Thursday, 2013-02-14

bman1ok so windows 2008 server R2 for NPS is a bit different that the document has this been tested?00:39
bman1then again could be person I am talking to but something appear different00:40
bman1is there a revised document anywhere?00:40
bman1nm, think its  them, i.e. sep department00:46
bman1had to go back over document w them00:46
bman1so i assume the doc for setting up wikid as a radius server is here?00:47
bman1http://www.wikidsystems.com/support/wikid-support-center/how-to/pam-radius-how-to00:47
bman1nm seemed too simple will try and stop bugging thought i saw something diff before00:50
bman1ok so found something I don't see covered, Radius Specific parameters, Assign Return Attribute: ? its a drop down cant find which to use the NAS ip address?01:10
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:59
nowenbman1: you here?14:34
bman1yes18:32
nowendid you get your radius question answered?18:32
bman1well kinda, one thing im not sure of is that if actually freeradius daemon need be running, I saw no mention of it in the docs, however I found a doc someone else published on centos and they stated it need be running18:33
bman1however i have some issue with radius daemon talking to wikid18:33
nowenare they running on the same box?18:34
bman1yes18:34
nowenare you using freeradius as a radius server?18:34
bman1yes, I have also installed pam_radius as per doc18:35
bman1i have a vm setup ( that other team setup ) as NPS18:35
nowenok, so know that WiKID is not a radius 'server' in the way freeradius or NPS is.  it is a 'radius server' in that it is the authoritative authentication source18:36
nowenfreeradius and nps will do other things, like validate that a user is in AD/ldap and has the right perms18:36
nowenthat is, they will do autorization18:36
nowenauthorization18:36
bman1right i understand that part but then not sure where my setup is messed up18:37
bman1i was looking at this doc 1 second18:37
nowenthere's no need for both freeradius and NPS18:37
bman1http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/how-to-install-the-wikid-strong-authentication-server-enterprise-edition-page-418:37
bman1ok18:37
bman1so the pdf i have for NPS18:38
bman1the eguide for adding 2 factor auth to your corp network18:38
bman1seems to indicate that once nps is setup18:38
bman1it should point to freeradius18:38
bman1or i mean radius18:38
nowenso, it should go:  pam_radius >> NPS/AD >> WiKID18:39
nowenthe >> are all radius transactions18:39
bman1ok so the radius daemon is not needed to be running18:39
nowenno18:39
nowenin fact, it would most likely cause networking confusion18:39
bman1ok so at the network level the nps server connects to wikid on the udp radius port?18:40
nowenyes, port 181218:40
bman1ok so restarted wikid to see if that port comes up, i might need to tweak log4j settings because i set to debug but still am not getting allot of logging to see whats going on18:42
bman1ok i see the port on udp thanks18:43
bman1will test a bit more thanks18:43
nowenso, netstat should show that java is listening on 181218:44
bman1im using radtest to try and test stuff will post back in a bit if i cant figure it out, i see the port is up now but radtest failed18:44
bman1yes it is18:44
bman1udp        0      0 0.0.0.0:1812                0.0.0.0:*                               25098/java18:45
nowenare you running radtest from an IP listed as a network client?18:45
bman1yes18:45
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests18:45
bman1cool thanks18:45
nowenalso, 'tcpdump port radius'18:45
bman1yeah i plan to18:45
nowenwill show if the packets are getting to the server18:45
bman1i know packets can get to it, because the radius server saw the connections in the logs and said the ip was zombie18:46
bman1so its not network18:46
nowenok18:46
nowengotta run an errand.  back in a bit19:07
*** nowen has quit (Quit: Leaving.)19:07
*** Tyler_ (8eb1ec77@gateway/web/freenode/ip.142.177.236.119) has joined #wikid19:39
Tyler_Hey anyone on?19:40
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid19:40
bman1damm still cannot get any logging, i've set the logging options via UI and they are persistent but nothing new is logging19:51
bman1i can see tcpdump connections from network client19:51
nowenis the date correct on the server?19:52
bman1but dont know whats going on, is there a manual way to change the logging in log4j19:52
bman1yes ntp is in sync19:52
bman1i can see reg http connections logging via the web ui and reg logging in catalina.err and out19:53
bman1just new logging options from ui are not being picked up19:53
nowenanything in /opt/WiKID/log/radius.log?19:53
bman1no its blank19:53
nowendid you add the radius logger?19:53
bman1i was hoping it would start writing to it, yes i did via the ui and set to debug19:54
bman1nothing, is there a way to manually put in the string via cli?19:54
bman1i.e. log4j.properties?19:54
nowendid you restart WiKID? because that will reset the loggers19:54
nowenyes19:54
nowenhttp://www.wikidsystems.com/WiKIDBlog/big-data-vs-easy-data-the-wikid-ossim-plugin for example19:54
nowenthat file should be well commented19:54
bman1thx19:54
bman1ok thanks now i have some logging20:02
nowencool20:02
nowenwhat does it say?20:06
Tyler_Hi. I am at a real loss regarding the ISO version and the Radius client. Is this the right place for assistance?20:22
nowensure20:35
nowenTyler_: what's going on?20:35
Tyler_Great20:37
Tyler_I am not sure what information you need but I am using the ISO version. When trying to connect to the WiKID Radius it timesout.20:38
nowen did you create a network client?20:38
Tyler_I can see the packets from the TCPDUMP on the WiKID server but the WiKID server Radius does not respone20:39
Tyler_Yes I did.20:39
nowenand did you run 'wikidctl restart'?20:39
nowenhold on = brb20:39
Tyler_I have created two client networks in order to further troubleshoot. Both client networks are attempting to communicate via different clients20:40
Tyler_I have restarted yes. I have been trying to get this working for a week now. I have gone so far as to uninstall and reinstall the entire OS again.20:41
Tyler_It is the same issue even though I have uninstalled and reinstalled the ISO. Everything else works like a charm.20:42
nowendo you have radius logging set to debug?20:44
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests20:45
Tyler_I tried that as well.20:45
nowenany radius error messages?20:45
Tyler_Nothing shows up in the logs other than the fact that I turned on debug.20:47
nowenrun 'netstat -anp | grep 1812' and make sure that the listener is up20:47
nowenit should state that java is listening on the port20:47
Tyler_if I look at /opt/WiKID/log/radius.log directly I do see an error.20:48
nowenwhat is that?20:48
Tyler_java.net.SocketException: Broken pipe         at java.net.SocketOutputStream.socketWrite0(Native Method)         at java.net.SocketOutputStream.socketWrite(SocketOutputStream.java:109)         at java.net.SocketOutputStream.write(SocketOutputStream.java:153)         at sun.security.ssl.OutputRecord.writeBuffer(OutputRecord.java:314)         at sun.security.ssl.OutputRecord.write(OutputRecord.java:303)         at sun.security.ssl.SSLS20:48
nowendid you create certificates during the install?20:48
Tyler_I did yes.20:49
nowenand a localhost cert?20:49
Tyler_drwxr-xr-x  3 wikid root  4096 Feb 14 16:45 . drwxr-xr-x 13 wikid root  4096 Feb 14 13:25 .. -rw-r--r--  1 wikid wikid 2760 Feb 14 14:27 CACertStore drwxr-xr-x  2 wikid root  4096 Feb 14 13:25 googlesso -rw-r--r--  1 wikid wikid 2311 Feb 14 14:28 localhost.p12 -rw-r--r--  1 wikid root  1752 Oct  4 16:28 WiKIDCA.cer20:49
Tyler_Yes a localone as well.20:49
nowenrun 'netstat -anp | grep 1812'20:50
Tyler_I have followed http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/referencemanual-all-pages to a tee 3 times now. Ok one second20:50
Tyler_udp        0      0 ::ffff:127.0.0.1:1812       :::*                                    7293/java20:50
nowenhmm, should be 0.0.0.020:53
nowenok, go to Configure / Enable Protocols /20:53
nowenand Radius20:53
Tyler_BRB20:53
nowenwhat's there?20:53
Tyler_RADIUS is ENABLED [ DISABLE ] Host Name:WiKID Radius IP Address:127.0.0.1 Port:181220:54
nowenhmm20:56
nowenwhat version is this?20:56
Tyler_3.5 build 0-b135920:57
Tyler_I am using a dual network card setup. One private and one public (DMZ). I have access through the VMWare console. Would you suggest I remove one of the NIC's and try again from Scratch?20:58
Tyler_At this point that is the only thing I have not tried/20:59
nowenit should work fine with two  nics20:59
Tyler_Ok.20:59
nowenI'm grabbing that iso to build a test21:00
Tyler_Is there a newer ISO?21:01
nowenyes21:01
nowenhttp://wikidsystems-dl.com/wikid-enterprise-3.5.0-b1403-install.iso21:01
Tyler_OH!!!!!21:01
Tyler_Let me try that.21:01
Tyler_I will get back to you either way. Thanks.21:02
nowenlisten21:02
nowenI'm traveling from tomorrow until a week from monday21:02
noweneither use the forums or email contact form21:03
nowenor my email if you have it21:03
Tyler_Will do thanks!21:03
nowennp21:03
nowenI bet that's it b/c the changelogs list a radius fix21:03
nowen Tyler_ if you didn't get my email response to your download, my email is nowen at wikidsystems.com21:19
bman1ok mine worked now, so remainder shd be making sure acls are good, thanks all21:34
bman1        Reply-Message = "Access Granted"21:35
nowenbman1: great!21:45
bman1just have to figure fw out now shouldn't be too much of issue thanks22:23
*** nowen has quit (Read error: Connection reset by peer)23:18
*** Tyler_ has quit (Ping timeout: 245 seconds)23:43

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!