Wednesday, 2013-01-09

*** d1ZZy_ (c3fea40c@gateway/web/freenode/ip.195.254.164.12) has joined #wikid09:26
d1ZZy_does anyone know if you can integrate WIKID into Office365?09:30
d1ZZy_my client is unable to obtain configuration11:30
d1ZZy_i know the appropriate ports are open to the server11:30
d1ZZy_firewall traffic is showing GREEN for HTTP connection11:34
d1ZZy_server is sat in a 192 DMZ network11:35
d1ZZy_One client is in the LAN / One client is external11:35
d1ZZy_appropriate ports are opened and NAT'd11:35
d1ZZy_Wikid server only has one interface (a 192 address)11:36
d1ZZy_The server has a public IP and is NAT'd to the 192 address11:36
d1ZZy_ports 80 and 443 are open on the internet11:36
d1ZZy_i can browse to the portal11:36
d1ZZy_both from the LAN and the internet11:37
d1ZZy_i've also disabled IPTABLES for testing11:40
d1ZZy_public firewall is only allowing 80 and 443 IN to the server11:40
d1ZZy_i can also see the attempt when i tail the access log for today under /opt/wikid/tomcat/logs11:48
d1ZZy_ive also noticed the unregistered device count is increasing11:58
d1ZZy_and FYI im restarting and stopping the server with each change12:04
d1ZZy_Log entry (with IP MASKED out of the url with XXXXXXXXXXXX);12:11
d1ZZy_[09/Jan/2013:12:07:03 +0000] "POST /wikid/servlet/com.wikidsystems.server.InitDevice5AES?a=0&S=XXXXXXXXXXXX&lck=1&CT=0 HTTP/1.1" 20012:11
*** d1ZZy_ has quit (Ping timeout: 245 seconds)15:17
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid15:32
*** d1zzy_ (c3fea40c@gateway/web/freenode/ip.195.254.164.12) has joined #wikid15:34
d1zzy_sorry got disconnected15:34
d1zzy_nick if you can help!!15:34
nowenhey15:36
nowentoken still not connecting to the domain?15:36
d1zzy_nope15:37
nowenoffice365?15:38
d1zzy_not yet15:38
nowenwhat happens when you browse to the url in that post15:39
d1zzy_hi sorry got called away15:49
d1zzy_lemme  check hold on15:50
d1zzy_you mean if i browse to http://FQDNwikid/servlet/com.wikidsystems.server.InitDevice5AES?a=0&S=XXXXXXXXXXXX&lck=1&CT=015:51
nowenyes15:51
nowendoes it reach the server?15:51
d1zzy_http status 40515:52
d1zzy_i believe it does get to thre server15:52
nowenwhat's the domain id?15:52
nowendid you limit the domain to any type of token or enter a registered url?15:52
d1zzy_you mean the padded ip?15:52
nowenyes15:52
d1zzy_no neither15:52
d1zzy_195.254.164.18015:52
d1zzy_my public server on http and https15:53
d1zzy_want to connect to it?15:53
d1zzy_im watching the log15:53
nowen195254164180 ?15:53
d1zzy_yes but you browse to 195.254.164.180 you mean15:54
d1zzy_50.194.249.125 - - [09/Jan/2013:15:54:06 +0000] "POST /wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=195254164180&CT=1 HTTP/1.1" 200 1 50.194.249.125 - - [09/Jan/2013:15:54:12 +0000] "GET /wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=195254164180&CT=1 HTTP/1.1" 405 1112 50.194.249.125 - - [09/Jan/2013:15:54:13 +0000] "GET /favicon.ico HTTP/1.1" 200 29015:54
d1zzy_i guess thats ur ip?15:54
nowenis the domain identifier 195254164180? on the WiKID server, that is15:55
d1zzy_sorry i deleted them, will readd now....15:55
nowenyou deleted what?15:55
d1zzy_sorry the domain and network clients15:56
d1zzy_let me re-add15:56
d1zzy_what do i put in network client for any ip?15:56
d1zzy_0.0.0.0 ???15:56
nowenjust do the domain first15:56
nowenone step at a time15:56
nowenwhich doc are you working off of?15:56
nowenI recommend: http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server15:57
d1zzy_http://www.wikidsystems.com/support/support/videos15:57
nowenmore details in the manual15:57
d1zzy_added domain, just restarting server15:58
d1zzy_and its back up15:58
nowenyou only need to restart after adding a radius network client15:58
nowenand now it is working15:58
d1zzy_oh ok15:59
d1zzy_no not working15:59
d1zzy_im trying the android client15:59
d1zzy_to try to connect publicly15:59
d1zzy_hmmm16:03
d1zzy_?16:03
d1zzy_i dont have a network client configured yet though16:03
nowenif your tokens are working, then I think you can add a network client16:03
d1zzy_so for clients connecting from many different ip addresses what do i put in the network client?16:04
nowenthe token clients don't know about the network clients16:04
d1zzy_can you confirm the following for me please?16:05
d1zzy_1. My server is in a DMZ (192 address). It has one ethernet interface. It is NAT'd to a public IP. Is this ok?16:06
d1zzy_2. Ports 80 and 443 are open for ANY to public IP -> NAT'd -> server16:06
d1zzy_is that correct?16:06
d1zzy_for testing I have disabled IP tables16:07
nowenthat depends on what you want. Do you want the WiKIDAdmin UI open to the internet?16:07
d1zzy_not really16:07
d1zzy_i just need the token client to able to communicate to receive the OTP16:07
d1zzy_ive had this working all in the same network segement16:17
d1zzy_doesn't seem to like NAT or DMZ16:17
nowenwhat's not working16:17
nowen?16:17
nowentoken works for me16:17
d1zzy_oh16:18
d1zzy_is it my token client then?16:18
nowenare you on the lan?16:18
d1zzy_im on the lan16:18
d1zzy_my phone is on an ADSL connection16:18
nowencan you access the serve UI?16:18
d1zzy_yes16:18
nowenon the external IP16:18
d1zzy_on both the external and DMZ ip addresses16:19
nowenand you can't get an OTP?16:19
d1zzy_no16:19
d1zzy_sorry i thought i said that16:19
nowenwhat about on your android via the cell network?16:20
d1zzy_same16:20
d1zzy_if i try to add a domain with the padded IP it tries then goes back to the original screen16:21
nowenTrans 2FA external is you domain name?16:21
d1zzy_i did notice in the log when you connected you get 3 lines in the log / im only getting 1 line16:21
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-run-the-token-in-debug-mode16:21
d1zzy_again i see ur connection16:21
nowenclearly some networking issue on your end16:21
d1zzy_how if you're connecting?16:22
nowenyou are trying to add 195254164180 to the token?16:22
d1zzy_plus im trying from my cells network and from a seperate adsl connection16:22
d1zzy_yes16:22
nowenwhat do the logs say when you connect? What's the debug output from your token?16:23
d1zzy_ill have to disconnect my laptop and use the adsl connection16:23
d1zzy_50.194.249.125 - - [09/Jan/2013:16:21:03 +0000] "POST /wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=195254164180&CT=1 HTTP/1.1" 200 426 50.194.249.125 - - [09/Jan/2013:16:21:08 +0000] "POST /wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=1&D=1119504358160292377&S=195254164180&CT=1 HTTP/1.1" 200 528 50.194.249.125 - - [09/Jan/2013:16:21:18 +0000] "POST /wikid/servlet/com.wikidsystems.server.WikidCode3AES?S=195254116:24
d1zzy_first three logs are urs16:24
d1zzy_last one is my mobile cell network16:24
d1zzy_82.132.237.205 - - [09/Jan/2013:16:23:30 +0000] "POST /wikid/servlet/com.wikidsystems.server.InitDevice5AES?a=0&S=195254164180&lck=1&CT=0 HTTP/1.1" 200 -16:24
nowenthis is the16:26
nowencommunity edition?16:26
nowenhttp://www.wikidsystems.com/community-version/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release/?searchterm=what%20is%20the%20difference16:26
d1zzy_yes16:26
nowensmart phone tokens are not supported. we use a 3rd party package for encrpytion16:27
d1zzy_desktop tokens supported?16:31
nowenyes16:34
d1zzy_brb to test16:35
*** d1zzy_ has quit (Ping timeout: 245 seconds)16:40
*** d1zzy123 (5189d267@gateway/web/freenode/ip.81.137.210.103) has joined #wikid16:46
d1zzy123still same16:46
d1zzy123i have uninstalled the client16:46
d1zzy123can you suggest which one to use16:46
d1zzy123im on the adsl connection now16:46
nowenwhich one are you using?16:47
d1zzy1233.1.23 bundle installer16:48
d1zzy123from the sourceforge website16:48
d1zzy123ive also tried the executable16:48
nowenand you're running it in debug mode?16:48
d1zzy123unlocked client16:48
d1zzy123no i will do now......16:49
d1zzy123damn gotta go to a meeting will try tonight and report back16:50
d1zzy123i do appreciate your help nick16:51
d1zzy123enjoy ur evening16:51
d1zzy123bye16:51
nowenlater16:51
*** d1zzy123 has quit (Client Quit)16:51
*** Mustio has quit (Ping timeout: 245 seconds)20:53
*** d1zzy_ (569ff3d8@gateway/web/freenode/ip.86.159.243.216) has joined #wikid22:27
d1zzy_good evening22:27
nowenhi22:27
d1zzy_you there nick?22:27
d1zzy_well22:27
d1zzy_i tried the client from my home windows 7 pc22:27
d1zzy_worked fine22:27
d1zzy_it must be somethign to do with my laptop22:27
d1zzy_how can i completely remove any reference to any save settoings for the token client22:28
d1zzy_everytime i try a new client it remembers details from initial setup even after ive uninstalled and deleted files from program files22:28
nowenwell, you can delete the wikidtoken.wkd file22:28
d1zzy_where is that stored by default?22:28
nowenI can't remember on windows22:29
nowennot sure that would be it22:29
d1zzy_lol22:29
nowenmore likely you have a firewall or anti-malware tool running22:29
nowenesat?22:29
d1zzy_esat ?22:29
nowenesat is an anti-spyware tool22:29
d1zzy_nope22:29
d1zzy_windows firewlal isnt running22:30
nowensomething blocking the token from writing a file22:30
d1zzy_ive got an antivirus client22:30
d1zzy_my account is local admin22:30
d1zzy_it must be my antivirus maybe22:33
d1zzy_ill see if i can disable it tomorrow22:34
d1zzy_one more thing22:34
d1zzy_in order to get the token do i only need tcp 80 open on the internet?22:34
d1zzy_i dont really want the portal live on the internet22:34
nowenyes, only port 8022:34
d1zzy_ok ill test tomorrow and see what happens ill let you know22:35
d1zzy_thanks again22:35
d1zzy_GETTING THERE!22:35
nowenglad to hear!22:35
d1zzy_the vpn client failed to authenticate on a challenge response22:37
d1zzy_probably a config error with tacacs+ setup on the actual firewall22:38
nowenI doubt you will need challenge response22:38
d1zzy_C:\Documents and Settings\adiscala\Application Data\WiKID22:39
d1zzy_thats where the file is22:39
d1zzy_bollox22:39
d1zzy_lol22:39
d1zzy_it wortks now22:41
d1zzy_must have been a corrupt wkd file maybe?22:41
d1zzy_:p22:41
nowenmaybe22:41
d1zzy_well im glad we have figured it out! got there eventually22:44
d1zzy_thanks for all ur help22:44
nowennp22:44
d1zzy_ive added a network client22:44
d1zzy_but what ip do i put in?22:44
nowenthe IP of your vpn or whatever the network client is22:45
d1zzy_so i am at home22:45
d1zzy_would i have to give the ip of my home connection?22:45
d1zzy_that would be very difficult to track with remote users and dynamic ips22:46
nowenno, you're not understanding the architecture22:46
d1zzy_the ip address of the firewall22:47
nowenwhat are you trying to do?  protect a VPN with 2fa, right?22:47
d1zzy_yes22:47
nowenthe IP of the VPN22:47
nowenthen the VPN needs to talk to the WiKID server22:47
*** bman1 (~burrutia@64.19.224.6) has joined #wikid22:47
d1zzy_so if the vpn resides on the firewall would it be the internal ip of the firewall or its public ip?22:47
noweninternal22:48
bman1is there a paritcular port that wikid connections come in on? I have a task of putting some boxes behind an LB and need to know the port to send the connections thru besides the default https22:48
d1zzy_thanks22:48
nowenbman1: the tokens use port 8022:48
bman1ok thanks22:49
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/what-ports-are-needed-for-wikid-how-do-i-know-if-the-listener-running-on-the-server?searchterm=what+ports+do+22:49
bman1thanks22:49
nowendepends on your setup, of course22:49
bman1well from firewall to load balancer is my concern22:50
bman1all others will have backend connection22:50
d1zzy_thanks again nick22:53
d1zzy_night22:53
nowengood night22:53
*** d1zzy_ has quit (Quit: Page closed)22:54
*** nowen has quit (Quit: Leaving.)23:15

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!