Wednesday, 2013-08-28

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:25
*** nowen has quit (Remote host closed the connection)13:19
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:20
*** AccentureDan (0cfa9442@gateway/web/freenode/ip.12.250.148.66) has joined #wikid16:58
AccentureDansup Nick!16:58
nowenhey Dan!16:58
nowenhow goes it?16:58
AccentureDanjust a little status update...have the VPN in place in the test domain, all working and ready to go...currently have my DC with NPS as my RADIUS server, and my little VPN box as the client16:59
AccentureDanso am ready to work on this solution today to get WiKID in place with VPN16:59
AccentureDangoing great man how ya doin?16:59
nowenok - so you have it all working without WiKID?16:59
AccentureDanyup16:59
nowendoing well!16:59
nowencool16:59
AccentureDanall working without wikid16:59
AccentureDanand i verified that wikid works internally16:59
nowenstart simple, I say17:00
AccentureDanadded a user, tested with that little java app17:00
AccentureDanabsolutely, keep it simple17:00
nowenyou mean example.jsp?17:00
AccentureDanyup17:01
nowenso, now you just have to add WiKID to NPS with a connection policy?17:03
*** Mark__ (8f74745b@gateway/web/freenode/ip.143.116.116.91) has joined #wikid17:07
Mark__Nick are you here?17:07
nowenyes17:07
Mark__hello17:07
Mark__got a question17:07
nowenok17:07
Mark__all of our ATT cell phone users are having an issue17:08
*** Troy__ (329b9bb1@gateway/web/freenode/ip.50.155.155.177) has joined #wikid17:08
nowenoh my17:08
Mark__their Wikid clients are being updated17:08
Mark__and erasing their token17:08
nowenandroid or iphone?17:08
Mark__Hello Troy17:08
Mark__android17:08
Troy__Hi there17:09
Mark__do you use different versions for different carriers as well?17:09
nowenno17:09
nowenwhat version are they using?17:09
Mark__Troy what version is it showing you on?17:09
Troy__on my Android phone, I upgraded to 4.3 last week and lost my domain17:09
Troy__sorry.. Token client for Android version 3.417:10
Mark__on Verizon i am on 3.5.13 and not showing any updates available17:10
nowenyou mean your OS updated and it deleted your token?17:10
Troy__no.. just the WiKID app updated.. I'm on Jelly bean 4.11 and hasn't had an OS update since last december17:11
nowenI thought you had updated the WIKID token17:11
nowenok17:11
nowenour current version is 3.5.1217:11
nowenoops17:11
nowen3.5.1317:11
Mark__whew okay so I am on hte latest on my phone17:12
nowenhmm17:12
Mark__I have not had any issues but i am on verizon17:12
Troy__I don't remember which WiKID app version I was running before..  last week or the week before the Google play store showed a WiKID client upgrade was available.. and I went ahead and upgraded17:13
nowen3.5.1 was released Sep 27, 201217:13
Troy__I'm going to remove the client and re-install from the play store17:13
Mark__Troy what Android version are you on?17:13
nowenI was going to remove the latest from production to stop any upgrades, but it seems like you'll are on a later version17:14
Troy__Android version 4.1.1 (jelly bean)17:14
Troy__on a Motorolla Atrix HD17:14
nowenTroy__: and you say the WiKID version is 3.4?17:14
Troy__yes.. it appears the upgrade actually downgraded me from WiKID 3.5.x down to 3.417:15
Mark__that does not sound good17:15
nowenthat's damn screwy17:15
nowenthere's not some special at&t app store, right?17:16
Troy__no.. i always remove those carrier stores17:16
Troy__this was straight from Google play17:16
nowenI don't even see 3.4 on the developer app store17:16
Troy__I just uninstalled WikiD app and re-installed and it's still WiKID 3.417:16
Troy__let me try on my wifes Nexus 7.. it's running Android 4.317:17
Mark__i have Android 4.1.217:18
nowenon the app store page, is the date published Aug 9th?17:18
Troy__Yes.. Aug 9th, 201317:19
Troy__that may have been when the update came though on my phone17:20
Troy__Just did a fresh install of WiKID app on my wifes Nexus and it's showing Version 3.4 as well17:20
Troy__this device hasn't had any version of WIkid app installed prior to now17:21
nowenhmm17:21
Mark__is it ATT?17:21
nowenno, I've replicated it on my deviec17:21
nowent-mobile17:21
Troy__Mark.. what does your Play store show for a date?17:22
Mark__okay17:22
Mark__aug 9th 201317:22
Troy__and doesn't it show an upgrade available?17:22
Mark__no17:22
nowenit could be that the version in the source code is inaccurate17:22
Mark__so when i open my about wikid it actually shows Token client for Android vers 3.417:25
Troy__in the meantime, can you stop the upgrade?17:25
nowentrying17:25
Troy__so folks aren't actually downgrading and losing their domain settings?17:25
Mark__not sure but so far you, Matt and Rick have all lost yours when these auto updates run17:26
Troy__i need to run for a bit to pick up my daughter from pre-school.. i'll be back in a few17:26
nowenI have removed it from the store17:26
Mark__okay can you follow up in an email if you find out what is occuring17:28
Mark__i need to drop off over in Europe this week and need to grab some dinner will leave this up and check back when i get back17:28
nowenok17:30
nowenTroy__ or Mark__ - how many devices did this affect?18:07
*** newbiw (41337b6e@gateway/web/freenode/ip.65.51.123.110) has joined #wikid18:31
newbiwhi nick18:31
nowenhi18:32
newbiwi have the wikid server installed for radius and wikid's protocol18:32
nowenwho is that?  ;-)18:32
newbiwi setup a network client18:32
newbiwi setup a user18:32
newbiwthe user is going to login into the network client , the network client is a ubuntu server18:33
newbiwi can see the pam radius is sending the request to wikid server18:33
newbiwbut i dont see the user getting the request to enter its token18:33
nowendid you restart the WiKID service after adding the network client?18:33
newbiwyeah18:34
newbiwi can see the user account being sent to  the wikid server18:34
newbiwi will restart wikid anyways now18:34
nowenyou can see the radius request hitting wikid?18:35
newbiwno18:35
nowenare you running tcpdump on wikid?18:35
newbiwclient is saying no one responding18:35
newbiwlet me start it, port 181218:36
nowenrun 'tcdump port radius'18:36
nowen;-)18:36
newbiwwikid sent a 'reject' but the user got the login shell on ubuntu machine18:37
newbiwi believe this is more of network client configuration to have 2 factor authentication for the user18:37
nowenyeah, sounds like your pam radius config is off18:38
*** AccentureDan has quit (Ping timeout: 250 seconds)18:38
nowenrun 'tail -f /var/log/auth.log' on the client to see what is happening18:39
newbiwdo i have to copy pam_radius_auth.conf to /etc/raddb/server18:39
nowenI did not do that.18:39
nowenthat should not be the issue as the requests are getting to WiKID18:40
nowenit is probably your /etc/pam.d/sshd18:40
newbiwso let me ask you a simpler question. what is the expected behivour18:40
nowenif WiKID sends a reject, the user is prompted for their password again18:40
newbiwyeah that didnt happen18:41
newbiwlet me reload ssh again18:41
nowenauth.log will tell you what is happening18:42
*** Troy__ has quit (Ping timeout: 250 seconds)18:42
newbiwwhat am i supposed to put in , the local password or the wikid token. I am only getting a prompt to put in the password18:43
newbiwgoogle auth token asks for password then passcode18:43
newbiwif i just put the passcode, i get Access Accept from WIKID18:44
nowenoh - just the WiKID OTP18:46
newbiwso i were to attempt to login from a different host into the client, i wont be allowed because otp is unique to my laptop18:47
newbiwno18:49
nowenmostly, the token on your laptop is valid for your username and PIN on WiKID. the private key in it is unique.  You can also have another token on your phone that would be unique, but also be valid for your username and PIN18:49
newbiwshould i create a password for the user on the local system ?18:49
nowenyou should create an account, unless you are using ldap or something for that18:50
newbiwOn this host i already have a few accounts18:50
nowentell me, why do you not want to use google auth?  I'm curious18:50
newbiwI dont want to because i cant get NX to work with it18:51
nowenahh18:51
newbiwi want to secure the machine using Wikid18:51
Mark__Nick i am back now18:51
nowenhey Mark__18:51
Mark__not sure at this moment i only know of 618:51
nowenMark__: we are working on it.  I think we may have signed the latest with a different key18:52
Mark__I will have to do some research to find out a total number18:52
Mark__okay18:52
nowenMark__: it's ok.18:52
nowennewbiw: what do you see in your /var/log/auth.log18:53
newbiw<@nowen>Aug 28 18:55:53 wikid-client sshd[27175]: pam_radius_auth: DEBUG: getservbyname(radius, udp) returned -1930210624.18:56
*** Mark__ has quit (Ping timeout: 250 seconds)18:56
nowenhmm. that's not super helpful ;-)18:56
newbiwAccepted password for jsingh from 10.120.20.109 port 50072 ssh218:57
nowenok - was that with the OTP?18:57
newbiwYes18:57
newbiwI am logged in using the Wikid Server Token and not using the local password18:57
nowenok - that's good right?18:58
newbiwi thought the tokens worked like google's system, where you had to put the password once then the token18:58
nowenhmm - is that what makes it not work for NX?18:59
newbiwyes18:59
newbiwi think so18:59
newbiwhow is it supposed to work Wikid18:59
nowenbecause the NX client only wants one password19:00
newbiwrequest passcode , then ssh into machine and enter the passcode19:00
newbiwi want to make sure first that i have 2 factor with wikid19:00
newbiwhow are we achieving that here sorry , i am not seeing that19:00
newbiwubuntu ssh client is only asking for one password, shouldn't it be asking for two things19:03
newbiwplease help me understand it19:03
nowenno - the two factors are represented in the OTP.  possession of the private key embedded in the token and knowledge of the PIN19:03
*** Troy (329b9bb1@gateway/web/freenode/ip.50.155.155.177) has joined #wikid19:04
newbiwok so this is a one time password , and since your account was setup with asysmetteric keys with wikid server on the client19:05
nowenyep19:06
TroyNick.. i don't know for sure how many installed the Android WIKID update.. but I would say there are about 1,000 or so Android devices of the 4200+ devices (1227 users)19:07
Troyhas the new source been updated in the play store?19:07
*** Mark__ (51b7fb04@gateway/web/freenode/ip.81.183.251.4) has joined #wikid19:07
Mark__back got disconnected19:07
nowenTroy: not yet19:08
Mark__Is there anyway to fix the users that have been affected besides having them re-register?19:08
Troyok..last time I checked, the token client wasn't available19:08
nowenTroy: good - they said it might take a few hours to unpublish19:08
nowenMark__: I have serious doubts about that19:09
Mark__okay19:09
*** nowen has quit (Remote host closed the connection)19:12
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid19:13
Mark__Nick when you think this is corrected can you send me an email so i can send a memo out ot all our users having them verify if they were affected and if so a quick reminder of how to register again19:15
nowenyes, will do19:15
noweni'm very sorry about this19:15
Mark__Is this only on Android?19:18
nowenyes19:18
Mark__did it affect the IOS or Windows mobile device tokens?19:19
Mark__okay19:19
nowenno - we have not updated those19:19
newbiwthanks nick19:24
nowennewbiw: is it all working?19:24
newbiwnow i have to test the NX part19:27
nowengreat19:27
Mark__Nick I am dropping off just let me know when it is fixed so i can send out a memo to our users making them aware of this issue and thanks again for your prompt support19:35
nowenwill do19:35
*** Mark__ has quit (Ping timeout: 250 seconds)19:43
newbiwNick i am now getting access reject on radius20:49
nowennewbiw: check to see if the user is enabled20:49
nowenthat happens in testing20:50
newbiwdoes it automatically gets disabled ?20:50
nowenif you exceed the limits on bad pins or otps20:50
nowenyou can set the logs to debug: http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests20:51
nowenand get more info20:51
newbiwhe was disabled20:52
nowenpeople try stuff when testing and it adds up. I doubt you will see it much in prod20:53
newbiwcool20:54
newbiwNX now works with the token20:54
newbiwi will present it to the client next week20:54
nowenif you do, you can change the settings on the domain20:54
nowennice!20:54
nowenare you using freenx or the commercial?20:54
newbiwi got the evaluation software21:02
newbiwi can create a new vm and try free nx tomorrow21:02
newbiwlet them know both ways21:02
nowenhave you checked out nx 4?21:02
nowenfreenx is a bit old21:02
nowenbut seems solid21:03
newbiwno my client is 3.521:03
newbiwlet me check the server's version21:03
newbiw3.5 also21:04
newbiwnx free is 3.5 also21:04
newbiwthanks21:06
*** newbiw has quit ()21:06
nowenjoevano: do you have an android token installed? or you coolacid21:59
*** nowen has quit (Quit: Leaving.)22:06
*** Troy has quit (Quit: Page closed)22:08
*** AccentureDan (0cfa9442@gateway/web/freenode/ip.12.250.148.66) has joined #wikid22:27

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!