Monday, 2013-04-29

*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:52
*** Tim__ (b899e60b@gateway/web/freenode/ip.184.153.230.11) has joined #wikid13:09
Tim__Hi Nick, i got the 2FA working last week. I can get a pass code from both my XP machine and iPad. I have 2 questions though, do you have an application that makes the XP machine require the passcode tpo log in, and also what protocols are used in 2FA on the network? All ive found is challenge/response.13:28
nowenTim:  you can try pgina for the windows login13:34
nowenprotocols:  radius/ldap/saml13:34
Tim__ok, thanks. Ill look into that right now.13:35
nowennot  many people use 2FA for windows login. it is mostly for remote accesss13:35
*** palguay (7ab36186@gateway/web/freenode/ip.122.179.97.134) has joined #wikid13:37
Tim__ok, what percentage would you say would use it for login? Ive never used it before and was interested and assumed it was used on campus for log ins.13:37
Tim__no exact figures needed, just rough estimate off the top of your head in case im asked during my presentation, thanks13:39
palguayHi I have inherited a system running wikid and do not know enough of the system to debug an issue we are having ,  Can someone point me to the right documents/logs to look at this13:39
Tim__Nick would be the one to ask, he would need the issued to point you in the right direction though13:41
palguaywhen a user logs into a system we get a cannot find group id for a logged in user ( linux system)13:42
nowenpalguay: what version of WiKID is this?13:42
palguayrpm gives me this wikid-server-enterprise-3.4.1.b3314-113:43
palguayit was running fine not sure what changed and started causing this error13:44
*** nowen has quit (Remote host closed the connection)13:45
palguayone thing I noticed is this error in the messages ERROR:  permission denied for relation full_domain_keys13:45
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:46
nowensorry13:47
nowenback now13:47
nowenso - did the server get restarted and then the issue happened?13:50
nowencheck the certificates: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid?searchterm=keytool13:51
palguaywhen I do a service wikid status I get the Master functions not functioning properly13:53
nowenyou can ignore that. you have to edit a file for that to work13:54
palguaylooking for the passphrase , seem to have forgotten13:57
palguaygive me a few minutes13:57
nowenit might be in /etc/WiKID/security13:58
palguaygreat I see it there13:58
palguaythanks13:58
palguaythe certificate seems valid14:01
nowenand the localhost too?14:01
palguayyes both14:01
nowenok - set your logging to debug and try to login again: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests?searchterm=radius+debug14:02
nowenso, the error you're getting is on the system your logging into - after the user has authenticated?14:03
palguayyes after the user has authenticated .. I do not see the Logger file14:05
palguayis is Wikid-syslog.xml14:06
nowenit is in the webgui / WiKIDAdmin14:06
palguaysorry for the noob question, I have not used the GUI before are the credentials the same as what is in security14:10
nowennot necessarily14:10
palguayI have got someone to login and enable that14:18
nowenok - you'll need access to the WiKIDAdmin for us to troubleshoot effectively14:18
nowenalso - are you sure this is a WiKID issue?  Is WiKID supposed to send group info via radius attributes?14:19
palguayI am not sure about that . Does this error mean something ERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.14:23
nowenyes, it means that your certificate is invalid/expired or that the passphrase is incorrect14:24
nowenso - the user is authenticated on the server and then rejected do to a group authorization issue?14:24
*** Smithart (1899c122@gateway/web/freenode/ip.24.153.193.34) has joined #wikid14:24
palguayboth the userid and group id cannot be found once the authorization is done14:27
nowenwhat system is responsible for that?14:36
palguayI am not sure but am assuming that wikid gets this from ldap14:38
nowenthat's not possible14:38
nowenmost likely your SSH server gets it from ldap14:38
nowenthe most WiKID can do it return a radius attribute that provides a group that is then matched on the server14:39
palguayhere is something from the wikid radius.log Check PAP bombed with AccessRejectException: Access Denied14:42
nowenthat is a user getting denied.  you will need the debug log to know why.14:43
palguaythere is this error com.wikidsystems.server.wAuth: Database error while validation offline response14:44
*** Tim__ has quit (Ping timeout: 245 seconds)14:45
nowenhere's the best way to find out what is going on: set the WiKIDAdmin logs to debug.  Try to login - then post the entire logs on pastebin.com14:45
palguayWiKIDAdmin logs from the GUI ?14:49
nowenyes14:51
Smithartcom.wikidsystems, com.wikidsystems.radius.log.DBSvrLogImpl, and com.wikidsystems.server.wAuth are all set to debug. The only errors in the GUI are:14:51
SmithartERROR: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file.14:52
Smithartcom.wikidsystems.server.wAuth: Database error while validation offline response14:52
nowenok - let's update the server to the latest version and create new certs14:52
nowenis this a vm?14:53
palguayno it is not a vm14:54
nowenhow do you do back-ups?14:54
palguayour hosting provider does backup -  this shows up on mouseover org.postgresql.util.PSQLException: ERROR: permission denied for relation full_domain_keys15:01
nowencan you have your hosting provider do a back up now?  I think we should upgrade the server and create new certs.15:02
palguaywe have a master slave setup if that can help15:03
nowenyes, that's good15:03
nowenwe will have to upgrade the master and then upgrade the slave15:03
nowenhere are the two rpms:  http://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1428-1.noarch.rpm15:04
nowenand http://wikidsystems-dl.com/wikid-utilities-3.4.3-1.i386.rpm15:04
nowenI assume this is a 32 bit server?15:04
palguaythis is a 64 bit server15:06
nowenscratch that last one then15:06
palguayIs there a 64 bit rpm for the utilities ?15:11
Smitharthow risky is this? these servers are the gateway to (and between) our production servers.15:11
nowenbulding it now15:11
Smithartwe have other means to authenticate, but i just want to make sure it won't indirectly break those15:12
nowenhow many WiKID users do you have?  it will be on the home tab15:12
SmithartLicenses In Use:415:12
Smitharti don't know how many we bought; probably 10?15:13
nowenyeah, that's the min.  I just wanted to know what we're dealing with15:13
Smithartthat server is our bastion server, and it proxies ssh connections from the outside into our secure servers15:14
Smithartand in some cases between internal servers15:14
Smithartwikid is our secure way in when we can authenticate into the environment thru that server using keys15:15
Smithartcan't*15:15
nowengotcha15:15
nowenhttp://wikidsystems-dl.com/wikid-utilities-3.4.3-1.x86_64.rpm15:24
nowenso, we have a new certificate in the latest rpm - so if we are going to do new certs, we need to update the rpm.15:25
nowenI don't think it is too risky, but you never know. it sounds like you also run other services on the server15:25
nowenstop wikid and then run 'killall -9 java'15:28
nowento make sure everything has stopped15:28
nowenthen, do 'rpm -Uvh wikid...' on those rpms.  the utilities first15:28
palguayfailed dependancies on the utilities15:34
palguayrpmlib(FileDigests) <= 4.6.0-1 is needed by wikid-utilities-3.4.3-1.x86_64 rpmlib(PayloadIsXz) <= 5.2-1 is needed by wikid-utilities-3.4.3-1.x86_6415:34
palguaywe are on redhat EL 5.615:38
nowenif you do 'yum update --nogpg wikid-*' does it list the reqs?15:39
palguayyes it seems to resolve dependancies , does not list the payload and filedigest15:43
nowengood15:43
palguayyou want me to update with yum ?15:44
nowenyes15:44
palguaygot the same error when it tries to rpm_check_debug15:46
nowensorry - did the yum update not work?15:46
palguayno it failed with the same error15:48
palguayERROR with rpm_check_debug vs depsolve: rpmlib(FileDigests) is needed by wikid-utilities-3.4.3-1.x86_64 rpmlib(PayloadIsXz) is needed by wikid-utilities-3.4.3-1.x86_6415:49
nowenhmm. works for me on el5 centos box15:50
nowendid you use the --nogpg?15:51
nowenwhat version of rpm is on this system?15:52
palguayyes I used that15:52
palguayRPM version 4.4.2.315:53
nowenok hold on.15:55
nowenI will have to rebuild15:55
nowenok - try the same link again for the utilities rpm16:03
palguaythe utilities package installed :-)16:04
nowenyay!16:04
palguayIs the server package the same ?16:05
nowenyes, use the same command16:05
palguayok the installation completed16:09
nowenok - restart wikid16:09
palguayservice wikid restart Restarting WiKID sudo: sorry, a password is required to run sudo Tomcat server already stopped. TimeCop process already stopped. Logger process already stopped. Database already stopped. ssh_exchange_identification: Connection closed by remote host rsync: connection unexpectedly closed (0 bytes received so far) [sender] rsync error: unexplained error (code 255) at io.c(601) [sender=3.0.7] Synchronizing master fi16:11
nowendid you setup wikid as a service?16:11
palguayyes it was already setup16:11
nowenhmm, it sounds like something with the slave16:12
palguayok I got logged out of the system , not sure why16:12
nowendid it start?16:16
palguaywe seem to be locked out of our systems16:17
nowenhmm, I don't think we did anything that would cause that16:17
palguaywe are trying to see if we can get in someplace16:21
Smithartwe both got booted from the server when wikid restarted16:21
nowenhmm, the command to restart starts postgres and tomcat16:21
nowencan you tell if the server is up at all?16:22
*** palguay_ (7ab36186@gateway/web/freenode/ip.122.179.97.134) has joined #wikid16:23
palguay_I can ping the server16:23
nowenis ssh up on port 22?16:24
*** Smithart has quit (Ping timeout: 245 seconds)16:25
*** palguay has quit (Ping timeout: 245 seconds)16:25
palguay_yes ssh seems to be up16:25
*** Smithart (1899c122@gateway/web/freenode/ip.24.153.193.34) has joined #wikid16:25
nowenbut you cannot login?16:25
Smithartno. we can still log into the slave16:26
Smithartbut not the wikid master server16:27
nowencan you login to the master from the slave?16:27
palguay_ok I am able to get in16:27
Smithartme too, apparently it was just really slow to come up?16:27
palguay_only on process for wikid /opt/WiKID/bin/usogres16:29
nowenpalguay_: ?16:30
nowenif you run 'netstat -anp | grep 444' is there a listener?16:30
palguay_netstat -anp |grep 444 tcp        0      0 127.0.0.1:2514              0.0.0.0:*                   LISTEN      4443/spiped          tcp        0      0 192.168.60.189:35419        192.168.60.191:22514        ESTABLISHED 4443/spiped          tcp        0      0 127.0.0.1:2514              127.0.0.1:40564             ESTABLISHED 4443/spiped16:31
nowensorry - 44316:31
palguay_tcp        0      0 0.0.0.0:443                 0.0.0.0:*                   LISTEN      8737/httpd16:31
nowenis apache running on this server?>16:32
palguay_apache is running but the wikid url returns a service temporarily unavailable16:33
nowenyeah, it should be running on 443 but can't.  did you have the WiKIDAdmin running on a different port?16:33
nowenare you using apache?16:33
Smitharti suspect wikid was running on a different port16:34
nowenlook in /etc/httpd/conf/httpd.conf16:34
nowenthere should be a redirect16:34
palguay_I get this when I check if the service is up16:34
palguay_sudo service wikid status sudo: sorry, a password is required to run sudo Stopped: WiKID master services not running on localhost.16:35
nowenfor status to work, you need to edit a file16:35
nowenit is easier to run netstat against the ports16:35
Smithartbased on the httpd conf, it looks like wikid gui should be accessable on 44316:36
nowenwhat does it say?16:36
palguay_These errors show up in wikid error logs (apache)16:37
palguay_(111)Connection refused: proxy: AJP: attempt to connect to 127.0.0.1:8009 (localhost) failed16:37
nowenSmithart: what does you httpd.conf say? because you cannot have apache and tomcat listening on the same port16:37
palguay_we have a ProxyPass /wikid/ ajp://localhost:8009/wikid/16:39
nowenok - that's for the OTPs16:39
nowenthey would use port 80, but you have switched it to 800916:39
nowenanything for WiKIDAdmin?16:40
palguay_we have a redirect for wikidadmin16:40
nowento what port?16:40
palguay_the redirect is for http to point to https16:42
nowenlook in /opt/WiKID/tomcat/conf/16:42
nowendo you see more than one server.xml ?16:42
nowenperhaps a server.xml.rpm16:42
palguay_there is server.xml at /opt/WiKID/tomcat/conf16:43
nowenwhen you went to the WiKIDAdmin in the past, did you have to append a different port number?16:44
palguay_no we did not have to append a different port16:47
Smitharthttps://wikid.genares.net/WiKIDAdmin16:47
nowenhmm. well, I'm not sure what is going on. apache and tomcat can't use the same port16:47
palguay_there is this line  <Connector port="80" enableLookups="false" redirectPort="443"                acceptCount="100" debug="0" connectionTimeout="6000"/>16:51
palguay_wikid was not able to start16:53
Smithartthe wikiadmin was definitely working before the upgrade16:57
nowendo you see this line: <Connector port="443" protocol="HTTP/1.1" SSLEnabled="true"16:58
palguay_Yes that seems to be there in the server.xml17:00
palguay_<Connector port="443" protocol="HTTP/1.1" SSLEnabled="true"17:00
nowenchange that to 8443 from 44317:01
nowen:q17:03
palguay_ok changed17:03
nowenare there any errors in /opt/WiKID/tomcat/logs/catalina.out?17:03
nowentowards the end17:04
palguay_looks like errors were before the upgrade17:04
nowenok17:05
nowenare you running anything else on this server that uses java?17:05
palguay_does not look like there is anything that uses java17:06
nowenrun 'killall -\9 java' and 'rm /opt/WiKID/tomcat/logs/catalina.out'17:06
nowenthen start wikid.17:07
nowenyou can tail catalina.out if you like17:07
palguay_start wikid thorugh service ?17:08
nowenuse 'wikidctl start'17:08
nowenjust in case there's a bug with the service sripts17:08
palguay_as root or as user wikid17:09
nowenroot should be fine17:09
palguay_it is asking me for the root password17:12
palguay_seems to be starting slowly17:13
nowenhow much memory is on this machine?17:14
palguay_ok it seems to have come up17:15
palguay_around 15 G17:18
nowenwell, should be fast then17:18
palguay_since we changed the tomcat port do we use a port to login to WiKIDAdmin17:19
nowenyes17:19
palguay_we may have a fire wall issue , checking17:21
nowenperhaps the redirect occurred at the firewall?17:25
*** Smithart has quit (Ping timeout: 245 seconds)17:26
palguay_maybe17:28
palguay_I am thinking of changing it back to what it was and restart wikid17:28
nowensure, then look at catalina.out for an error17:28
palguay_firewall rules are at our hosting provider17:28
nowenis the person who set it it up originally available?17:29
palguay_no we are not able to get hold of him17:30
palguay_let me try to change it back and restart17:31
nowenok17:34
nowentail the catalina.out file17:35
palguay_nothing in catalina.out but there are some errors in catalina.err17:44
nowenwhat?  and is tomcat listening on 443?17:44
palguay_ no we get back the old server unavailable error17:50
nowenwhat are the errors in catalina.err?17:50
palguay_http://pastebin.com/Xkc4nGA417:53
nowenjava.net.BindException: Address already in use <null>:44317:55
palguay_yes , when we did an install does it overwrite the old files in /opt/WiKID dir ?17:55
nowenyes17:55
nowenin your server.xml, I recommend you comment out the 80 to 443 redirect and put in:17:56
nowen    <Connector port="8090" protocol="HTTP/1.1"17:56
nowen               connectionTimeout="20000"17:56
nowen                />17:56
palguay_let me check the settings on the slave17:57
nowenthen, change the 443 port to 8443.17:57
nowenare you using apache on this server?17:57
palguay_no only for this17:58
palguay_do you think we can only run tomcat and use standard ports ?18:00
nowenso if you turn off apache, nothing bad happens?18:00
palguay_yes18:01
nowenthen turn it off18:01
nowenwe will use the standard ports18:01
nowenwhy was apache running?18:01
palguay_not sure18:06
nowenrun 'chkconfig httpd off'. It might have just come on after a reboot18:06
palguay_errors here http://pastebin.com/WJ4JXQKf18:24
nowenrun 'ls -all /opt/WiKID/tomcat'18:25
palguay_drwxr-xr-x  8 wikid root  4096 Apr 29 11:08 . drwxr-xr-x 14 wikid root  4096 Apr 23 21:11 .. drwxr-xr-x  2 wikid root  4096 Apr 29 11:08 bin drwxr-xr-x  3 wikid root  4096 Apr 29 13:18 conf drwxr-xr-x  2 wikid root  4096 Apr 29 11:06 lib -rw-r--r--  1 wikid root 57846 Apr 23 21:11 LICENSE drwxr-xr-x  2 wikid root  4096 Apr 29 13:16 logs -rw-r--r--  1 wikid root  1228 Apr 23 21:11 NOTICE -rw-r--r--  1 wikid root  9054 Apr 23 21:11 RE18:27
nowenrun 'netstat -anp | grep 443'18:28
palguay_there is process listening on 44318:29
nowenis it jsvc?18:29
palguay_yes jsvs.exec18:29
nowencan you get the WiKIDAdmin?18:29
palguay_no18:29
nowenis there an error?18:30
palguay_connection to the server was reset whie page was loading18:31
nowenwas that the entire output of that ls command?18:31
palguay_http://pastebin.com/9eQXEZSD18:32
nowenodd, there should be a work directory18:33
nowenwhat user are you?18:35
nowenroot?18:35
palguay_yes18:36
nowenwill you run wikidctl setup and then restart?18:37
palguay_ok18:39
palguay_looks like networking is already configured18:40
nowenjust step through it anyway18:40
palguay_yes or no18:41
nowenyes18:41
palguay_do I use both eth0 and eth118:44
nowenI don't know, one is typically used for the external IP and one for the internal. I recommend you ctrl-c out of this rather than risk messing up your network18:46
palguay_let me check something18:48
nowenalso, can you run 'ls -all /opt/WiKID/tomcat/logs'18:51
palguay_http://pastebin.com/WCxX1u0y18:56
nowenpalguay_: did you check on your thing?19:36
palguay_yes19:44
nowenand?19:44
palguay_there seem to be too many things around wikid that have been setup and it might be of not much use to go forward till that is figured out19:45
nowenyou mean to many customizations or too many other things running on the server?19:45
palguay_yes customizations and security setup19:45
nowendo you want to start over with a fresh setup?19:46
palguay_not sure about that now19:47
palguay_I will ping you once we decide how to go about this19:52
nowenok19:52
nowenalso, I need to send you'll an invoice.19:52
nowenis there a good email for that?19:54
nowensrane?19:55
palguay_yes20:01
nowenthx20:01
*** palguay_ has quit (Ping timeout: 245 seconds)20:41
*** nowen has quit (Quit: Leaving.)21:06
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid21:07
*** nowen has quit (Read error: Connection reset by peer)21:17
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid21:18
*** nowen has quit (Quit: Leaving.)22:10

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!