Friday, 2012-11-09

*** nowen has quit (Quit: Leaving.)00:03
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:45
*** MarkH (540c8c38@gateway/web/freenode/ip.84.12.140.56) has joined #wikid15:51
MarkHNick?15:52
nowenhi15:52
MarkHHi. Our Wikid system has stopped working. lots of errors to do with Invalid Certificate after I restarted after adding a new Network Client15:53
nowenwhat company do you work for again?15:54
MarkHSoft Option Technologies Ltd15:54
MarkHRenamed now to MJog Limited (same co - different name). www.mjog.com15:54
*** _markh_ (~chatzilla@wish-hq3.gotadsl.co.uk) has joined #wikid15:57
_markh_@nowen. Got bounced .. back again. Did you get my last?15:57
nowenyes15:57
_markh_OK. Crap network link today. Logging says "Couldn't validate the client certificate. Verify the validity and dates of the client cert."15:58
nowencan I get you to pay your invoice?15:58
_markh_What invoice?15:58
nowenI just resent it15:58
_markh_:)15:58
_markh_Never got the original... I'm trying to pay it now. The software should warn before it just quits tho.16:01
nowenworking on it16:01
nowenyou just need to recreate your certs16:01
nowenare you only using radius?16:02
_markh_not only radius. Some wAuth16:02
nowenhmm, those will need to be recreated - new p12 files16:02
_markh_but it's none opf the hosts are working now...16:04
_markh_I can't get your shopping catrt to work. Can't update the quantity of a line nor delte anything...16:04
nowenaghh16:05
nowenhow many licenses are you?16:05
_markh_10 users16:05
_markh_some how I have qty 3 of 10user/iyear licences16:06
_markh_1 year16:06
nowenfrack. can you pop into a new browser?  http://www.wikidsystems.com/simplecartitem/10-seat-1-year-license16:06
nowenthat is odd16:07
nowenwhy would that suddenly stop working?16:07
_markh_OK Paid - via mark.howells@mjog.com16:11
nowenthanks16:11
_markh_I added a new Network client16:11
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid16:12
_markh_and restarted the wikid server. The new client doesn't appear in iptables -L either16:12
nowencheck both your certs to  see if they are expired16:12
_markh_sorry - BRB16:19
*** MarkH has quit (Quit: Page closed)16:19
_markh_keytool error: java.io.IOException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded16:21
nowenrun 'locate java.security'16:22
nowentwo should come up16:22
nowenrun diff on the two and let me know if there is a difference in the files16:23
_markh_sorry. let me try again16:24
_markh_the first "keytool -list -v -keystore /opt/WiKID/private/intCAKeys.p12 -storetype pkcs12" show expired Jan 23 201216:24
nowenok - I recommend you recreate the intermediate CA from the WiKIDAdmin16:25
nowenyou can rm them from /opt/WiKID/private if you like too16:25
_markh_done. Server restart?16:33
nowenyes16:33
nowenthen check radius clients.16:34
nowendo your wauth clients use localhost.p12?16:34
_markh_the old radius NC's now work - phew!16:38
nowen;)16:38
_markh_the new one I added doesn't.16:38
nowenhmm16:38
nowenis there an error message in the logs?16:38
_markh_iptables -L doesn't show the NC ip address16:38
nowenhmm.16:39
nowenperhaps modify it and then restart? you don't need to change anything16:39
_markh_well, I deleted it, added it again and restarted the wikid server - still not presetn in iptables -L16:44
nowenwhen you restart, are you using 'wikidctl restart'?  if so, can you try stop/start?16:45
nowenyou can also run 'killall -9 java' after stop16:46
_markh_no improvement. loads of errors in the log16:53
_markh_Error loading WebappClassLoader delegate: false repositories: /WEB-INF/classes/ ----------> Parent Classloader: org.apache.catalina.loader.StandardClassLoader@11db6bb pgPool16:54
nowenis a little bomb icon next to the error?  click it for the full trace16:54
nowenare you in replication?16:54
_markh_java.lang.ClassNotFoundException: pgPool16:55
_markh_no replication16:55
nowenwhat version of WiKID is this>16:56
nowen?16:56
_markh_wikid-server-enterprise-3.4.87-b117116:57
nowenmight be that upgrading will clear that error.16:58
nowenis this a vmware image?16:58
_markh_yes16:58
nowendo you have a backup image?16:59
_markh_nope17:00
nowenhttp://wikidsystems-dl.com/wikid-server-enterprise-3.4.87.b1216-1.noarch.rpm17:00
nowenwell17:00
nowenI guess take one now?17:00
_markh_Sorry, there was an error while checking for updates.17:00
_markh_Error: /opt/WiKID/sbin/check_for_updates.pl returned exit value 9. (Instead of the expected value 0.)17:00
nowenjust run 'wget http://wikidsystems-dl.com/wikid-server-enterprise-3.4.87.b1216-1.noarch.rpm;17:01
nowenI mean 'wget http://wikidsystems-dl.com/wikid-server-enterprise-3.4.87.b1216-1.noarch.rpm'17:01
nowenand then rpm -UVh wikid-server-enterprise-3.4.87.b1216-1.noarch.rpm17:01
_markh_--upgrade: unknown option17:04
_markh_I'm not familiar with rpm - we use ubuntu17:04
nowen just 'rpm -Uvh wikid-server-enterprise-3.4.87.b1216-1.noarch.rpm'17:05
nowenwill do it17:05
_markh_OK, so it said "Preparing... 1:wikid-server-enterprise########################################### [100%]", then stopped the services. Shall I start them?17:07
nowenyes17:07
_markh_same error17:09
_markh_:(17:09
_markh_hold on...17:09
_markh_first error appears to be "IOException while saving persisted sessions: java.io.FileNotFoundException: /opt/WiKID/tomcat/work/Catalina/localhost/wikid/SESSIONS.ser (No such file or directory)"17:12
nowenyou can ignore that one17:12
_markh_then the first error on restart is "Error loading WebappClassLoader delegate: false repositories: /WEB-INF/classes/ ----------> Parent Classloader: org.apache.catalina.loader.StandardClassLoader@11db6bb pgPoo"17:13
_markh_as before ...17:13
_markh_I have 13 radius NC's all was well whemn there were 12...17:14
nowenok 'cd /opt/WiKID/tomcat/webapps/WiKIDAdmin'17:15
nowenand then 'grep -r pgPool .'17:15
nowenit should return17:15
nowen./WEB-INF/web.xml:    <!--<servlet-name>pgPool</servlet-name>-->17:15
nowen./WEB-INF/web.xml:    <!--<servlet-class>pgPool</servlet-class>-->17:15
nowendoes it?17:15
_markh_yes17:16
nowenok17:16
nowenstop the server17:16
nowenand 'cd /opt/WiKID/tomcat/work'17:16
nowenand them 'rm -Rf *' in that directory17:16
nowenthen start the server17:16
_markh_same error....17:21
nowenand does the 13th radius client still not work?17:22
nowenis the date correct on the server?17:22
_markh_client fails.17:23
_markh_Date is correct.17:23
_markh_I was mistaken about iptables -L tho.  It is (and always was) listed17:23
nowenyou created a new localhost cert, right?17:23
_markh_yes17:23
nowenok17:23
nowenthat's interesting17:23
nowenset radius logging to debug: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests17:24
nowenperhaps it is something else17:24
_markh_it a new dedicated server and the reverse pointer appears to point to the old owners so I didn;t recognose it17:25
_markh_no requests hittin wikid from that host. I can see other requests17:32
nowenrun 'tcpdump port radius' on the WiKID terminal to see if they are hitting the server17:32
nowendouble check the IP address17:33
_markh_Looks like the reverse pointer might be the problem. The rev lookup on the address gives the old owners domain. A forward lookup on that gives a different IP. I guess iptables is throwing it out17:39
nowenseems likely17:41
_markh_still getting that error on starup tho. Leave it with me and I'll beat up our ISP and see if I get the DNS sorted properly whether that helps.17:42
nowennot sure why that error is hanging around. but, if the other network clients are working and the one isn't, I don't think the error is the issue17:43
_markh_I agree. I'll the the IP records fixed, and try again. Leave it with me till next week. Cheers, Mark17:47
nowencheers17:48
_markh_And thanks ...17:48
nowenthank you for renewing117:48
nowenand sorry for the sudden issues.17:48
_markh_no worries. Thanks..17:49
*** _markh_ has quit (Quit: ChatZilla 0.9.89 [Firefox 16.0.2/20121024073032])17:49
*** Sroman (46b71922@gateway/web/freenode/ip.70.183.25.34) has joined #wikid18:06
SromanHi all, I have a questio on Cisco Router authenticaion to Radius18:07
nowenfor WiKD?18:07
SromanI have WikID runnign and working great against ASA 5525X for VPN auth18:08
nowenok18:08
SromanI am now trying to get a Cisco Router to auth users for admin purposes18:08
SromanThe router is a basic config18:08
SromanI setup th eRadsius info and the network client matching ther ASA but the logs on the WikID keep showing me java errors18:09
SromanI have checked numerous sites for radius config on the routers and they are all the same.  It should be a simple setup, but I am hung up on something18:10
nowenwhat are the errors? use pastebin.org if they on long18:11
Sromanok will upload18:11
SromanPasted18:22
SromanIE kept crashing so had to use FF18:22
nowenok - post the url here18:22
Sromanurl?18:24
nowenthe pastbin.org url.18:24
SromanI pasted ok to pastebin18:24
nowenI go to it to see the upload18:24
Sromansubject is WikID and cisco router18:24
nowenpaste the url here, so i know what post it is18:24
Sromanhttp://pastebin.com/87D1VbBR18:28
nowenthanks18:28
nowenunknownNAS means the request is coming from a different IP than expected18:29
nowendid you restart WiKID after you added the network client/18:29
nowen?18:29
Sromanno18:32
nowenok just run 'wikidctl stop'18:32
nowenand then 'wikidctl start'18:32
Sromanforgot about that18:33
Sromanlet me try that real quick18:33
Sromanbut different IP that is odd18:33
Sromanthe router only has one interface up18:33
nowenyeah, radius caches everything, so if the IP isn't cached, it is rejected18:33
SromanNow I get this, closer18:37
SromanAccess-Request(1) LEN=98 10.41.1.30:1645 Access-Request by sroman Failed: AccessRejectException: Access Denied18:37
nowencheck to make sure you are enabled18:37
Sromanyup enabled18:38
SromanI have been using VPN with WikID and an ASA for awhile now18:38
nowenset radius logging to debug: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests18:38
nowenthat will tell you more about why you are being denied18:39
Sromanother msg18:39
SromanAccess denied for sroman, domain code: 070183021137 client: /10.41.1.3018:39
nowenis that client ip the cisco?18:40
Sromanyup18:42
Sromanjust set logging to debugging18:42
nowenok, try again18:42
SromanPasscode is not a number. error18:43
SromanRADIUS client supplied passcode is ?????%? +_??18:43
nowencheck your shared secrets.18:43
Sromanthey are matched18:45
nowenand you only entered the OTP?18:45
SromanI changed the port for radius to 1812 and 1813 to match the ASA, should I put bacl to 164518:45
Sromanyes on the OTP18:46
nowenthe port needs to be 181218:46
Sromanok then that is good18:47
SromanWonder if I need to put a domain with my login name?18:47
nowenif your wikid username is sroman, then that seems right18:48
Sromananother msg18:48
SromanRADIUS client supplied passcode is ?b?n??b?Ld?+?18:48
nowenthat is the problem18:48
Sromanwonder if I need any attributes on the WikiD Server for network client.  It has non selected, but the ASA which works also has nothing18:51
nowenthat's fine.18:51
nowenthe "RADIUS client supplied passcode is" should be the decrypted passcode18:52
SromanI know it is something simple, just cannot find the issue18:53
nowenhmm.  usually it is the shared secrets.18:54
SromanI will re enter them18:55
nowenok, and restart wikid for good measure18:55
Sromanyup18:58
Sromanrestarting18:58
SromanLittle better but no go   RADIUS client supplied passcode is 37956419:02
nowenok - now check that you are enabled19:03
SromanAccess denied for sroman, domain code: 070183021137 client: /10.41.1.3019:03
SromanCheck returned false19:03
nowenthe previous attempts would be counted as bad passcode attemtps19:03
SromanServer returns passcode: -119:03
Sromanyes 10.41.1.3019:03
nowenare you enabled?19:06
Sromanyup19:06
nowenyou will probably need to reset the logs for debug - they get reset on a restart19:07
nowenthen try again19:07
Sromanhold that19:07
SromanI check my user and inside says enabled19:07
Sromanbut looking at the user list I am disabled19:07
Sromana bug maybe?  or my browser greaking out19:07
Sromanlet me enable19:08
nowenprobably just cached19:08
Sromansame error and denied19:12
nowenhmm19:16
nowentry resetting the logs to debug again19:17
Sromansee the port on this error19:19
Sroman<30> Access-Request(1) LEN=98 10.41.1.30:1645 Access-Request by sroman Failed: AccessRejectException: Access Denied19:19
nowenis the cisco sending to 1645?19:19
Sromanthe router is setup for 1812 but it look like it is talking 164519:20
Sromanradius-server host x.x.x.x auth-port 1812 acct-port 181319:20
nowenand your other network clients are working fine?19:23
Sromanyes19:24
Sromantried changing to 1645 and 1646 and the logs show good info but the router keeps saying access denied19:25
nowenI don't think changing the ports on WiKID is a good idea19:25
nowenI have to go out for a meeting soon.  I will be back around 4pm.19:27
Sromanonly changed th erouter port19:28
nowenahh19:29
Sromanbut stil no work19:29
nowenwhat i don't get is why wikid would say ") LEN=98 10.41.1.30:1645" if it is listening on 1812?19:29
nowenok, try this19:30
nowenrun 'wikidctl stop'19:30
nowenthen 'killall -9 java'19:30
nowenthen 'wikidctl start'19:30
nowenmaybe the radius cache isn't getting stopped fully19:30
Sromanstopped19:35
Sromanchecked and no java running19:35
Sromanstarted and still no login19:35
nowenis there additional logging from debug?19:35
Sromanciphertext length: 25619:38
SromanPasscode request processing successfully completed.19:38
SromanSent 256 bytes to client.19:39
Sromantrace com.mchange.v2.resourcepool.BasicResourcePool@34151f [managed: 3, unused: 2, excluded: 0] (e.g. com.mchange.v2.c3p0.impl.NewPooledConnection@178b64b)19:39
SromanAll looks good but no login19:39
nowendo you see anything like:19:40
nowenUser-Name (1), Length: 7, Data: [nowen], 0x6E6F77656E Acct-Session-Id (44), Length: 18, Data: [1352489956T57phl], 0x3133353234383939353654353770686C NAS-IP-Address (4), Length: 6, Data: [IP 127.0.0.1], 0x7F000001 NAS-Identifier (32), Length: 11, Data: [Localhost], 0x4C6F63616C686F7374 NAS-Port (5), Length: 6, Data: [# 0], 0x00000000 Calling-Station-Id (31), Length: 12, Data: [1115551212], 0x31313135353531323132 User-Password (2), 19:40
nowenand Checking nowen:912899:19216800108119:40
nowenok - I have to run. I'll be back at 4.  Sorry19:41
Sromanok19:42
*** nowen has quit (Quit: Leaving.)19:42
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid20:41
nowenSroman: any progress?20:42
Sromannope, I tried everything20:44
SromanI have debuggiung on the router says acess rejected20:44
SromanReceived from id 1645/62 192.168.28.28:1812, Access-Reject, len 2020:44
nowenstill with the 1645?20:45
Sromanno I have it at 181220:45
nowenwhat does the leading 1645 mean?20:45
Sromanradius-server host 192.168.28.28 auth-port 1812 acct-port 1813 key20:45
Sromanthat says id, not sure if it means port as you can see the IP: 181220:46
nowenok20:46
nowenok, can you show me the part of your logs that looks like:20:48
nowenUser-Name (1), Length: 7, Data: [nowen], 0x6E6F77656E Acct-Session-Id (44), Length: 18, Data: [1352489956T57phl], 0x3133353234383939353654353770686C NAS-IP-Address (4), Length: 6, Data: [IP 127.0.0.1], 0x7F000001 NAS-Identifier (32), Length: 11, Data: [Localhost], 0x4C6F63616C686F7374 NAS-Port (5), Length: 6, Data: [# 0], 0x00000000 Calling-Station-Id (31), Length: 12, Data: [1115551212], 0x31313135353531323132 User-Password (2), 20:48
Sromanhere is comes20:50
Sroman*Nov  9 20:51:38.844: RADIUS(00000048): Config NAS IP: 0.0.0.020:50
Sromannot pasting all20:51
SromanI will put on pastebin20:51
Sromanlink20:51
Sromanhttp://pastebin.com/qmedryVa20:51
nowenis that from your cisco?20:52
Sromanyup20:53
nowenI need to see the WiKID logs20:53
Sromanoh20:53
Sromangetting that20:53
Sromanhttp://pastebin.com/m918xuS020:56
nowenhmm20:58
nowenwhat state is this for?20:58
nowencalifornia?20:58
Sromanyes20:59
nowenand you've double-checked that the user is still enabled?21:01
SromanAs of my last few tests yes enabled.  I keep checking on that21:02
nowensorry to keep asking, but the user should get disabled in this situatino21:02
Sromanit does get disabled afwer a few tries then I need to go and enable it21:04
nowenok, let's review everything.21:04
nowenon your WiKID server, you have a network client 10.41.1.3021:05
Sromanthe cisco router config is super simple setup21:05
nowenit's using radius and the same domain as your other21:05
nowencan you post that?21:05
Sromanyes 10.41.1.3021:05
Sromanyes same domain21:05
nowenare the other network clients also 10.41.1.x?21:06
SromanCisco config21:06
Sromanaaa authentication login default group radius local21:06
Sromanradius-server host 192.168.28.28 auth-port 1812 acct-port 1813 key xxxxxx21:06
Sromanthat is basically it21:07
nowenhmm, can you disable accounting?21:07
Sromanyes other net clients 10.41.1.x21:07
Sromanon the router?21:07
nowenyeah, is accounting required?21:08
Sromanno21:09
Sromanbut it auto populates the acct port21:09
Sromanradius-server host 192.168.28.28 auth-port 1812 acct-port 1646 key21:09
nowenok, new idea21:13
nowencan you edit /etc/WiKID/log4j.properties to be http://pastebin.com/VSTMHe6q21:13
Sromanwill this break the anything?21:14
nowenno, upon restart it will send the logs to /opt/WiKID/log21:15
nowenand we might get a bit more insight21:15
SromanI only had a few differences21:22
Sromanrestartintg services21:22
nowenwell, now that i have done the same, I don't see much difference21:23
nowenI assume you only have the one domain/21:26
nowen?21:26
Sromanyes21:27
Sromannice and simple21:27
nowenand this same user can login to the other network clients now?21:28
Sromanonly one other network device ASA which authenticates VPN users and yes I can still login21:31
nowenok, so what are the differences?21:32
Sromanso I just checked th eVPN and now  I cannot login anymore21:34
nowenok, that's interesting21:34
SromanSo now no auth to WikID is working21:34
nowencan you check the validity of your certs: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid21:35
nowenyou set this up in May, right?21:37
Sromanyes21:38
Sromanit was all working the last time I checked the Firewall21:38
Sromanseems like something has change on the wikID server since nothing works now21:44
nowendid you check the certs?21:44
nowenwhat version of WiKID is this?21:45
Sromanhow can I check AD auth from wikID?21:46
Sromanwonder if AD is disconnected?21:46
nowenwait, are the authentications passing through NPS?21:46
Sromanwikid-server-enterprise-3.4.87-b121621:46
SromanNPS?21:47
nowenThe MS radius plugin21:47
nowenit's the only way to tie in AD21:47
SromanI think I did it the simplest way, I remember you helped me21:48
nowenok, then AD is most likely not in the loop21:48
nowenthe most likely culprit is your certs21:48
SromanI think it was21:48
Sromanbut not sure anymore21:49
nowenwell, in the case of the router, you had it talking directly to the WiKID, IP, correct?21:49
Sromanyes21:50
Sromansame as firewall21:50
nowenso, that means no AD.  otherwise, AD would be a network client.  and probably the only one21:50
nowenplease run the commands listed here: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid21:52
SromanOk I can connect now21:54
SromanI was trying user sroman21:54
nowen?21:54
SromanI have wikid on a new iphone21:54
SromanSo since I could not use the original name I created a new one21:54
SromanI just tried it and it works21:54
SromanSo I knew it was something simple21:55
nowencan you also use that name on the router?21:55
SromanJust a mixup in user account21:55
nowenso, everything works now?21:55
Sromanyes21:56
Sromanso hhow can I change the usernames, I have one for iphone 1 and one for iphone 221:56
SromanI want to user sroman for iphone 2 not 121:56
nowenif you want two tokens on one username, you need to add the 2nd token via the API, see :http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/installing-the-wikid-strong-authentication-server-enterprise-edition-page-521:58
Sromanthis shows how to create one user22:00
SromanI already have that part22:00
nowenyeah, but edit the page and you'll see the full functionality.  "Add additional device to existing userid"22:00
nowenthe page is very well documented22:01
SromanSorry for being lame, edit the page? from the Server or browser?22:02
joevanoStart reading the web page he just posted to you after Figure 28 (real near the bottom)22:06
nowenyeah, edit that page and browse to it22:10
joevanohave a good weekend nowen22:16
nowenthanks joevano you too!22:17
SromanLine 48 says this22:18
SromanString chall;22:18
nowenlook on line 46, change 010000000129 to your domain id22:19
nowenthen on 51, change 'passphrase' to your localhost passphrase22:20
Sromanok, edited lines and browse and get constant invalid login22:25
nowenare you logging in with the WiKIDAdmin credentials?22:26
Sromanoh no user22:26
Sromanlet me try that22:26
SromanNow I cannot remember the WiKIDAdmin password and cannot change it.  I created admin accounts to use and now this one cannot get on22:29
nowenany admin account will work22:29
SromanGet this22:35
SromanThe wClient connection to the server was NOT successfully established22:35
Sromanwith my admin account22:35
nowenhmm22:35
nowenso, are you sure you got the passphrase correct?22:35
Sromanthe secret one correct?22:37
Sromanor an admin pwd22:37
nowenwell, the passphrase for the localhost cert.22:37
Sromanwhich should be the one when restartig services22:37
nowenit's not the one for the intermediate CA that starts the service22:37
Sromanoh thats whatI was using22:38
Sromanhow can I find that one22:38
nowendidn't you check the validity of your localhost cert earlier using the keytool command?22:39
Sromanno22:40
nowenwell, you can guess at it that way22:40
nowenwhat passprhase did you use in the example.jsp?22:41
Sromansecret!@#22:41
nowenI meant did you use the intCA one?22:41
Sromanyes believe so22:42
nowenok, so I guess it is not that one22:42
nowenyou can create a new localhost through the WiKIDAdmin interface22:42
Sromanwont that break everything22:44
nowenno22:44
nowenbut it's late here.  5:44, so I'm not going to be around much longer22:44
Sromanin the example.jsp22:44
nowenmaybe we should pick this up monday22:44
Sromanline 52 has a CA certstore changeit22:45
nowenleave that one be22:47
nowenok - gotta go.  one tip: you will have to restart wikid to get any changes in example.jsp to show up22:48
nowen2nd tip:  don't mess with critical infrastructure late on a Friday afternoon!22:48
nowen;_22:48
nowen;-)22:49
Sromanok have a good weekend22:49
nowenl;ater!22:49
*** nowen has quit (Quit: Leaving.)22:49
*** Sroman has quit (Quit: Page closed)22:53

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!