Wednesday, 2013-09-18

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:14
*** bdashrad has quit (Quit: leaving)16:55
*** bdashrad (~bdashrad@ocean.bdashrad.com) has joined #wikid16:56
bdashradHi. We currently run wikid for two factor auth, and recently had a problem where we couldn't reach our wikid server. Are their options for high availability?18:00
nowenbdashrad:18:18
nowenhi18:18
bdashradnevermind, i was able to find this: http://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-configure-wikid-for-replication18:18
nowenwhat do you mean you can't reach your server?18:18
bdashradwhich i think will do what we want18:18
bdashradthere was an amazon ec2 outage18:18
nowenahh18:18
bdashradso we couldn't generate passcodes18:19
bdashradand we use wikid for ssh authentication to our hosts18:19
bdashradbut i think the replication will do what we need.18:19
bdashraddo you need to change dns to point to the secondary when you fail over?18:20
nowenyes. it is a manual failover.  it can be scripted18:20
nowenwe are working on a version that will have real-time replication18:21
nowenyou in us-east?18:23
bdashradwell18:23
bdashradwe  have stuff in every region18:23
bdashradbut our wikid server is in us-east-118:23
nowenif you're interested in real-time replication and would be willing to beta test the new server, let me know18:26
bdashradi'll discuss it with my team.18:28
bdashradSo manual replication means we have to run the sync every time we add a user?18:28
nowenno - it automatically syncs - you have to promote the replicant to master to get it to serve OTPS18:28
nowenreplication is automatic, failover is not18:29
bdashradahhh, i got it.18:29
nowenso, on ec2, you could just change the virtual IP.18:29
nowencan you do that across data centers?18:29
bdashradi don't think you can use the same elastic ip in different regions18:30
bdashradbut you can use the elastic load balancer18:30
bdashradcould you get me some more information about the real-time replication?18:31
nowenworking on the docs right now.18:32
bdashradcool. i'll ping you back in here and let you know once i've talked to the rest of the team.18:32
nowenthe new version is pretty much a re-write.  We do real-time replication of everything and use DNS instead of IP addresses18:32
bdashradthat would definitely be beneficial.18:33
nowenbut - downside - new tokens.  need to re-register18:34
bdashradok, good to know.18:35
nowendo you have a lot of users?18:35
bdashraddo you need to do anything with the clients when you do a failover in the current state?18:35
nowenno - they will go to the IP address and if the secondary is promoted, they will get the response18:36
bdashradi think well over 10018:36
nowenmostly PC or smart phone or both?18:37
bdashradi'd say mostly smart phone18:37
bdashradmaybe 60/4018:37
bdashradmaybe not, my team is almost all PC, but i know a lot of the other teams use the iphone and android apps18:38
bdashradi'm sure i could find out18:38
bdashradactually. i'd say it's almost all smart phone, since our setup instructions say to use the mobile app ;)18:39
nowenjust ruminating on what the upgrade path might be18:39
nowenyou should be able to see on the Users page18:39
bdashradi don't have the login right now, i was just asked to do the research. I'm trying to find out now18:40
bdashradwe have between 200-300 users... mostly PC.18:41
bdashradeither using the java client or python client18:42
bdashradbut we're seeing more and more smartphone lately.18:42
nowenthe python client?18:43
bdashradunofficial. i'm just parroting back info.18:43
bdashradumm, hang on.18:43
bdashradhttps://code.google.com/p/pywikid/18:44
nowenthere is a python client18:44
nowenyeah, that's the one18:44
nowenthat is interesting!18:44
bdashradwe have some very technical users, and some very non-technical users18:44
bdashraddeploying new tokens may be a challenge for us18:48
nowenyeah18:48
nowenwe could throw in a license for the old server and you can migrate at your own pace18:49
bdashradthat would be super helpful.18:49
nowenthere would be management costs, but hopefully, they aren't too bad18:49
bdashradyeah, that would probably be the hardest part. lots of op's tickets.18:50
nowenwe18:50
nowenare also thinking about adding an AD/LDAP password reset capability18:50
bdashradwe don't currently use wikid with any of our ldap stuff, but it sounds interesting as well18:51
nowenjust trying to sell more seats by saving companies more money ;-)18:52
bdashraddefinitely. we could have used that at my last place18:53
bdashradinstead they had secureauth for 2FA and manage engine adselfserve plus for password resets18:54
nowenI do wonder if a lot of places have something for resets and don't care18:55
bdashradwe had it because we had 550 remote users and too many helpdesk tickets18:56
nowenouch18:56
bdashradplus they had to answer security questions which helped us meet pci compliance for verifying identity for passwrod resets18:56
nowengod I hate those questions18:56
bdashradyeah. pci is not fun.18:58
nowenok - got to run - daughter's volleyball game19:27
*** nowen has quit (Quit: Leaving.)19:28

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!