*** volga629 (~bendersky@host7.pythian.com) has joined #wikid | 12:27 | |
*** volga629 has parted #wikid (None) | 13:00 | |
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid | 13:03 | |
*** nowen has quit (Remote host closed the connection) | 14:34 | |
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid | 14:35 | |
*** explorer21st (324e40ae@gateway/web/freenode/ip.50.78.64.174) has joined #wikid | 19:22 | |
*** explorer21st has quit (Client Quit) | 19:22 | |
*** Angel (417113c2@gateway/web/freenode/ip.65.113.19.194) has joined #wikid | 21:07 | |
nowen | hey Angel! | 21:07 |
---|---|---|
nowen | I thought this would be faster | 21:07 |
*** Angel has quit (Client Quit) | 21:08 | |
nowen | ero | 21:08 |
*** Angel (417113c2@gateway/web/freenode/ip.65.113.19.194) has joined #wikid | 21:08 | |
Angel | Hello | 21:08 |
nowen | welcome back ;-) | 21:08 |
Angel | yep | 21:09 |
nowen | ok - so, you have no radius listener on the WiKID server? | 21:09 |
Angel | It's installed but apparently not responding. | 21:09 |
nowen | what do you mean 'installed'? | 21:10 |
Angel | Using the enable parameters of the WiKID page. | 21:10 |
nowen | ok | 21:10 |
nowen | and you created a network client for the Citrix? | 21:11 |
Angel | yep | 21:13 |
nowen | and it's still not there? | 21:13 |
Angel | Double checking the settings? | 21:16 |
nowen | did you change any of the settings? | 21:17 |
Angel | No | 21:18 |
nowen | is ldap enabled? | 21:18 |
nowen | it shouldn't be, it would just take up memory | 21:19 |
Angel | No | 21:19 |
Angel | Just WAUTH and Radius | 21:19 |
Angel | Let me go ahead and start and stop. | 21:19 |
nowen | ok | 21:19 |
Angel | Interesting that when starting and stopping from v3.4.87-b839 I can see that RADIUS messages about starting and stopping is showing. | 21:23 |
nowen | you know, I think 839 is very slow for radius | 21:24 |
Angel | Bun on v3.5.0-b1403 I don't see any messages about it starting | 21:24 |
Angel | I am using right now tcpdump port radius -v to see if there is any communication when I use the Citrix Web Interface to communicate and the Web Interface fails. | 21:25 |
Angel | and no communication. by the way both servers are on the same subnet | 21:26 |
nowen | do you have both servers up? 839 and 1403? | 21:26 |
Angel | yep | 21:27 |
Angel | But the servers are on different zones. | 21:27 |
Angel | One is at our Data Center the other one is here at corporate for testing. | 21:27 |
nowen | ok | 21:28 |
nowen | are we working on 839? | 21:28 |
Angel | Trying to get things working first in the test environment so I can make sure configurations are sound before implementing on production version. | 21:31 |
nowen | just making sure | 21:31 |
nowen | does 'netstat -anp | grep 1812' show anything? | 21:31 |
Angel | yes | 21:32 |
nowen | ok good | 21:32 |
nowen | that was not the case before, right? | 21:33 |
Angel | It showed nothing, even though I enabled it. | 21:33 |
nowen | ok, that's progress | 21:34 |
nowen | however, if you weren't seeing anything on the tcpdump command, that means that the citrix isn't getting the radius packets to wikid | 21:35 |
nowen | can you try that again now that we know wikid is listening? | 21:38 |
*** Angel has quit (Ping timeout: 245 seconds) | 21:38 | |
*** Angel (417113c2@gateway/web/freenode/ip.65.113.19.194) has joined #wikid | 21:43 | |
Angel | Looks like I lost communication with you through IRC | 21:43 |
nowen | yeah | 21:43 |
Angel | Anyways I found what the potential problem is from the Web Interface side | 21:44 |
nowen | what's the status? have you tried citrix again? | 21:44 |
Angel | I did a bing/google search to see about the error. Some someone suggested I edit the web.config file and add the IP address of the RADIUS server directly and now I am at lease getting the PASSCODE prompt | 21:45 |
nowen | what radius server are you using? | 21:45 |
Angel | The WIKID server. | 21:45 |
nowen | there is no web.config on the wikid server | 21:46 |
nowen | did you install something else on the WiKID server? | 21:47 |
Angel | Sorry. I am referring to the Web server hosting the Citrix Web Interface. | 21:47 |
nowen | ok - people do install freeradius on the WiKID server and it messes everything up | 21:48 |
Angel | This is something that you may want to add to your knowledge base article that you have on Web Interface | 21:48 |
Angel | Regarding adding the IP address to the web.config | 21:49 |
nowen | yeah, once we get it all running, send me some notes so I can update that doc | 21:49 |
nowen | and you can reference it for the move to prod ;-) | 21:50 |
Angel | Is wikid case sensitive with the preregistration user names? | 21:52 |
nowen | I think so | 21:52 |
nowen | although, user names in wikid should be case-insensitive. | 21:55 |
Angel | I am now seeing requests arriving at the WiKID server from tcpdump | 21:55 |
Angel | still not able to authenticate for some reason | 21:55 |
nowen | sweet | 21:55 |
nowen | anything in the WiKIDAdmin logs? | 21:55 |
Angel | ERROR: java.net.SocketException: Broken pipe | 21:56 |
Angel | Couldn't validate the client certificate. Verify the validity and dates of the client cert | 21:56 |
Angel | 10.14.95.25 - - "GET /openid/images/logo.gif HTTP/1.1" 404 344 | 21:57 |
nowen | is the date on that recent? | 21:57 |
nowen | http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests | 21:57 |
Angel | today | 21:57 |
nowen | is the user enabled? | 21:57 |
Angel | 2013-03-26 13:21:13.234 | 21:57 |
nowen | set the logging to debug for radius and try to auth again | 21:57 |
nowen | but first | 21:58 |
nowen | check the user | 21:58 |
Angel | Still get an authentication error. | 22:02 |
nowen | did you set up radius debugging? | 22:02 |
Angel | yes. What am I supposed to see? | 22:02 |
Angel | I do see something that says Username Attribute (1) etc... | 22:03 |
nowen | if you set the log level to Debug and hit the filter button you should see a lot | 22:03 |
nowen | do you see a reason for denying? | 22:03 |
nowen | you can post it to pastebin.org, if you like | 22:03 |
Angel | How do I know if Wikid is accepting the client passcode. | 22:08 |
nowen | do you see > Access-Request(1) LEN=116 10.100.0.112:42935 Access-Request by ossim Failed: AccessRejectException: Access Denied | 22:09 |
nowen | where ossim is the username? | 22:10 |
nowen | and the 10.100 address is your citrix? | 22:10 |
Angel | Iv'e tried entering a bad passcode and I get the same message as if I enter a good passwcode. | 22:13 |
nowen | what is the message? | 22:13 |
Angel | Access Request (q), id: 0x00 length:77 | 22:14 |
Angel | Instead of that q it's supposed to be 1 | 22:14 |
nowen | is that in the WiKIDAdmin logs? | 22:15 |
nowen | it should look like: http://pastebin.com/DxBmDs3F | 22:16 |
Angel | Interesting that I am not getting any logs showing. | 22:17 |
Angel | During that test time | 22:17 |
nowen | on your configure loggers page, do you have the three middle loggers set to debug? | 22:18 |
Angel | No. Just changed. | 22:19 |
Angel | Will test again. | 22:19 |
nowen | and add the radius logger | 22:19 |
nowen | com.wikidsystems.radius.log.DBSvrLogImpl and set it to debug | 22:19 |
nowen | note that restarting will set them all back | 22:19 |
Angel | where do I add the Radius logger from | 22:26 |
nowen | see the new logger filter? click select a current logger | 22:26 |
Angel | got it | 22:28 |
Angel | Do I need to change the startup logging configuration? | 22:28 |
nowen | only if you want it to stay that way. you might want to for now, but don't do it in production as the logs get huge | 22:29 |
Angel | What am I looking for in the Debug log? | 22:37 |
Angel | it shows no errors | 22:37 |
Angel | Issued passcode to device 2967410642912467481 | 22:37 |
nowen | and that's the last thing? | 22:37 |
nowen | that means no radius traffic | 22:37 |
nowen | do you still see it via tcpdump? | 22:37 |
Angel | yes | 22:38 |
Angel | shows the same message I sent you earlier | 22:38 |
nowen | you sent a tcpdump message? | 22:38 |
Angel | The source in the log was com.wikidsystems.server.DeviceTransactionExec | 22:38 |
nowen | yeah, that doesn't matter | 22:39 |
nowen | but what do you see using 'tcpdump port radius' on the terminal? | 22:39 |
Angel | IP vmlvw01.hdi.com.62923 > vmlvwikid03.hdi.com.radius: RADIUS, Access Request (1), id: 0x00 length: 77 | 22:40 |
Angel | that's the exact message with the exception of the time | 22:40 |
Angel | vmlvw01 is the Citrix web interface server | 22:41 |
nowen | what's the IP address of that server? | 22:42 |
Angel | 10.14.80.105 | 22:42 |
Angel | The Wikid is 10.14.80.104 | 22:42 |
nowen | run 'iptables -L -n' | 22:42 |
nowen | do you see that ip? | 22:42 |
Angel | All show 0.0.0.0/0 | 22:43 |
nowen | run 'service iptables stop' and try again | 22:44 |
Angel | Same | 22:53 |
nowen | what IP did you use on the network client? | 22:53 |
Angel | 10.14.80.105 | 22:53 |
nowen | hmm | 22:54 |
Angel | I also have the secret stored in the conf folder as well | 22:54 |
nowen | the radius listener is still up? | 22:54 |
Angel | Yes. I am seeing the communique from tcpdum port radius | 22:54 |
nowen | well, you are seeing the request from citrix, but you're not seeing the response from WIKDI | 22:55 |
Angel | Let me test something real quick. I am going to temporarily disable the Radius 2Factor from the web interface and make sure that I can log in as normal. | 22:55 |
nowen | [root@167 ~]# tcpdump port radius | 22:55 |
nowen | tcpdump: verbose output suppressed, use -v or -vv for full protocol decode | 22:55 |
nowen | listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes | 22:55 |
nowen | 18:55:38.243465 IP 10.100.0.112.58375 > 167.radius: RADIUS, Access Request (1), id: 0x0a length: 117 | 22:55 |
nowen | 18:55:38.260002 IP 167.radius > 10.100.0.112.58375: RADIUS, Access Reject (3), id: 0x0a length: 38 | 22:55 |
nowen | that's what tcpdump should look like | 22:55 |
nowen | the WiKID server is not respondig for some reason | 22:56 |
Angel | Ok. that part does work. | 22:56 |
Angel | So it has to do with the wicked Authentication | 22:56 |
nowen | yes, can you run 'netstat -anp | grep 1812' again and post the response? | 22:57 |
Angel | udp 0 0 ::fff:127.0.0.1:1812 :::* | 22:58 |
Angel | 1479/java | 22:59 |
nowen | can you check that all four of those loggers are still on debug? | 23:00 |
Angel | Ok now I'm getting debug info | 23:01 |
Angel | com.wikidsystems.server.DeviceTransactionExec Submitted PIN verified | 23:01 |
Angel | com.wikidsystems.crypto.wJceEncKeys Cipher's block size is 117 | 23:01 |
Angel | com.wikidsystems.server.WikidCode5AES Passcode request processing successfully completed. | 23:01 |
Angel | That's just some. | 23:02 |
nowen | that's all just the passcode still | 23:02 |
nowen | we need radius | 23:02 |
nowen | it should look like: http://pastebin.com/DxBmDs3F | 23:03 |
Angel | one moment I am having my firewall guy open access to that site. | 23:05 |
Angel | Ok. I have access now. | 23:12 |
nowen | do you see what I mean by radius logging info? | 23:15 |
Angel | Yes | 23:25 |
nowen | but still none on your server? | 23:25 |
Angel | But there is no information like that | 23:27 |
nowen | ok | 23:27 |
nowen | so, iptables is off, the requests are coming in, but not getting recognized | 23:28 |
Angel | It appears that way. | 23:28 |
nowen | this is 839? | 23:28 |
Angel | Correct | 23:28 |
Angel | All filter levels have been set to debug including com.wikidsystems.radius.log.DBSvrLogImpl | 23:29 |
nowen | ok - I'd like to upgrade, I think it must be a radius issue we fixed somewhere along the ling | 23:29 |
nowen | line | 23:29 |
Angel | Did you want to shift to the 3.5 v in our Data Center? | 23:30 |
nowen | I would like to upgrade this server | 23:30 |
Angel | Np | 23:30 |
nowen | I'll get you the link | 23:30 |
nowen | unless you have the rpms already | 23:30 |
Angel | let me check | 23:31 |
nowen | was this built with the iso? | 23:31 |
Angel | yes | 23:34 |
Angel | Build with the ISO | 23:34 |
nowen | http://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1411-1.noarch.rpm | 23:34 |
nowen | and http://wikidsystems-dl.com/wikid-utilities-3.4.2-1.i386.rpm | 23:34 |
nowen | you can get them to the server using 'wget http://wikid...' | 23:37 |
nowen | and then run 'rpm -Uvh wikid-*' | 23:37 |
nowen | not sure what your linux level is... | 23:38 |
Angel | Not too much. More of a Windows system expert. Low experience with linux. Know some commands. but not alot . sorry | 23:40 |
nowen | no problem | 23:40 |
Angel | I understand the rpm packaging and how this get installed. | 23:40 |
nowen | I think WiKID is a good platform to learn on | 23:40 |
nowen | I did ;-) | 23:40 |
Angel | Agreed. | 23:40 |
Angel | Ok. I have downloaded them. | 23:45 |
Angel | sorry I did it on my win box. meant to do it on my server. | 23:45 |
nowen | np | 23:49 |
Angel | They are extracting now. | 23:53 |
nowen | extracting? | 23:53 |
Angel | Sorry wrong terminology executing with the rpm. Installing... | 23:53 |
Angel | Marbles in mouth... | 23:54 |
nowen | phew ;-) | 23:54 |
Angel | It's done. | 23:54 |
nowen | ok, start wikid | 23:54 |
Angel | k | 23:54 |
nowen | and try to login again | 23:54 |
Angel | its starting. | 23:54 |
Angel | It's applying the updates now. | 23:54 |
Angel | what username and password do I use now | 23:57 |
nowen | for what? | 23:57 |
nowen | the WiKIDAdmin? | 23:57 |
Angel | When I try and log in to the web page the admin credentials I used before are not working? Were you talking about the WiKID server or the Citrix Web Interface login? | 23:58 |
nowen | well, the original ones are WiKIDAdmin and 2Factor | 23:58 |
nowen | that could be a database issue though | 23:58 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!