Friday, 2013-03-29

*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:03
nowenmorning13:04
nowenback in a bit13:08
nowenARG: how goes it?13:34
ARGHey good morning I have the radius configured but how do I add users to wikid15:09
nowenfor one, you can add your domain to a token, then go under Users/Add a user manually and click on the reg code15:10
nowenyou can also do it programmatically, but I would wait on that15:10
ARGthe user manually tab after you click on it  is missing the enable botton15:14
nowendo you see a registration code listed?15:16
ARGno15:16
nowendo you have a token?15:17
ARGI'm not sure If I do15:18
nowenget one here: http://www.wikidsystems.com/downloads/token-clients15:18
ARGOk I see thanks let play with this now15:19
ARGSo the Token needs to be download on every user device that requier authentication15:34
ARGI found a video with the instruction15:38
ARGI'm getting this:The wClient connection to the server was NOT successfully established when trying to test the wAuth17:03
nowenon example.jsp?17:04
ARGyes17:04
nowenyou edited the file?  changing the localhost passphras?17:04
ARGyes17:05
nowenand then, did you restart wikid?17:05
ARGno17:05
nowentry that17:05
ARGok17:06
ARGis working now17:09
nowennice17:09
nowenit will show you the whole API17:09
ARGThe WAuth test passed17:13
ARGnow this is not working https://server/wikid/ADRegister/ADRegister.jsp17:14
nowendid you edit that file?17:14
ARGwhat file17:14
nowenADRegister.jsp17:15
ARGI think I did yesterday17:15
ARGI made some changes to the file17:15
nowenany error?17:15
ARGyes it resjected my login17:16
ARGAuthentication to the directory failed for17:16
nowendid you login using your AD creds?17:16
ARGI'm using radius17:16
nowenthat file allows users to login with their AD creds and register their own token17:17
nowenonce registered, they can login to a radius network client using WiKID17:17
ARGis not working for me any idea why17:18
ARGis there a way to test the radius17:18
nowenyes - set up a radius network client17:18
ARGI did17:19
nowenand does it work?17:19
ARGno17:19
nowenwhat error do you get in the WiKIDAdmin logs?17:19
ARGI can see that is setup on the netwokd client tab17:20
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests?searchterm=radius+debug17:20
ARGthis is the only error on the logs: 2013-03-29 10:39:49.119ERRORcom.wikidsystems.client.wClientERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.17:42
nowenset the log level to debug and hit filter17:43
ARGno errors on the radius logs17:43
ARGI already did17:43
ARGI followed the link instruction17:43
nowenwhich loggers do you have set for debug?17:43
nowenso you have 4 loggers to debug?17:44
ARGTo enable debugging for radius, go to Logs/Configure Loggers and set com.wikidsystems and com.wikidsystems.wauth to debug and add com.wikidsystems.radius.log.DBSvrLogImpl and set it to debug as well.17:44
nowenok17:44
nowendid you get an OTP from the token?17:44
ARGThe token is working no problem17:44
nowenyou should see the OTP request from the token in the logs17:45
ARGok let me see17:45
ARGI don't see anything17:46
ARGmaybe this ERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.17:48
ARGis there a way I can send you a screenshot17:48
nowencut and paste the text into pastebin.org17:49
nowenand then paste the url they give you here17:49
nowenis the that error repeating?17:49
nowenbecause I am assuming it is from your example.jsp or adregister.jsp hits17:50
ARGyes it is an example but the first one I sent you is not17:51
nowenwhat is the time on the pkcs error?17:52
ARG2013-03-29 10:39:49.11917:53
nowenso, not recent17:54
ARGhttp://pastebin.com/kfLViV1G17:55
nowencan you paste the logs too please?17:55
ARGhttp://pastebin.com/hKEBaZnj17:55
ARGThere is no logs the second link is the only one that has logs17:56
nowenI want to see the page that has the pkcs error17:57
nowenwhen you get an OTP, you should see 'Issued passcode to device -3767091469847503280' in the logs17:59
nowenare the dates correct on this server?17:59
ARGlet me check18:00
ARGYes Fri Mar 29 12:00:32 MDT 201318:00
nowenwhat is the domain identifier of the server?18:01
ARG01001001116518:01
ARGHow do I get the pkcs error18:02
nowenon the top right hand side of the WiKIDAdmin UI is a link that says 'logs'18:02
ARGYes I'm there now18:03
nowenok,  set the log level to debug and hit filter18:04
ARGwhat source you want me to choose18:04
nowenNone18:05
ARGok done18:05
nowendo you see 'Issued passcode to device -....'?18:06
ARGis only showing one error and is highlighter on red nothing else18:07
nowenget an OTP on the token and then hit filter againb18:07
ARGok18:07
ARGOK I got a new one18:10
nowenand do you see it in the logs?18:10
ARGyes18:10
ARG013-03-29 11:11:59.090WARNcom.mchange.v2.c3p0.management.ActiveManagementCoordinatorA C3P0Registry mbean is already registered. This probably means that an application using c3p0 was undeployed, but not all PooledDataSources were closed prior to undeployment. This may lead to resource leaks over time. Please take care to close all PooledDataSources.18:11
nowenyou can ignore that18:11
ARGok18:11
ARGthat is all I see and the old one18:11
nowenyou do have a 'Issued passcode to device ' log entry?18:11
nowenso, you are getting a passcode back to your software token, but you are not seeing it in the logs?18:12
ARGI'm not sure18:12
nowenhttp://pastebin.com/nrgEMHn618:14
ARGWell I'm not sure how the logs work for wikid but on the logs tab all I see is what I told you I don't see any where else where I can click to see details of the erroe18:14
nowenthat's what it should look like18:14
nowenthen, I guess my question is:  when you entered your PIN into the software token, did you get back a one-time passcode?18:15
ARGI don't see that anywhere18:15
ARGyes18:15
ARGI also tested here and it works https://10.10.11.165/WiKIDAdmin/example.jsp18:15
nowenso, everything is working, except the logs?18:16
ARGyes18:16
ARGwell no radius is not working18:17
nowenon the logs page, what are the settings on each drop down?18:18
ARGif you click on the log tab I should be able to see what show me on the link or there is another botton inside the logs18:19
ARGok wait is working now18:19
ARGI just change it back ot debug and none and show me the logs18:20
nowenyes, debug and none is what you want18:20
ARGI had it that way before but it was not working18:20
ARGbut now is working18:21
nowenok18:21
nowennow try to login to your radius client and let me know what you see in the logs18:21
ARGok18:21
ARGhttp://pastebin.com/GD6A9LPQ18:25
nowennone of that is radius18:27
ARGyes I know18:28
nowendo you see the OTP request?18:28
ARGwhere should I see the otp request18:28
nowenin the logs:  it will say:  'Issued passcode to device ' xxxxx'18:29
ARGlet see the logs18:30
ARGyes 2013-03-29 11:12:00.135INFOcom.wikidsystems.server.DeviceTransactionExecIssued passcode to device -750369151069551993518:31
nowenwhat time is it there?  seems a bit old18:32
ARG12.32 pm18:32
ARGbut that is the only one18:32
ARGlet refresh the logs18:33
nowendid you get a new OTP when you tried to log in to the radius client?18:33
ARGno but maybe takes time to see the new logs18:33
ARGI just update the logs but nothing new18:34
nowenyou need a new OTP to login with! they are only good for 60 secs18:34
nowendo this:  Get an OTP on the token.  Enter the OTP into whatever radius client you are using.   Check the logs.  Everything after the OTP will be radius info.18:35
nowenwhat radius client are you using? Openvpn?18:37
ARGOk let me clear this when I got the wikid/ADRegister/ADRegister.jsp it asked me for my AD username and password then when I click authenticate it reject me18:37
nowenADRegister does not use radius!18:37
ARGcrap18:38
nowenit is for user registration!18:38
ARGwhat do I loging using radius18:38
nowenanything that supports radius!18:38
nowenopenvpn, a radius test client, a vpn18:38
nowenapache18:39
nowenpam18:39
nowenaren't you setting up openvpn?18:39
ARGI have openvpn and is already configure with ldap18:39
ARGsorry man I very cofused here18:41
ARGmy wireless over here uses radius18:41
ARGmy vpn ldap18:41
ARGso when would I use a radius with wikid from what device18:43
nowenmaybe something like this: http://www.iea-software.com/products/radlogin4.cfm18:46
ARGOk I'm going to lunch thanks18:50
ARGone more question before I go I have the token intalled on my pc18:51
ARGIf I log out would it allowed to log back in18:51
nowenWiKID has no knowledge of your session or any concept of session.18:52
ARGok I need to see how wikid works Im lost right now if you have a video can you send to me18:53
nowenhttp://www.wikidsystems.com/learn-more/technology/overview18:53
nowenI'm going to move the website, so there might be a bit of downtime.20:23
ARGOK20:25

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!