Wednesday, 2013-04-03

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:10
*** jnosky (d83ae01e@gateway/web/freenode/ip.216.58.224.30) has joined #wikid15:11
*** jnosky has quit (Client Quit)15:12
blackvipehello18:14
nowenhi18:14
blackvipesorry didnt get back as soon18:14
nowennp18:14
blackvipestil working on the radius server18:14
blackvipeI am using a tool to test it call NTRadping18:14
nowenok18:15
blackvipenow it is running on alpha0118:16
blackvipebut getting no responce back from the radius server18:16
blackviperadius WIKID is setup like this18:16
blackvipeAlpha01 192.168.1.16 Radius Alphacomm-usa.com [EDIT] N/A18:16
blackvipe[erich@linux01 ~]$ nslookup alpha0118:17
blackvipeServer:         127.0.0.118:17
blackvipeAddress:        127.0.0.1#5318:17
blackvipeName:   alpha01.alphacomm-usa.com18:17
blackvipeAddress: 192.168.1.1618:17
blackvipe[erich@linux01 ~]$18:17
blackvipehere is the wireshark it going to the server18:23
blackvipe75532.424241000192.168.1.16192.168.1.25RADIUS62Status-Server(12) (id=10, l=20)18:23
blackvipethis is tcp dump getting the request18:26
blackvipetcpdump: verbose output suppressed, use -v or -vv for full protocol decode18:26
blackvipelistening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes18:26
blackvipe14:26:14.819831 IP 192.168.1.17.64951 > linux01.alphacomm-usa.com.radius: RADIUS, Status Server (12), id: 0x0d length: 2018:26
blackvipeso based on that it should work18:28
nowenyes18:28
blackvipeiptables is off18:28
nowendid you get the example.jsp page working?18:28
blackvipeyep it works18:40
blackvipeso I was able to generate a use token18:41
nowenand did you login to the example.jsp page?18:41
blackvipeyep18:41
blackvipeSuccess18:41
nowenthe the logging to debug and try again: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests18:42
nowenyou should see some radius information18:42
nowenwhich version of WiKID is this?18:43
blackvipewikid-server-enterprise-3.5.018:45
nowenwhat's the build number?18:46
blackvipewikid-server-enterprise-3.5.0-b137318:46
blackvipeone error I do see18:49
blackvipebut don't thing it is related18:49
blackvipeA C3P0Registry mbean is already registered. This probably means that an application using c3p0 was undeployed, but not all PooledDataSources were closed prior to undeployment. This may lead to resource leaks over time. Please take care to close all PooledDataSources.18:49
nowenthat's nothign18:49
nowenlet's update the rpm18:51
blackvipeok18:51
nowen'wget http://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1421-1.noarch.rpm'18:51
nowenand then 'rpm -Uvh wikid-server-enterprise-3.5.0.b1421-1.noarch.rpm'18:51
nowenand restart18:52
blackvipeok restarted18:57
blackvipegoing to give it a try18:57
blackvipenope same thing18:57
blackvipejust so ya know I have IPtables disabled18:58
nowenhmm.  disable the radius protocol.  restart WiKID and re-enable it.18:59
blackvipeok its stopped19:02
blackvipejust so ya know there are no other raduis servers19:02
blackvipe[root@linux01 init.d]# netstat -anp | grep 181219:02
blackvipeunix  2      [ ACC ]     STREAM     LISTENING     11812  2022/master         private/relay19:02
blackvipe[root@linux01 init.d]#19:02
blackvipeok status is showing disabled19:04
blackvipeRadius Disabled19:04
blackvipegoing to enable it and restart19:04
blackvipeok it's restarted19:06
blackvipegoing to test it now19:06
blackvipenope19:07
blackvipestill timming out19:07
nowenanything in the logs?19:08
blackvipeyep19:08
blackvipeCan't start RADIUS Server19:08
blackvipelooks like it's a problem starting the radius server19:08
nowenhmm19:09
nowenand the upgrade took ok?19:14
blackvipeyep19:15
blackvipelet me see if I can setup a webex19:16
nowenwell, there's a bug in that version19:16
nowenhere's what happened:  in the website update, the download pages got dropped back a version or two19:16
nowenso you downloaded an old version19:16
nowenso, you updated the Radius Protocol page? Can you do that again, but this time, hit shift-ctrl-R to reload the page?19:19
blackvipeyep I went back to home then went back into configuration19:20
blackvipehere is webex information19:26
blackvipeI don't have audio19:26
blackvipehttps://www.webex.com/login/attend-a-meeting19:26
blackvipe19308283719:26
blackvipemeeting number19:27
blackvipeI'll share the linux stuff19:27
nowenkeyboard is screwy19:31
nowenrun 'netstat -anp | grep java'19:32
nowenyou will have to enter the passphrase19:37
blackvipeas ya can see there is no responce19:43
nowendo you see the error19:43
*** Philipp_ (d5b39ef2@gateway/web/freenode/ip.213.179.158.242) has joined #wikid19:45
nowenhi Philipp_19:45
Philipp_Hello...19:45
nowenblackvipe: looks like the WiKID server thinks the packets are coming from .1719:46
Philipp_can anybody give mit some help with the community edition and the integrated ldap server?19:46
nowenmaybe19:46
nowenwhat are you trying to do?19:47
Philipp_as the community edition has to radius enabled, I tried to use the system as an ldap server to authenticate my citrix users against the wikid token systems19:48
nowendoes citrix support ldap?19:48
Philipp_yes, the citrix access gateway does...19:48
Philipp_the problem I have is that the ldap server doesn't run (I checked via netstat) on my wikid server...19:49
Philipp_I followed the support-document and tried to browse the ldap via ldapsearch, but no success...19:49
Philipp_first question is: is it correct, that the wikid-server has the function of an ldap-authentification server?19:50
blackvipethere we go19:51
blackvipethat is alittle different now19:51
blackvipelooks like it worked19:53
blackvipewhen I changed the request type19:53
nowenPhilipp_: yes19:53
nowenblackvipe: excellent19:53
blackvipecool thanks for the help19:53
nowennp19:53
nowensorry for the download issue19:53
blackvipeno problem19:55
blackvipeI have a idea for the password startup issue19:55
blackvipethough19:55
blackvipeso you can start it without operator19:55
blackvipeor root I should say19:55
nowenthe server or the token?19:55
blackvipeis expect script19:55
Philipp_how can I troubleshoot my problem? It seems, that the ldap services doesn't start.19:56
blackvipeI have used them before in SSH19:56
nowenblackvipe: for the server or the token? if the former: http://www.wikidsystems.com/support/wikid-support-center/faq/how-can-i-restart-the-server-without-being-asked-for-the-passphrase19:56
blackvipeoh ok cool19:56
nowenPhilipp_: do you see any errors in the  WiKIDAdmin logs?19:56
blackvipeCool!19:57
Philipp_you meen at startup?19:57
nowenPhilipp_: no, in the WiKIDAdmin web UI19:57
Philipp_hm, not really... I installed the server on CentOS 6.4 64bit. Could that be an problem? Should I use another OS?19:59
nowenI don't think so19:59
nowenyou enabled the protocol and created a network client?20:00
Philipp_yes, I did...20:00
Philipp_but I didn't create any certificates via the gui. is that neccessary?20:00
nowenyes, it is20:00
Philipp_first intermediate ca?20:01
nowenboth20:01
nowenbut yes, that firsty20:01
Philipp_when trying to create an intermediate ca, I just get an page with the wikid navigation-bar, but no content or form...20:02
nowenwhat version are you running?20:02
Philipp_wikid-server-community-3.5.0-b139920:02
Philipp_is that the latest stable?20:03
nowencheck /opt/WiKID/tomcat/logs/catalina.out20:03
nowenyes20:03
Philipp_no error in catalina.out... just a blank page.20:04
nowenhmm20:04
Philipp_on which os have you successfully tested the version wikid-server-community-3.5.0-b1399 ?20:04
nowenwhat version of java?20:04
nowencentos, but mostly 6.220:05
Philipp_OpenJDK Runtime Environment (IcedTea6 1.11.9) (rhel-1.57.1.11.9.el6_4-x86_64)20:05
Philipp_OpenJDK 64-Bit Server VM (build 20.0-b12, mixed mode)20:05
Philipp_do I have to change any parameters like Auth Passwords to create a certificate?20:09
nowenno, you shouldn;t't20:09
Philipp_any possibility to change the debug level of the tomcat?20:11
nowenbrb - phone call20:12
Philipp_sorry, phone call not possible at the moment. maybe a remote session?20:13
Philipp_oh sorry ;-) didn't know the meaning of brb ;-)20:14
*** Philipp__ (d5b39ef2@gateway/web/freenode/ip.213.179.158.242) has joined #wikid20:16
*** Philipp_ has quit (Quit: Page closed)20:16
Philipp__I'm still there... just changed my computerdevice...20:17
nowenok20:17
Philipp__do you think my problems could be solved when installing the server on centos 6.2?20:18
Philipp__do you recommend 32 or 64 bit?20:18
nowenit doesn't seem like that would be a factor20:18
nowenwhat doc did you follow for the install?20:18
nowenI bet it is a networking thing20:19
nowencan you re-run setup and enter your network info?20:19
Philipp__http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-install-the-wikid-community-edition-3.x20:20
Philipp__I could try to rerun the setup...20:20
Philipp__should I?20:20
nowenyes20:20
Philipp__ok... one moment please.20:21
Philipp__how should I rerun the setup?20:22
nowenwikidctl setup20:22
Philipp__wow, now I can create an certificate...20:26
Philipp__I have now created all certificates and will now restart the server...20:30
Philipp__how can I see, if the ldap server is running?20:33
nowen'netstat -anp | grep 389'20:34
Philipp__result: unix  2      [ ]         DGRAM                    18389  3622/sshd20:34
Philipp__when starting the wikidctrl I get: Starting LDAP protocol daemon...Success!20:38
Philipp__but the service does not seem to run...20:38
nowenI'm building a test server20:38
Philipp__do you have any idea in which log I could check?20:39
Philipp__do you build the test server right now?20:47
Philipp__I just read after the certificate creation: If you choose to use the commercial version after 30 days please contact certs@wikidsystems.com for a permanent production certificate.20:48
Philipp__does that mean, that I can't use the community version after 30 days?20:48
nowenno20:49
nowenyou can use it20:50
Philipp__ok; is there anywhere an special logfile for the ldap daemon?20:50
Philipp__could you please send me an email with the result of your tests?20:51
nowenI will probably have to have someone else look at this21:02
blackvipenowen21:04
blackvipequestion21:04
blackvipeunix authnication under centos21:05
nowenblackvipe: yes21:05
blackvipedoesn't centos still required LDAP to get it's directories and UID and GUI from?21:05
nowenyes, radius won't do that21:05
blackvipecool21:05
blackvipeI got that part down21:06
blackvipeI have done that under solaris :D21:06
Philipp__nowen, could that be a problem: lh-wikid.lhdon.local : Apr  3 23:05:44 : wikid : user NOT in sudoers ; TTY=pts/0 ; PWD=/ ; USER=postgres ; COMMAND=/usr/bin/psql -h localhost -d wikid -f /opt/WiKID/conf/database/db-data.sql ?21:08
nowennot sure21:09
nowenyes21:11
nowenwhat you need to do is run 'chown -R root:root *' on /opt/WiKID/directory' and then restart wikdi21:13
nowenit's a permissions issue21:13
blackvipeya have any recomendations for using WIKID for windows domain Auth?21:20
blackvipelike windows login?21:20
nowengood luck on that21:20
nowenyou can try pgina21:20
nowenthe problem is that MS doesn't like people messing with the gina21:24
nowenyou are better off going to VDI21:24
blackvipeyep there domain control is a pain in butt to setup and keep running smoothly also hahahha21:27
Philipp__thanks for your support nowen... I'll try to reinstall the server with centos 6.221:40
Philipp__regards21:40
nowenPhilipp__:21:40
nowenwait21:40
Philipp__ok.21:40
nowendid you change the permissions as suggested>21:40
nowen?21:40
nowenPhilipp__:  run 'chown -R root:root *' on /opt/WiKID/directory' and then restart wikid21:41
Philipp__yes, but now the tomcat does not start anymore... do I have to do a su wikid before starting the wikid server with wikidctrl start?21:41
nowentomcat doesn't start?21:42
nowenyou do not have to su to wikid21:42
nowendo you get an error in the browser?21:43
nowenI'm on 6.3, I don't think that is the problem21:44
Philipp__no, just an timeout...21:44
nowenwhat does 'netstat -anp | grep 443' say?21:44
nowenand does wikid still own /opt/WiKID?21:45
Philipp__netstat on 443 does not return anything...21:46
Philipp__yes, /opt/WiKID is owned by wikid:root21:47
Philipp__ok, another machine reboot and the gui is back...21:50
Philipp__but still no running ldap service...21:53
nowentry running /opt/WiKID/directory/bin/start-ds21:53
Philipp__now the service runs...21:55
nowenhmm21:55
Philipp__I always get the following message after restarting the wikid service:21:55
Philipp__user NOT in sudoers ; TTY=pts/0 ; PWD=/opt/WiKID ; USER=wikid ; COMMAND=/opt/WiKID/directory/bin/start-ds21:55
Philipp__I get this via email...21:55
Philipp__seems that the script can't start the start-ds...21:56
nowengo ahead and add wikid to the sudoers file21:56
Philipp__do you know how?21:56
Philipp__Ok, found.21:58
nowenwell, this is probably the wrong way, but I just edit /etc/sudoers and under the line 'root    ALL=(ALL)       ALL' I put 'wikid   ALL=(ALL)       ALL'21:58
nowenyou can do it better, I'm sure21:58
Philipp__hm, the start-ds does not start automatically... but I can start it manually. I'll look after that later...22:09
Philipp__I have now setup an network client with ip 127.0.0.1 and tried to make the ldapsearch-test.22:10
nowenI've opened a bug for it.  are you saying that it doesn't start when you run 'wikidctl restart'?22:10
nowenyou will need to use an external network client22:10
Philipp__no, it does not start when doing an wikidctl start or wikidctl rstart22:15
Philipp__I think, I found another bug... the firewall does not allow incoming requests for 443, so the gui is not reachable...22:20
Philipp__do I need the internal firewall of the wikid-server?22:33
nowenthat depends on your set up and requirements22:33
Philipp__I have an firewall in front of my network and the wikid server will be in an dmz.22:34
Philipp__I asked because I found some prerouting iptables rules in the startup scripts...22:34
Philipp__but if I don't need it, I will deactivate it.22:34
nowennot needed22:35
Philipp__enough for today... it's time for bed ;-)22:40
nowenhah! time for me to go too22:40
Philipp__I'll try the rest tomorrow. thank you for great support!22:40
nowennp22:40
Philipp__regards from cold germany!22:40
nowenthanks for the trouble shooting22:40
Philipp__I'll give you feedback if I have my complete solution.22:41
nowenthanks22:41
Philipp__bye22:41
*** nowen has quit (Quit: Leaving.)22:50
*** Philipp__ has quit (Ping timeout: 245 seconds)22:50

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!