Friday, 2013-01-18

*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid15:31
bman1anyone in here?19:21
nowenyes19:24
bman1hello Nowen, ok so I have a question on how using ADRegister, after thats setup which works fine, once the wikid client connects and gets a  a token if the user still utilizes that or their ad creds to authenticate say via a firewall19:25
bman1for example the client can get a token then I have a cisco fwsm which intercepts the request to auth and then should connect back to 2factor to the wikid server19:26
bman1however that final stage I am still wondering what the best method to auth is, i.e. via ldap or tacas?19:27
bman1i would think ldap19:27
nowenADRegister is completely separate - it is registering a token.  the firewall process is authentication19:27
bman1ok right, so the register part is fine19:27
nowenradius!19:27
bman1so when the client connects it gets a token, i assume i still use that19:27
bman1radius is preferred?19:28
nowentechnically,  the use the token to get an OTP19:28
bman1right19:28
nowenyes, radius is the best19:28
bman1ok ill give that a try19:28
bman1for radius i would have it go back to AD correct? I want to make sure I understand correctly19:29
nowenif you're using NPS19:30
nowentake a look at this guide: http://www.wikidsystems.com/webdemo/Two-factor_Authentication_in_your_Network_eGuide.pdf19:30
nowenit shows how to set up FW >> NPS/AD >> WiKID19:30
bman1ok thanks19:31
bman1hmm i was assuming it would go  FW>>WIKID>> NPS/AD since it goes FW>>WIKID>>POSTGRES but will relook ( trying to minimize change from where/how our older arch is setup)19:40
nowenWiKID won't proxy anything to NPS.  it's an authoritative endpoint19:41
nowenyou can do FW >> WiKID, but then AD is out of the picture19:41
bman1i see, so if i were to attempt ldap it would also be the same or could I do FW>> WIKID>>LDAP?19:44
bman1the reason is also that windows is managed by another team in my co19:44
bman1and they are not the most ...19:45
nowenyou can't proxy from WiKID using any protocol19:45
bman1well they are good people but we'd like to avoid having them manage more apps19:45
bman1ok thanks19:45
nowenyou can avoid windows altogether and have the users in WiKID19:45
bman1yeah we have that already, thats not what we want however19:46
nowenyeah, then NPS is the way19:46
bman1its ok, I'll figure it out19:46
bman1thanks yeah19:46
joevanobman1: i set up nps lastweekend with wikid in about 15 minutes... very straight forward20:43
nowenjoevano: what doc did you follow? one of ours or MS?20:47
joevanoyours mostly20:55
joevanofor the actual config... theirs for the install and some prelim research20:56
nowenI find that if you need a lot of details, our docs don't cut it.20:56
nowenbut we aren't trying to replace theirs...20:56
joevanoyeah, I read up on it first so I knew what was expected20:57
bman1joevano thanks for your comment , however as I stated our windows team is different23:08
bman1they are a sep unit and mostly desktop support23:08
bman1its not so much as to how much time it would take or how many steps, its partially a wait thing23:09
*** nowen has quit (Quit: Leaving.)23:31

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!