Monday, 2013-03-04

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:13
*** markw78 (~mark.wole@38.83.98.34) has joined #wikid17:14
markw78hi17:14
markw78getting an error about currput keystore or something, and there's a SSL error in the RADIUS log17:15
markw78not really sure what to do, can't find the password for the tomcatKeystore (if thats where I should be looking)17:15
nowenwhat version of WiKID is this?17:16
markw78not sure... sec17:17
markw78probably older17:17
markw78wikid-server-enterprise-3.4.87-b109217:17
nowenyou probably just need to update your certificates, maybe just the localhost17:17
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid17:18
nowenwill show you how17:18
markw78ok I will check that out17:18
nowenwe're up to 3.5 too, upgrading is probably a good idea17:18
markw78java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.17:18
markw78same error I get in the Wikid Logs in the web UI17:18
markw78ERRORcom.wikidsystems.client.wClientERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.17:19
markw78maybe I just recreate via wikidadmin?17:20
nowenis this for the localhost?17:20
nowenyes, are you only using radius?17:20
markw78I think so, thats the log in the Wikid log when I click Logs and Filter17:20
markw78yes17:20
markw78only radius17:20
nowenthen recreating should be fine17:20
markw78ok17:21
markw78<create a localost certificate>17:21
markw78oh I was using the wrong password on the keytool command :/17:22
markw78sure enough17:22
markw78expired today17:22
nowenif the IntCA is ok, then you can just create a new localhost17:22
markw78oh17:25
markw78its not expired, I just can't read17:25
markw78Valid from: Tue May 11 04:31:01 EDT 2010 until: Fri May 10 04:31:01 EDT 201317:25
markw78its the only cert in the store17:25
markw78Your keystore contains 1 entry17:26
markw78Alias name:17:26
markw78Creation date: Mar 4, 201317:26
nowenI would go ahead and create both anew.17:26
markw78Weird that the creation date shows that17:26
markw78ok17:26
markw78/opt/WiKID/private/intCAKeys.p1217:27
markw78thats the localhost?17:27
nowenthat's the intermediate CA.  localhost.p1217:27
markw78ah17:27
markw78I have 2 passwords documented trying to figure out which is which heh17:28
markw78oh I see, reread the KB heh17:28
markw78sorry17:28
markw78localhost expired 2 months ago17:29
markw78but this just broke overnight17:29
markw78I'll recreate both17:29
nowendid you restart overnight?17:29
markw78hmm over the weekend possibly, yah17:30
markw78thats probably it17:30
markw78yah17:30
markw78we did a vmware tools update yesterday17:30
markw78so now I just need to figure out the 2 passwords, it said my keystore password isn't right for the store ;/17:30
markw78there17:31
nowenyou can change them when you re-create17:31
markw78when I recreated it said the keystore password wasn't right, I tried the other one and it worked tho17:31
markw78bleh can't get a token now17:37
markw78Can't start RADIUS Server17:37
nowenhmm, that should not be affected by the certs17:38
nowenis there an error?17:38
markw78yah, in the wikidlog17:38
markw78the radius.log has this...17:38
markw78log4j:ERROR Could not connect to remote log4j server at [localhost]. We will try again later.17:38
nowenthat doesn't relate to this17:39
markw78ok17:39
nowenrun 'netstat -anp | grep 181217:39
nowen '17:39
nowenand see if the radius listener is up17:39
markw78yah17:39
markw78java listening17:39
nowenok - it can take a while for radius to start b/c it needs random info17:39
nowenthe updated versions start radius faster17:40
markw78argh17:40
markw78com.wikidsystems.client.wClientERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.17:40
markw78I just made the new one lol17:40
nowenhmm17:40
markw78that error just happened17:40
nowenthis is after you restarted WiKID?17:40
markw78yah, I updated the localhost cert, and rebooted the box17:41
markw78I wonder if I need to update my password for it somewhere?  but that would prevent wikid from starting all together I thought?17:41
nowendid you get prompted for the passphrase on start?17:41
nowenthe intermediate CA passphrase, which is used to start the server, can be entered into /etc/WiKID/security17:43
markw78oh we got a passcode now17:43
markw78thats the file I was thinking of17:44
markw78ok let me check17:44
markw78ok we get a token now, but still can't connect heh17:44
nowencan17:44
nowencan17:45
nowenerp17:45
nowencan't connect meaning?17:45
nowen VPN ?17:45
markw78yah vpn sorry17:46
nowenok= any error in the wikid admin logs?17:46
markw78having someone check17:46
nowenalso, make sure that the user is still enabled17:46
markw78yah did check that17:46
markw78we have the passphrase in the file17:47
markw78and wikid starts, can get tokens... so the passphrase should be OK?17:47
markw78or could it still be wrong?17:47
nowenif it is wrong, the server won't start17:47
markw78ok, thats what I thought17:47
markw78so that should be ruled out17:47
nowenyes17:47
nowendid any ip addresses change?  for the vpn ?17:48
markw78awhle back17:48
markw78we had you create a DNS alias for us17:48
markw78so its slow to get a token, and that part works17:48
markw78but its possible this is the first server restart since then?17:48
nowenmaybe17:49
markw78radius log has stuff now17:50
markw78nothing new in the GUI log17:50
nowenyou might want to set radius logging to debug: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests17:51
markw78ah I was filtering wrong too17:54
*** josha (~josh.arri@38.83.98.34) has joined #wikid17:54
markw78<10> Access-Request(1) LEN=275 192.168.10.245:51354 Access-Request by user.name Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.17:55
nowenhmm17:55
markw78checking the domain controller / IAS server17:56
markw78thats the error on the wikid server, when I check the radius server I see this17:57
markw78 Reason = The remote RADIUS (Remote Authentication Dial-In User Service) server did not process the authentication request.17:57
markw78lol17:57
markw78tcpdump time17:57
nowenthere have been a lot of updates to the radius plugin.17:58
nowenI don't think it would cause these issues though17:58
markw78yah, its weird that it just stopped after the reboot  I guess :/17:58
nowenI'll post the newest rpms and you can download them.17:58
nowenhttp://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1411-1.noarch.rpm17:58
nowenand17:58
markw78ok17:59
nowenhttp://wikidsystems-dl.com/wikid-utilities-3.4.2-1.i386.rpm17:59
markw78wikid is sending a reject radis packet17:59
markw78back to the radius server17:59
nowenyou have to update both17:59
markw78VPN sends request to RADIUS server, RADIUS server sends request to WIKID, WiKID rejects it17:59
nowenhmm.  no way the shared secret changed, right?18:01
markw78I'm fairly sure not18:01
nowencan you take a snapshot and then do the RPM upgrade?  'rpm -Uvh wikid...' should do it18:02
markw78yah18:02
nowenThere was one fix for radius that might be it, and md5 issue18:02
markw78will we need to reconfigure the security file or startup or anything?18:02
nowenyou might need to re-edit it.18:02
markw78ok18:03
nowendo you'll use the example.jsp or adregister?18:03
markw78adregister18:03
nowenmake a copy of it as it will get overwritten18:03
markw78alright18:03
markw78yah the wikid log just shows an auth failure for MS-CHAPv218:03
markw78like both servers are blaming each other, but the tcpdump showed the wikid server the source rejection... going to try the upgrade18:04
markw78thx for the help btw18:10
nowennp, sorry for the issue18:10
markw78happens18:10
markw78if it didn't us IT folks would be out of jobs lol18:10
nowenha18:10
markw78ok18:17
markw78upgraded, I Went to copy my adregister back18:18
markw78and the ADregister folder isn't there18:18
markw78/opt/WiKID/tomcat/webapps/wikid/ only has ROOT, and 2 .war files18:18
markw78suppose thats not really important right now tho18:18
nowenhmm18:18
nowenare they WiKIDAdmin and wikid?18:18
markw78right18:18
markw78I just restarted the service after the update...18:19
markw78Starting database...Success!18:19
markw78Applying cumulative schema updates...18:19
nowenok18:19
markw78now services starting18:19
markw78Passphrase is good18:19
markw78ok18:19
markw78let me go find someone to test18:19
markw78left my token at home lol ;/18:19
nowenyou can create a new one ;-)18:20
markw78true18:20
markw78I do need to setup a new domain18:21
markw78but I tried and couldn't get it working :/18:21
joshawill we be needing to update anything on the tokens or will they continue to work?18:21
markw78(to deal with our IP change so we can get rid of the DNS timeout lag)18:21
markw78^^ josha = coworker18:21
nowenhmm, dns shouldn't be that slow18:21
markw78login failed again :/18:21
nowenjosha: if we're not changing the domain, the tokens shouldn't need to be altered18:22
joshaawesome18:22
nowenmarkw78: you will probably have to enable radius debugging again18:22
markw78ok, checking that now18:22
markw78ok failed... refreshing log filter18:24
markw78This is a MSCHAPV2 request18:25
markw78trace com.mchange.v2.resourcepool.BasicResourcePool@ef5502 [managed: 3, unused: 2, excluded: 0] (e.g. com.mchange.v2.c3p0.impl.NewPooledConnection@1c0e45a)18:25
markw78<18> Access-Request(1) LEN=275 192.168.10.245:51354 Access-Request by mark\ Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.18:25
nowenif you want you can post it to pastebin.org18:25
markw78I don't see any more details, other than the whole RADIUS Packet in the log18:26
nowenyeah, let me see the packet18:26
markw78ok18:26
markw78http://pastebin.com/GG7rjb1d18:27
markw78I replaced the actual username with user.name18:27
markw78and formatting leaves a lot to be desired... but there it is18:27
nowendamn, I'm not sure why it would stop working all the sudden.  the cert issue stopped it from starting properly, but no settings changed18:29
markw78yah18:29
nowenis the date correct?18:30
markw78where18:30
markw78just in general?18:30
markw78its the wrong time zone, but otherwise the time/date is right on the OS18:30
nowenon WiKID18:30
nowenhuh, did you move the server or was it never right?18:31
markw78no its never been right as far as I know18:31
markw78just the wrong timezone set18:31
markw78thinks its EST18:31
markw78at least I think it's always been like that?18:31
markw78let me see18:32
markw78ugh18:33
markw78I just typed setup18:33
nowentry /usr/bin/system-config-time18:33
markw78and its running wikidsetup18:33
markw78oh phew :)18:33
markw78ok time info all right now18:34
markw78restarting wikid18:35
nowenyep18:35
markw78the ADreigster stuff, do I just need to manually create the folder/files ?18:35
nowenyou can copy your old one over or just edit the new ones18:36
markw78but the folder was missing when I looked18:36
markw78unless it's there now18:36
nowenshould be there18:36
markw78there it is18:36
markw78I guess it was the schema update thing18:36
nowenalso, on the loggers  > configure loggers page, set the middle three loggers to debug18:36
markw78ok18:37
markw78still can't auth18:37
nowennote that you can save the config on a restart, but don't leave it in debug for production, our your logs will overflow18:37
markw78ok18:37
nowenchange those loggers and retry. hopefully, more info will help18:38
markw78gotta re-add the radius one too18:38
markw78no change18:41
markw78new log:  http://pastebin.com/ngW0SqmM18:41
markw78on the domain controller side, just get " Reason = The remote RADIUS (Remote Authentication Dial-In User Service) server did not process the authentication request. "18:41
nowenthere should be more log data though18:42
nowenyou should see the passcode18:42
markw78checking18:42
nowenis 192.168.10.245 the radius server?18:43
markw78yes18:43
markw78MS IAS18:43
nowenand that's what's listed on the Network Client page?18:43
markw78I don't see anything about the passcode18:43
markw78Network clients has that I in it twoce18:43
markw78I was trying to setup a 2nd one a long time ago18:44
markw78so the same thing is in there twice18:44
markw78maybe I should delete one?18:44
nowenyes, I think so18:44
markw78Also under Certificate it says N/A for both, but I think thats Ok18:44
markw78ok18:44
markw78oh yah I duplicated out domain too18:44
markw78with a new domain ID18:44
markw78I'll delete that also18:44
markw78restarting18:45
markw78awhile back we changed our VPN IP and Wikid server IP, so you put a DNS work around in place for us... but that makes it slow, because the first attempts have to timeout first...  so I was trying to setup a new domain using the new IP's18:46
markw78but the domain name etc was all the same, so maybe that confused things when the services started18:46
markw78still fails :/18:47
nowenhmm18:47
markw78log looks the same18:49
markw78I could check the radius passphrase, thats easy to do and independant of things right18:50
markw78was also thinking of making a new user18:50
markw78I still don't see the passcode logged tho18:50
nowencan you try a pap request from nps?18:50
markw78not sure how18:50
nowendo you have com.wikidsystems.client.wClient and com.wikidsystems set to debug?18:51
markw78http://pastebin.com/qSAnvDrm18:51
markw78checking18:51
markw78yes18:51
markw78alld ebug except HTTP access logger and org.apache18:52
nowenyou can change the encoding settings on NPS18:52
nowenfrom chap to pop18:52
nowenerr pap18:52
markw78we're not using NPS18:53
markw78windows 2003 - IAS18:53
markw78let me check18:54
nowenoh, yes18:54
markw78unencrypted PAP?18:54
markw78and should I uncheck CHAP or leave them both?18:55
markw78change to... sounds like uncheck :)18:55
nowenuncheck chap18:55
nowenand let's see18:55
markw78failed18:55
markw78want to check the log I assume18:55
nowenhmm18:56
markw78nothing new :/18:56
markw78http://pastebin.com/4rz2QKBa18:57
nowenstill thinks it's a chapv218:58
markw78interesting18:58
nowenok - run 'wikidctl stop18:59
nowenand the 'killall -9 java'18:59
nowenand then start again18:59
nowenmaybe the radius cache is not getting cleared out18:59
markw78ok18:59
markw78bounced IAS too18:59
markw78interesting19:02
markw78it worked now... BUT the radius.log still says MSCHAPV2 lol19:02
markw78"This is a MSCHAPV2 request"19:02
markw78let me re-enable CHAPV2 and see19:02
markw78starting back up19:06
markw78ok CHAP is working too,  this really makes no sense at all :/19:09
markw78I mean root cause is probably the cert... but I rebooted the whole server after I fixed the cert...19:09
nowenyes19:09
markw78and we restarted IAS earlier this morning19:09
markw78some random magic combonation though19:09
markw78and an upgrade :D19:09
nowenI  know that radius caches a lot of stuff.  I can't believe it made it through the upgrade19:10
markw78yah19:10
nowentake a look at this: http://www.wikidsystems.com/downloads/changelogs/enterprise-changelog19:10
markw78I guess I didnt reboot after the upgrade19:10
nowenyou shouldn't have to19:10
markw78I just mean to fully clear our all the cache/ram etc19:10
markw78we need to pay more attention to the server in general though lol, its been so solid it just sorta works19:11
nowenhehe19:11
markw78also could have had something to do with my duplicate domain info in there19:11
markw78I do need to setup a new domain ID for the same domain tho, so we can get rid of the DNS work around19:11
nowenyeah, that could have confused the radius request19:11
markw78yah19:11
nowenhow many users do you have again19:11
markw78about 60 or so I think19:11
markw78right now the issue is that the DNS work around has a longer delay than the iphone app waits for a token19:12
markw78so people who wanted to use their iphone apps were complaining, that may have gotten fixed though19:12
markw78hasn't really been a priority lol19:12
nowenare the iPhone tokens not working?19:13
nowenwhat's your domain id again?19:13
markw78I'll have to double check... I know at one point, right after we changed IP's and put the DNS work around in they were not... but no ones been complaining so it may be OK now19:13
nowenyou can also put an entry into your dns19:13
markw7801206906516519:13
markw78yah I have one internally I think19:14
markw78the issue is that the client tries to hit the domain IP the normal way, and has to timeout before it does the wikidsystems.com lookup19:14
markw78I gotta go update my boss on the vpn issue, I'll ask about the iphone app while I'm down there19:14
markw78then gonna grab a bit and I'll be back in a bit19:14
markw78thx again for the help getting us back up!  We'll put something in place to monitor / remind us about the cert heh19:14
nowenwe're going to improve that sometime19:15
nowenhmm, odd. it is slow on my phone19:16
*** cdub_ (40fee8e2@gateway/web/freenode/ip.64.254.232.226) has joined #wikid19:18
cdub_I am trying to install the desktop client and after running it is asking for a passphrase19:19
nowenis this a re-install?19:19
cdub_It may have been installed in the past. Also the uninstaller does not seem to do anything19:19
nowensomething is wrong with the short-cut.  run the uninstaller jar works,  also, you can just delete the directory as it's all in there.19:20
nowenyou can search for wikidtoken.wkd and delete that file. If you using the latest, then entering the wrong passphrase 5 ttimes will prompt you to re-create it19:21
cdub_ok thx19:21
*** cdub_ has quit (Ping timeout: 245 seconds)19:34
*** nowen has quit (Quit: Leaving.)21:19
*** markw78 has parted #wikid (None)21:26
*** josha has parted #wikid (None)21:34

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!