Tuesday, 2012-11-06

*** WiKIDLogBot has quit (Ping timeout: 246 seconds)04:11
*** WiKIDLogBot (~WiKIDLogB@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid13:55
kornbluth.freenode.netTopic for #wikid is: wikid If no one is here, please try the forums: https://www.wikidsystems.com/support/support/wikid-forums13:55
kornbluth.freenode.netUsers on #wikid: WiKIDLogBot @nowen joevano13:55
nowenthat's better14:08
*** cdub_ (40fee8e2@gateway/web/freenode/ip.64.254.232.226) has joined #wikid19:57
cdub_Have you had any reports of the latest version of IOS causing issues with the wikid app?19:57
*** cdub_ has quit (Ping timeout: 245 seconds)20:33
*** dystie (c7ff5332@gateway/web/freenode/ip.199.255.83.50) has joined #wikid21:10
dystiehey Nick.21:10
nowenhey21:57
nowendystie: you still here?21:57
dystieyes.  :)21:58
dystiesorry, was in another tab.21:58
nowenme too - well, another room21:58
dystie:)21:58
dystieso.  i wanted to bounce past you the best way to handle this -21:58
dystieI have DBAs who like to share credentials.21:58
dystieand they share machines.21:58
dystieso same DBA will use the same win 7 desktop as other DBAs21:58
dystiei'm trying to figure out the best way to prevent credential sharing;  the locked JAR file doesnt appear to support preregistration21:59
dystieit might be best to put them on a USB stick token, but that didn't look straightforward in that you have to manually copy a file that gets written to c:21:59
dystie(unless I'm incorrect)21:59
nowenhmm, I'll have to check on the locked token pre-reg thing.  it should support it22:00
dystieand the desktops don't have java by default.  I've been having them use the non-java installer and manually installing java, but i'm going to have their desktop support person test to see if the package that incldues the jar works on their stuff.22:00
dystieplease do - i need to make it so it's user friendly but so they stop sharing their passwords22:00
dystieunlocked tokens make it too easy.22:00
dystiebut it's also got to be easy to administrate, and my current install instructions for wikid + how to access us are like.  30 pages.22:00
nowenso, they share windows creds too?22:01
dystiewhich means i'm / we're doing it wrong22:01
dystieoh yes.22:01
dystiei've started performing daily review of the tickets they work and comparing the tickets against our access logs.22:01
dystieas far as on their desktops, i don't knwo if they log out and log in as themselves22:02
dystiethier management indicates that they do.22:02
dystieand if the token software is multiuser and does not share the same seed between users - if there's an install path that means they can share it on the same desktop in different profiles, that's preferable.22:02
dystiei've not had to deal w/ that for angel employees.22:02
nowenwell, if they install as different windows users, they have different keys22:03
nowen30 pages?22:03
nowenthat seems excessive.22:03
dystieit is.22:04
dystiethe problem is that the process really is that busted - when you start w/ downloading the jar, then java, then installing + configuring the jar, then downloading + installing + configuring openvpn, it gets log.22:04
dystielong.22:04
nowenwant me to take a look at it?22:08
dystieinstructions?  sure - onesec.  i was actually going to pop them to you in case they helped anyone else, or at least the wikid specific portions.22:08
dystienowen@wikidsystems.com?22:08
nowenyes22:09
dystiegimmie a few;  email box quota fail.22:22
nowenok22:22
dystieyou should have mail22:33
nowengot it22:33
nowenhmm. not sure why the locked token is only one 1922:35
nowenonly on22:35
joevanodystie: I can't believe that you have DBAs that share credentials... that is shocking and scary to me22:35
dystieyeah, i looked at that.22:35
dystiejoevano:     :)22:35
dystieworking on them.22:35
dystieit's a india thing.22:36
nowendystie: you should fake an incident and then blame the wrong one ;)22:36
dystienah, i have the ability to prove things a bit better.  i've got a writeup process now that appears to be effective.22:36
joevanooh... yeah the cultural differences have surprising reprucutions22:37
dystiei audit every ticket they work against who logged in.  if there's a difference I escalate to their management for confirmation, if it's not legit then both users involved get kicked for a period of time22:37
dystiei notify senior management on down, so they lose face.22:37
dystielosing face is the only thing that works on them.22:37
dystieso i'm working on it, but the technical issues (it's not easy to get the creds working right) are a reason we have problems, and i need to streamline.22:37
dystiethey know if they don't knock it off they'll lose the contract, and i'm working on a contract change that will allow us to actually sue them.22:38
joevanothat would make them stand up and notice22:38
dystieyeah.  i'm pouring pressure down in the way that supposedly works.22:39
dystieit's expensive to switch vendors, so we're trying to change their behavior before we replace them.22:39
nowenok - do you use the jar or the exe?22:42
nowenhttp://www.wikidsystems.com/webdemo/tokens/j2se/3.1.21-locked/wikidtoken-3.1.21.exe22:43
nowenhttp://www.wikidsystems.com/webdemo/tokens/j2se/3.1.21-locked/wikidtoken-3.1.21.jar22:43
nowenwikidtoken-3.1.21-bundle-installer.exe/wikidtoken-3.1.21-bundle-installer.exe22:43
nowenerp22:43
nowenhttp://www.wikidsystems.com/webdemo/tokens/j2se/3.1.21-locked/wikidtoken-3.1.21-bundle-installer.exe22:43
nowenthose all support pre-reg22:43
dystieonesec22:44
dystiea.For Windows, the client is ‘wikidtoken-3.1.22.exe’ under Unlocked Token Clients:   was what we're using.22:46
nowenI thought you wanted a locked token that supports pre-reg?22:46
dystieyes, i do.22:47
dystiethats' what we were using / is in the doc22:47
dystielooking at hte site22:47
nowenok - I can bump the locked tokens to .22 if you like22:48
dystiei'm not seeing htose linked off the site22:48
nowenI haven't posted them yet22:48
dystieyes, pplease.22:48
dystieesp the one with the embedded jre becuase that's the one i'd like to try and push22:48
dystiewhat about using it on a usb stick?22:48
nowennot sure if the locked token will 'lock' on a usb stick22:49
nowenit uses data from the pc like the cpu identifier22:49
dystiefor the embedded jre 3.2.22 - if I have them install the embedded jre clietn as any user, is it then reusable (the software) by other users, but the seed per user is locked still to the machine?22:53
dystiejust want to make sure that that client is multiuser so I can have them test it on their image.22:54
nowenhmm22:54
nowenI'm not sure if it is available to any user22:54
nowenis that the way it works now?22:55
dystiei don't think so.22:55
dystiei'm checking w/ our image (which is not theirs, sadly.)22:55
nowenwell, nothing has changed in that regard22:55
dystiek.   if I let them use the unlocked token on a usb stick, how complex is that to set up?22:56
dystiein terms of say having them go to a administrators' desk to get the token, and have to configure it + set their angel credentials at the admins' desk.22:56
nowennot sure i follw22:57
dystieone of the options the contractor proposed was to have a centralized contact set folks up22:58
nowenthe only difference for a usb token is that you will have to make sure that the WiKIDToken.wkd file is on the usb and not the hd22:58
dystieso for me to distribute credentials to that person and for that person to have the dba go to the contacts' desk and configure the token22:58
dystieok, so it's  a manual step to copy the token seed file to the usb key.22:59
nowenyes22:59
dystiebasically it's the same as wikid checks the current directory for the jar for the seed file and then checks the default install directories?23:00
nowenyes23:00
dystiek.  hrm.  ok.  then sending them a bunch of usb keys won't work becaue it'd require that manual step every time they set someoen up.23:01
nowenyes23:02
nowenbrb23:03
nowenwebsite is updated btw23:04
*** dystie has quit (Ping timeout: 245 seconds)23:05
*** dystie (c7ff5332@gateway/web/freenode/ip.199.255.83.50) has joined #wikid23:19
dystieso - i'm looking at the packed installer23:19
dystieand i get this error (emailing)23:19
dystielooks like Angels' default image *does not* contain a JRE23:22
dystiejust mailed you the screenshot of the error we get when we try and use it (which is why our install process involves manually installing hte jre)23:22
dystiewhatcha think?23:22
nowenlet me check on it. i have emailed to the dev. seems like it is not picking up the packaged jre23:43
dystieyeah - if that can be fixed it'll take out pages of my instructions.23:44
nowenok - time for me to check out23:44
nowenI'll be back tomorrow23:44
dystiekk23:46
*** nowen has quit (Quit: Leaving.)23:46
*** dystie has quit (Quit: Page closed)23:46

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!