Friday, 2012-11-30

*** ionepoch has quit (Read error: Connection reset by peer)08:36
*** ionepoch (~ionepoch@wsip-98-173-30-75.sb.sd.cox.net) has joined #wikid08:36
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:12
*** nowen has quit (Client Quit)13:16
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:18
*** proactis (bc5fce57@gateway/web/freenode/ip.188.95.206.87) has joined #wikid16:32
proactishi there, quick question can wikid be used with windows login16:32
nowenproactis: that's a tough one16:32
nowenin a domain?16:32
proactisyes in a domain16:33
nowendon't think so,  there's a project called pgina that will allow you to login with radius, but domain login isn't supported yet16:34
proactisok ta16:35
proactisCould Wikid be used with remote desktop connections?16:35
nowencertainly16:35
proactisis their a guide anywhere16:36
nowenthe key to deploying any 2FA system, really, is getting the service (RDP) to use a good authentication protocol like radius16:36
nowentake a look at the eguide here for starters: http://www.wikidsystems.com/learn-more/two-factor-authentication-white-papers16:37
nowenit doesn't discuss rdp specifically, but you'll get the idea16:37
nowenwill you use ms rdp? or something like citrix?16:37
proactisMS RDP16:37
proactiswe don't have the budget for citrix16:38
nowenso, you just need to put it behind something that supports radius, like forefront16:38
proactischeers16:40
nowenlater!16:40
proactiswill look into it16:40
nowenok16:40
*** proactis has quit (Quit: Page closed)16:40
*** bgeorge_ (444022c4@gateway/web/freenode/ip.68.64.34.196) has joined #wikid19:35
nowenwelcome bgeorge_19:35
bgeorge_Hello19:36
bgeorge_I am working on getting two factor up using NPS, but I'm a bit confused.19:37
nowenok19:37
bgeorge_At what point do I enter the one time password?19:38
nowenyou enter it instead of the password19:38
nowenNPS authorizes the user based on the username only19:38
bgeorge_hmm...i see19:39
nowenthen WiKID performs authentication using the username and OTP19:40
bgeorge_Cant seem to get the NPS to use the policy, even tried using the 24/7 time option. I think there is a nps server somewhere messing with me.19:42
nowenyeah, MS managed to make it more complicated than needed19:43
bgeorge_Do you know if I need an another network policy to allow access with NPS configured?19:46
nowendid you edit the user to say 'use nps'?19:47
bgeorge_Yup. But it get denied right away if i don't create a separate network policy to grant access19:47
nowenyeah, you need both19:48
nowendoes it work without WiKID?19:48
bgeorge_Yes19:50
bgeorge_It seems as if it wont forward the request. Are there logs I can check on the wikid server?19:51
nowenprobably nothing there because the request is stopping on nps.19:52
nowenyou can look at the MS logs, but they probably won't have much19:53
nowenwhat doc are you following? the eGuide pdf?19:54
bgeorge_ms only shows an event when it works, without wikid19:55
bgeorge_I followed this. http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps/view?searchterm=nps19:55
nowenyou might step through the NPS section of the eGuide to see if there is something you missed http://www.wikidsystems.com/learn-more/two-factor-authentication-white-papers19:57
nowenalso, you might try using the ip address of your vpn instead of time19:57
nowenwe don't really maintain working set ups for a lot of the stuff we test - if someone come in and wants to know if some setting works, we might test that.19:58
bgeorge_Thanks for that pdf, some nice evening reading. I'll report back tomorrow.20:10
nowenok - well, how about Monday?20:10
nowenand as always, we defer to MS documentation20:10
bgeorge_business tomorrow.20:11
*** bgeorge_ has quit (Quit: Page closed)20:12
*** nowen has quit (Quit: Leaving.)22:32

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!