Friday, 2013-06-28

*** Rsh (52a898bc@gateway/web/freenode/ip.82.168.152.188) has joined #wikid13:06
*** Rsh has parted #wikid (None)13:07
*** Rensharma (52a898bc@gateway/web/freenode/ip.82.168.152.188) has joined #wikid13:08
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:11
*** nowen has quit (Quit: Leaving.)13:43
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:45
*** nowen has quit (Ping timeout: 268 seconds)19:05
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid19:07
*** Ssamantha (~Ssamantha@50-88-95-126.res.bhn.net) has joined #wikid20:08
SsamanthaHello anyone around?20:09
nowensure20:09
SsamanthaDoes WIKID server function as RADIUS server or just talks to RADIUS?20:09
nowenreally, the latter.20:09
nowenwhat are you trying to do?20:10
SsamanthaCOnfigure 2 factor for vpn wifi and xenapp fundamentals20:10
nowenwell, you can have all of those point to WiKID, but it is best to run it through a radius server20:11
nowendo you have one?  are you partial to cisco, windows or freeradius?20:11
SsamanthaWhat is benefit of going through RADIUS? How would you be able to avoid RADIUS with Xenapp?20:11
SsamanthaDo not have a RADIUS server yet20:11
nowenRadius gives you one point to disable your users, which is a big deal. you can also do authorization at your directory and then auth at wikid20:12
nowenare you running AD?20:12
SsamanthaNO these are very small independent physician offices that need regulatory compliance20:13
nowenahh20:13
SsamanthaTypical one db server 5-10 users20:13
nowenso, is xenapp running at these offices?20:13
SsamanthaYes at a few20:14
nowenyou can have them all talk radius directly to wikid20:14
SsamanthaStatic password port 443 forwarded , simple stuff20:14
SsamanthaOk so WIKID functions sort of like a RADIUS server?20:14
SsamanthaCAn I point directly to WIKID server instead of RADIUS20:15
nowensort of.  it is really an auth server that talks radius20:15
nowenyes20:15
SsamanthaSuper. that is what I was hoping. Are you a user or admin20:16
nowenI work for WiKID20:16
SsamanthaSo is it possible to aggregate all of these independent offices/users to one cloud based WIKID server.20:17
SsamanthaPrivate Cloud20:17
nowenI would think so.20:17
nowenseems like you might want one big xenapp server, etc20:17
SsamanthaWhat ports would have to be open to access WIKID server in that scenario?20:18
nowenthe tokens use port 80. the admin is 44320:18
SsamanthaWish I could but each office is a completely independent business entity.20:18
nowenif you use radius between your cloud and the offices, you will need to tunnel it. radius is not encrpyted20:18
SsamanthaGot it so will need WIKID server at each office. Xeanpp uses 443 is it possible to configure WIKID smrtphone app and server for alternate port?20:20
nowenthe WiKIDAdmin interfaces uses 443.  the token use port 80.  You can change the admin interface port, but not the tokens20:21
nowenyou can proxy them to a different port if you have that capability, but we can't re-write the token clients20:21
SsamanthaRight ok20:22
SsamanthaI downloaded the appliance ISO and will set up to test. Thanks for all the info.20:22
nowengreat20:23
SsamanthaIin Virtual Box which Linus distro should I choose?20:49
nowenredhat 3220:49
SsamanthaThanks20:49
nowennp20:49
SsamanthaRun as live CD or install to a vxd20:50
noweninstall20:50
Ssamanthaok20:50
SsamanthaInstall boot stuck on NET: Registered protocol family 220:58
SsamanthaAny boot flags I should pass?20:58
nowenhmm.  did you Enable IO apic?20:58
SsamanthaWill check20:59
nowenusually that happens automatically20:59
SsamanthaYea i used default Vbox params20:59
nowenis this an AMD host?20:59
SsamanthaYes20:59
nowenhmm, google thinks it is the IO apic.  check it under Settings/System21:00
SsamanthaYep found it rebooting now21:01
SsamanthaYea thats was it21:01
SsamanthaUsername:WiKIDAdmin  (mixed-case)21:10
SsamanthaPassword:2Factor??21:10
SsamanthaIs that console login as well?21:10
nowenthe console login is root/wikid21:16
Ssamanthaok21:19
nowenonce you are logged in as root, you can follow this doc: http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/referencemanual-all-pages21:20
noweni see you got your cert22:02
SsamanthaYes working on it got interrupted22:18
SsamanthaLot of new concepts. I am generally knowledgable re public private key encryption but need some study.22:19
SsamanthaAny good primers?22:19
nowenhttp://www.wikidsystems.com/learn-more/how-it-works22:19
SsamanthaAs relates to WIKID22:19
nowenand http://www.wikidsystems.com/learn-more/white-papers22:19
SsamanthaWill read, Thanks22:20
nowenessentially, we use the keys to encrypt PINs one way and OTP back.  Most tokens use shared secrets22:20
nowentime for me to head out.  Are you at a goodish spot?22:20
SsamanthaYea I have a lot of reading to do and will probably take back up on Monday, Thanks again and have a good weekend.22:21
nowenyou too!22:21
*** nowen has quit (Quit: Leaving.)22:21
*** Ssamantha has quit ()22:34

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!