID/conf/templates  called wikid15:00
joevanoyw15:00
joevanohmm... didn't remember doing that but we must have15:00
Dacostaok, thanks Nick15:05
*** chiong (daba130a@gateway/web/freenode/ip.218.186.19.10) has joined #wikid16:20
chiongHi there, could someone let me know what is the default password to login to wikid after running the installation from ISO image downloaded?16:22
nowenroot/wikid16:22
chiongo, i try now. thks16:22
nowennp16:22
*** Dacosta has quit (Quit: Page closed)16:24
chionghi @nowen, it works.. thanks alot. i am now running yum update to patch first. and it is late now. i will try to install wikid tomorrow.16:30
nowenok - I won't be around much tomorrow as we are hosting a conference16:31
nowenbut, if you follow the install manual from here, you should be good16:31
nowenhttps://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server16:31
chiongok, noted. thanks for your help.. bye!16:33
nowenbye16:35
*** chiong has quit (Ping timeout: 245 seconds)16:58
*** Skelroy_ (~Skelroy@71-85-217-74.dhcp.stls.mo.charter.com) has joined #wikid18:17
*** Skelroy_ has quit (Client Quit)18:17
*** Skelroy has quit (Ping timeout: 246 seconds)18:19
*** hany (4e65a0d5@gateway/web/freenode/ip.78.101.160.213) has joined #wikid18:39
*** genewitch (~genewitch@unaffiliated/genewitch) has joined #wikid19:01
*** hany has quit (Quit: Page closed)19:11
*** hani_ (4e65a0d5@gateway/web/freenode/ip.78.101.160.213) has joined #wikid19:11
genewitchnowen: Hi there19:35
nowenhi19:35
genewitchI'm trying to install wikid on a redhat instance on AWS. I'll let you know how it goes19:38
nowenok19:41
nowenshould be fine19:41
genewitchlast time it nuked eth0, is there documentation about what the network setup actuall does so i can set it up manually/19:44
nowenhmm, I've never seen it do that.  it just writes out the ifcfg files, I believe19:45
genewitchyeah i was able to start wikidctl this time19:49
genewitchnowen: how do i clear the generated cert and start over?19:54
nowenthe intermediate ca and localhost?19:54
nowenthey are in /opt/WiKID/private19:54
genewitchwhatever it had me generate during "setup"19:54
nowenboth are p12 files19:54
nowenoh that19:54
genewitchif i delete them and re-run setup will it have me regenerate them?19:55
nowenno, that's a different cert19:55
genewitchI only have links available and it throws an SSL error when i connect to the URL https://localhost.localdomain/WiKIDAdmin/19:56
nowenwell, it's a self-signed cert19:56
nowenare you accessing it locally?19:57
genewitchyeah19:59
nowenI thought you said it was in the cloud?19:59
genewitchI tried both, local and opening the firewall to allow external access20:00
genewitchyeah, i was using links to access the http://localhost.localdomain20:00
nowenare you running X on the server?20:00
genewitchNot yet :-)20:00
noweni do not recommend it ;)20:01
nowenif you accept the ssl error, do you get the login?20:01
genewitchit appears not. I'll just start over, back in 10 :-D20:04
nowenI'm going to have to check out soon and run some errands - and tomorrow we're hosting a conference...20:33
genewitchI'll be ok21:08
genewitchhave fun!21:08
nowenthanks21:08
nowenlater all,21:09
nowenI'll peek in periodically tomorrow21:10
*** nowen has quit (Quit: Leaving.)21:10
genewitchbummer, i got the same error again21:17
genewitchit's just Elinks. I killed iptables and now my remote machine can access the admin page.21:22
genewitchcool, the token app just crashes my iphone21:50
*** hani_ has quit (Ping timeout: 245 seconds)21:57
genewitchI got it to work!22:22
genewitchI have no idea what to do with it, but that's not my job!22:22

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!