Tuesday, 2013-04-02

*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:52
*** nowen has quit (Client Quit)12:56
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:14
*** blackvipe (~blackvipe@23.31.140.107) has joined #wikid15:20
blackvipehello15:20
joevanohi15:25
nowenHI15:25
joevanosomething we can help you with?15:25
blackvipehey joe15:26
blackvipeI am working on my server tring to get Wikid installed15:26
blackvipeand I think I am still having issues15:26
blackvipelet me show ya a error I am getting15:26
blackvipe: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted fil15:27
blackvipehey nowen15:27
nowenhey15:28
blackvipeany idea's?15:28
blackvipeI have tried to regen the local cert15:28
blackvipethis is a dual homed system15:28
nowencheck them via the command line: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid15:29
blackvipeyep both keys work15:37
blackvipeand the date and time are correct15:37
nowenwhat is the date/time of that error?15:37
blackvipe2013-04-02 11:34:07.997ERRORcom.wikidsystems.client.wClientERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.15:38
blackvipelet me restart the server15:39
nowenwhat are you doing when it occurs?15:39
blackvipeAD Registeration15:40
nowendo you have the proper passphrase on that page?15:40
blackvipelet me check15:41
blackvipefixed but still cert problems15:44
blackvipeCouldn't validate the client certificate. Verify the validity and dates of the client cert.15:44
nowenrestart wikid15:44
blackvipesame problem15:48
blackvipe2013-04-02 11:47:27.571ERRORcom.wikidsystems.client.wClientERROR: java.net.SocketException: Broken pipe15:48
blackvipe2013-04-02 11:47:27.550ERRORcom.wikidsystems.server.wAuthCouldn't validate the client certificate. Verify the validity and dates of the client cert.15:48
nowencan you post the relevant portion of the code to pastebin sans passphrase?15:49
blackvipesure15:49
blackvipehttp://pastebin.com/WE8tfcMw15:52
nowenare you running selinux?16:01
blackvipecentos16:02
blackvipe6.316:02
nowenis selinux enabled?16:02
blackvipeI beleave it is disabled16:03
blackvipelet me check16:04
nowenrun 'getenforce'16:04
blackvipeEnforcing16:04
nowenrun 'setenforce disabled' and edit your selinux file so it won't restart on reboot16:05
nowenand restart wikid16:05
blackvipesame error16:13
nowendid you set up the network using 'wikidctl setup'?16:15
blackvipeno, because my network was already configured16:18
nowengo ahead to do it, even if you just enter the info as it is16:18
blackvipeon other thing I did noticed is it requested for postgress-pl16:19
blackvipeThey don't have that package availble for centos16:19
blackvipe6.316:19
blackvipereconfiguring the network was a bad move because it has lost connection with the outside16:38
blackvipenot that I can't get to it16:38
blackvipelet me reconfigure the network connections16:38
blackvipegot the network connections fixed16:58
nowenok16:58
blackvipewell not it can't find any of the webpages bummer hahahah17:00
blackvipeok I am just going to yank it out17:01
blackvipeand start from scrtch17:01
nowenok.  well, it could be that postgresql-pl thing too17:01
nowenback in a bit17:56
*** nowen has quit (Quit: Leaving.)17:56
blackvipefound somehting interesting18:32
blackvipethe directions on the site are alittle off18:32
blackvipepostgresql-pl : The postgresql-pl package contains the the PL/Perl, and PL/Python procedural languages for the backend. PL/Pgsql is part of the core server package.18:32
blackvipeso postgresql-pl is apart of the core package18:32
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid19:03
*** nowen changed the topic to: "@wikid WiKID"19:08
*** nowen changed the topic to: "#wikid WiKID's IRC support channel. Logs are here: http://www.wikidsystems.com/webdemo/irclogs/index.html. If no one is here use the forums: http://www.wikidsystems.com/support/support/wikid-forums"19:09
blackvipenowen20:35
nowenyes?20:35
blackvipelooks like your missing the ASP scripts on your server to configure users20:35
blackvipehttp://www.wikidsystems.com/documentation/howtos/strong_authentication_initial_validation20:35
nowenthose are replaced by adregister20:36
blackvipeoh ok20:36
blackvipecool20:36
blackvipenow I am back at adregister20:36
nowenwhere did you see that link?20:36
blackvipe:D20:36
blackvipehttp://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/installing-the-wikid-strong-authentication-server-enterprise-edition-page-520:36
nowenwhy don't you try example.jsp first20:36
blackvipeexample.jsp?20:37
nowenyes, browse down that same manual page20:38
nowenlook for Testing One-time passcodes on the WiKID Strong Authentication Server20:39
blackvipeI just got the file configured but don't see one-time passcodes on the page20:45
nowenyou wouldn't. OTPs are only one the tokens20:45
blackvipefor like Registration code what goes there20:46
nowenthe registration code.  ;-)20:47
blackvipeReally hahhahaha20:47
nowenlol20:47
nowenget yourself a token and add your domain to it.20:47
nowenafter you double enter your PIN, you get back a reg code20:47
nowenonce the reg code is entered into the server, the token is registered20:48
blackvipeyes but I still have to add the user20:48
blackvipelet me mess with the adreg script20:48
nowenyou can manually reg a user too20:49
blackvipeyes20:49
blackvipebut what is confusing to me is the format20:49
blackvipe1234567890123456789012345,username120:49
blackvipe            0987654321-0000-xyz,username2.last20:49
blackvipe            abcdefghij,username3@example.com20:49
nowenthat is for pre-registering users only20:50
blackvipeI know certin parts but the numbers for example20:50
nowendid you set up a token on your domain?20:50
blackvipeYes20:50
nowenclick on 'Manually add a user'20:50
blackvipeI added the domains20:51
nowenthe domain for your WiKID server?20:51
blackvipeno20:51
blackvipehaven't added that20:51
nowendo that. the order of them install manual is important. there is meaning for each step20:52
blackvipecool21:00
nowenit also helps to understand how the crypto works21:01
blackvipeI noticed like some of the screen shots have changed like when adding radius user21:01
nowenprobably21:01
blackvipelets see if my network cleint works :D21:02
blackvipewhat Radius Auth method does Wikid us21:09
blackvipeRadius-Chap or PAP?21:09
nowenwe support both21:16
blackvipecool21:16
nowenbut aren't you using the Community version?21:16
blackvipeI have the enterpise version installed21:17
blackvipeI reinstalled it today21:18
nowenok21:18
blackvipeinteresting21:37
blackviperadius server of Wikid looks like it is not running21:38
blackvipebut it says it started the daemon21:38
nowendid you create a network client?21:38
blackvipelooking into that right now21:38
nowenalso, are you using the latest version?21:46
blackvipeyep21:54
blackvipeclient is configured21:54
blackvipelet me check the listing port of 181221:54
nowenrun 'netstat -anp | grep 1812'21:54
blackvipenetstat: no support for `AF INET (sctp)' on this system.21:55
blackvipenetstat: no support for `AF INET (sctp)' on this system.21:55
blackvipeunix  2      [ ACC ]     STREAM     LISTENING     11812  private/relay21:55
blackvipenetstat: no support for `AF IPX' on this system.21:55
blackvipenetstat: no support for `AF AX25' on this system.21:55
blackvipenetstat: no support for `AF X25' on this system.21:55
blackvipenetstat: no support for `AF NETROM' on this system.21:55
blackvipelooks like no radius server21:55
blackvipeinteresting21:55
nowenrun 'netstat -anp | grep java'21:55
blackvipeok correction21:56
blackvipe[root@linux01 ~]# netstat -anp | grep 181221:56
blackvipeudp        0      0 :::1812                     :::*                                    14961/java21:56
blackvipeunix  2      [ ACC ]     STREAM     LISTENING     11812  2022/master         private/relay21:56
nowenthere it is21:56
nowenso, why do you say you think it is not running?21:58
blackvipeis it dedicated to a ethernet adaptor21:59
blackviperunning a test tool on it and it is not responding21:59
blackvipebut have the correct information21:59
nowenis the test tool listed as a network client?22:00
blackvipecorrect22:00
blackvipeAlpha01 192.168.1.16 Radius Alphacomm-usa.com [EDIT] N/A22:00
nowenany errors in the WiKIDAdmin logs?22:01
blackvipenope I wish22:02
nowenrun 'tcpdump port radius'  on the server22:02
blackvipetcpdump: verbose output suppressed, use -v or -vv for full protocol decode22:04
blackvipelistening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes22:04
blackvipe18:04:15.504026 IP alpha01.alphacomm-usa.com.49786 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x08 length: 2022:04
blackvipe18:04:19.011427 IP alpha01.alphacomm-usa.com.49786 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x08 length: 2022:04
blackvipe18:04:22.526882 IP alpha01.alphacomm-usa.com.49786 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x08 length: 2022:04
blackvipe18:04:26.049663 IP alpha01.alphacomm-usa.com.49786 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x08 length: 2022:04
blackvipe18:04:29.558803 IP alpha01.alphacomm-usa.com.49786 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x08 length: 2022:04
blackvipe[root@linux01 webapps]# nslookup alpha01.alphacomm-usa.com22:05
blackvipeServer:         127.0.0.122:05
blackvipeAddress:        127.0.0.1#5322:05
blackvipeName:   alpha01.alphacomm-usa.com22:05
blackvipeAddress: 192.168.1.1622:05
blackvipe[root@linux01 webapps]#22:05
blackvipeso it knows who it is22:06
nowenright22:06
nowenrun 'iptables -L -n' and check to make sure that ip is listed22:06
blackvipedisabled22:08
blackvipestill the same22:09
blackvipeI usally disable IP tables while testing22:09
nowendid you restart WiKID after creating the network client?22:11
blackvipetried but tring again22:12
blackvipequestion on the Assign Return Attribute22:14
blackvipedoes any should be put in there22:14
blackvipeIdidn't add anything22:15
nowennothing is fine22:15
blackvipeI know on radius that it just returns a accept or deny22:15
nowendid you change any of the defaults on the protocol enable page?22:15
blackvipe22:16
blackvipeRADIUS Configuration22:16
blackvipeTypically, there is no need to change any items on this page.22:16
blackvipeRADIUS is ENABLED [ DISABLE ]22:16
blackvipeHost Name: WiKID Radius22:16
blackvipeIP Address: 127.0.0.122:16
blackvipePort: 181222:16
blackvipeDebug Level: Normal High Debug22:16
blackvipeUTF is specified22:16
blackvipeUTF822:16
nowenok22:16
blackvipebrb22:17
*** nowen has quit (Quit: Leaving.)22:19
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid22:19
*** nowen has quit (Client Quit)22:20
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid22:20
nowenhmm22:56
nowenlater23:35
*** nowen has quit (Quit: Leaving.)23:35

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!