Wednesday, 2013-01-30

*** nowen has quit (Quit: Leaving.)00:01
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid14:02
*** nowen has quit (Quit: Leaving.)18:04
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid19:15
*** entrans (be50c986@gateway/web/freenode/ip.190.80.201.134) has joined #wikid19:54
entranshello everyone - i have a question about replication and running two wikid servers in two different geographic locations - presumably two different external ip addresses - anyone have a moment to go through the details right now?19:55
joevanonowen: ^^^21:09
nowenentrans: hey21:09
nowenjoevano: thanks for the ping21:09
joevanonp21:09
nowenworking on an ossim/alienvault plugin and it's not working21:10
nowenentrans: is this for a new deployment?21:11
entransremember the chilean company you referred to me - its for them - so they apparently have an existing install that they need to migrate along with their other facilities to a new data center21:20
nowenahh21:20
entransso the trick is how to do it while leaving the old server up for current operations and migrating to the new server for future operations21:20
nowenok21:21
entransi gave some ideas based on what i understand but i wanted to talk it out with you to see if there maybe some options i haven't considered21:21
nowenso, we can set up the new server as the replicant and move the users over.  then we can set up a DNS entry to fool the tokens into going to the new IP21:22
entranswouldn't the token have to register to a new domain with the dns?  right now (I'm assuming) they are going to the padded IP address directly.  That said if it did work they would still be able to switch between the two at any time?21:24
nowenthe tokens check the IP and if that fails, check domainid.wikidsystems.net21:25
nowenthat's how we do the demo domain 8888888888821:25
entransokay so we can put something in the hosts file to fake the ip - got it21:26
nowenno need.21:26
entransexplain please...21:26
nowenwe'll put an entry into the wikidsystems.net dns pointing to the new IP21:27
entransthat saves going to every machine (or in cases of smartphones not having much option)21:28
nowenthe token will look up  xxxxxxxxxx.wikidsystems.net and get pointed to the new IP21:28
entransso i get that then - it handles not having to register to a second server - how do we give the option of going to one or the other for the 3 months of transition time they will need - this solution sounds like an all or nothing approach - am i wrong in that assessment?21:29
nowenno, you're right about that21:30
nowenthey need to get to both?21:30
entransyeah - because they have plan to move the datacenter over a period of time so they will need to get to one or the other of the sites until they bring down the original site entirely21:30
nowenhmm21:31
nowenhow many users?21:31
entrans5021:31
nowenwell, you could set up a webpage on the 2nd server protected by the first.  They login with their existing token and register the new domain on the new server21:32
entranswill the registration eliminate the need for an administrator to complete the process?21:33
nowenyes21:33
entransif so is that any different that what I've seen white papers on to integrate with AD to accomplish something similar?21:34
nowenvery much the same21:34
nowenin fact, the same code, just remove AD and put in WiKID21:34
entransokay - because that's what i've given them as a solution so far - since i'm not sure they are running an AD environment or that the wikid server can access it your idea is a good alternative21:34
entranscool21:35
entransanother question about ths21:35
nowenyeah,  probably best for the long run too21:35
nowenand our dns isn't in the middle21:35
entranswhat is the downside of creating a replica and then breaking the replica to have two masters - from a user migration, domain and network configuration perspective?21:35
entransyeah - having your DNS in the middle indefinitely could be a concern21:36
nowenthe users would have to re-register anyway.21:36
entransokay - i figured as much but i wanted to confirm21:36
nowenthose token keys are associated with the old domain21:36
entransexactly what i thought21:36
nowennetwork config would be ok21:36
nowenbut that21:36
nowenisn't much work anyway21:37
entransyeah but the network config is the easy part - its really the registered tokens i'm trying to work out21:37
nowenalso, I'm more comfortable if you set up the new server ;)21:37
entranslol - i understand21:37
entransok - i'll read up on the web page and AD approach and see what I can get cooking in the lab to be prepared21:37
nowenwill you be able to do this all remote?21:37
nowenif you look at the example.jsp page, it also has all the needed code.  pretty much 'login' and 'register'21:38
entranswell they told me they can give me remote access to their network and i have a few tricks of my own so as long as they can manage installing the image i should be able to take it from there21:38
nowencool21:38
entransexcellent21:38
nowenI might have another lead for you too. Let me dig it up21:39
entransi have to drop you a few e-mails about other clients - i'll be sure to reach out to you by tomorrow regarding those21:39
nowenok21:39
entransok - cool - just call me a wikid kind of guy ;-)21:39
nowenok - i'm heading home early today.22:06
nowenstorming here and that means bad traffic22:06
joevanohave a good one... I think our thunderstorms are over for the day, bring on the snow tonicght22:13
nowennice22:13
joevanostarted the day at 52 F low tonight is supposed to be 12 with 19 as a high tomorrow22:14
nowenbrr22:15
nowenlater!22:18
*** nowen has quit (Quit: Leaving.)22:18
*** entrans has quit (Quit: Page closed)23:03

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!