Friday, 2013-10-11

*** joevano has quit (*.net *.split)02:44
*** joevano (~joevano@c-71-193-108-171.hsd1.in.comcast.net) has joined #wikid02:44
*** humanSupafly (d4826f72@gateway/web/freenode/ip.212.130.111.114) has joined #wikid12:54
humanSupaflyhi, after upgrade of the wikid client on ios 7 it works no more12:55
humanSupaflywhen i try to generate a passcode from the domain nothing happens12:56
humanSupaflyis this a known bug? I tried on several ios devices12:57
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:59
nowenhumanSupafly: it is working for me.13:01
nowencan you try this domain:  88888888888813:01
nowenthat should be 12 8s13:01
humanSupafly@nowen, yes it works ... so it must be something with our wikid server.13:09
humanSupaflythx alot !13:09
nowenyeah, check with your admin13:12
nowentry 17412900610013:12
nowenare you on wifi? or cell?13:12
nowenit could be a dns problem13:14
*** nowen_ (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:34
humanSupaflywhen i remove the dedicated domain attribute from the jw.propterties file it works from my win8 wikid client13:48
humanSupaflyhow can i see what is in that file on an ios?13:49
*** eea (d4826f72@gateway/web/freenode/ip.212.130.111.114) has joined #wikid13:49
nowenhumanSupafly: there is no equivalent on ios13:50
nowenso, your domain is not working on either win8 or ios?13:50
nowenhmm. what is you domain id?13:52
humanSupafly21707420920413:52
humanSupaflyit's not an ip no13:52
humanSupaflyworks only via dns13:52
humanSupafly@15:50  nor android ... win8 works after dedicated domain attribute was removed from jw.properties file13:53
eeaany way to specify useIpBeforeDns=false on android/ios/win8 phone ?13:55
nowenthis is specific to you'll only13:55
nowenhmm13:56
eeanick, we created the domain back when that domain ID was a valid IP13:56
nowenyes, I'm reviewing my emails13:56
eeawe changed provider13:56
humanSupaflyforum user eea is my colleague he will take over13:56
nowenwhy would the 888 domain work but not yours?13:56
eeaworks fine using dns13:57
nowenit is only ios?13:57
eeaon PCs13:57
eeaeven if we don't specify useipbeforedns=false on PCs it works13:57
eeaafter the timeout13:57
eeait works instantly with the setting13:57
eeaon iOS, android or windows phones13:58
nowenyes.  works for me on pc and android13:58
eeaon android ?!13:58
eeawe couldnt make it work13:58
humanSupaflynope, eea, it doesnt work with ios13:58
nowenall the other dns based domains are working on ios7 for me13:59
eeawith no configuration changes?14:00
nowencorrect14:00
nowenyou can try the 888888888888 domain14:00
eeawe will try again on android and ios14:01
nowenI know it doesn't work on ios7.14:01
nowenworks for me on android too14:02
eeathanks for confirming this. if we have more data we shall get back in contact14:02
nowenI would like to know what's going on.  It is very odd14:03
nowenhas your old IP been claimed? but if that were the case, all tokens would be affected14:04
eeano, ip is not used14:05
eeai'm trying with an android and is blocked on requesting domain configuration for a alooong time now14:05
nowenhuh, I swear I just tried it on my android and got a pin request, but not mine is spinning too14:07
eeaok, pin dialog and a new long wait now ...14:07
nowenyes, same here14:07
eea217074209204.wikidsystems.net is a CNAME to a host in our domain14:08
eeacould this confuse phone clients14:08
eea?14:08
nowenhmm14:09
nowenwell. joevano's domain is also a cname and it works14:09
nowenI can change it to an ip if you like14:10
eeait worked14:10
eeai got a registration code14:11
eeait took forever but in the end ...14:11
nowenodd. so, could it be that your old IP is not failing fast enough?14:12
eeayes14:12
eeait's atimeout problem14:12
eeacan you make the client configurable or use dns before ip by default ?14:13
eeamaybe a special version for people like us ?14:13
nowennot really, because almost everyone uses IPs14:13
nowenwhy is your IP so slow to fail and not the others?14:14
eeaI can make it fail faster14:14
nowenso you still have that IP?14:14
eeai can try to contact the old (banckrupt) isp14:15
eeaand tell them to stop doing what they are doing with it14:15
nowenI wonder if they are server ads or something14:16
eeawhy a config variable in the software token would it be so wrong?14:16
nowenwe can probably set a better timeout on the app14:16
nowenoh, it's not, it's just that we are working on a new edition and don't have the cycles.14:17
nowenhttp://217.74.209.204/14:17
nowenThe server at 217.74.209.204 is taking too long to respond.14:17
nowenif that means anything14:17
eeasomeone is doing a drop of packets somwhere14:18
eeai'll try contacting the old provider but ...14:19
nowenwe can put a time out on it14:19
eeathat would help14:19
nowenI'm opening a bug on it now.14:19
eeathank you14:20
eeathat might solve it14:20
nowennp14:20
eeabye for now. I'll keep an eye out for a new version with short timeouts :)14:21
nowenwait14:21
eeawaiting14:21
nowenis this only for new registrations or for OTPs too?14:21
eeaOTPs too14:23
nowenok14:23
nowena traceroute to that IP goes to a blackhow14:23
eeaactualy the registration on androided worked (very slow) but getting the pass doesn't14:23
nowenblackhole14:23
eea:)14:23
eeayes14:23
nowenthe android token is not new though14:23
nowenhas it been happening there longer?14:24
eeawe haven't tried14:24
nowennot many android tokens/14:24
nowen?14:24
eeawe are just implementing this for mobile devices. only used laptops14:24
nowenahh14:24
nowenwell, I suggest chatting with the isp.  it would solve both issues.14:25
eealet's see if i can stil find anyone there. other than lawyers i mean14:26
nowenugh14:27
eeai'll try in the morning14:27
eea(it's 16:30 here)14:27
nowennot the best time to get a lawyer on the phone14:27
eeayap14:27
eeaby danish standards working day is over ;)14:28
nowenon a friday, same here!14:28
eeaoh. didn't realise it's f14:28
eeaso, back on this issue on monday14:28
nowenhmmm14:29
eeaa timeout clientside would help anyway14:29
nowenis there any other option?14:29
nowenit took a week for apple to approve this new version14:29
eeawindows and android might be faster :)14:30
nowenwindows is working right?14:30
eeanot windows phone14:30
eeaif we can make jw.properties it works14:30
eeaif we cannot ... depends on the default timeout on the OS14:31
nowenhow many registered users do you have?14:33
eeai'm back. we have about 70 active. we shall go to 200 or a bit more with mobile devices14:41
nowendo you expect many windows mobile users?14:42
eeanot many. 10 perhaps14:42
eeamore iPhones and androids14:43
nowenyeah. we would have to contract out the windows mobile. it's not a big platform for us14:43
eeaandroid is almost working. i was able to get a PIN now. I wouldn't call it usable though14:44
nowenany interest in moving to an IP you control?14:44
eeathat might prove tough! i'll talk to management about it14:45
nowenwell, we're chatting about adding a dns first option to the tokens.14:45
eeawe have people dispersed arround europe14:45
noweneea: you think a checkbox on domain creation that says 'Use DNS First" would be good?14:50
eeayes14:50
nowenok - digging into it14:50
*** AccentureDan (0cfa9442@gateway/web/freenode/ip.12.250.148.66) has joined #wikid14:52
AccentureDannickkkkkkkkkkkkkkk14:52
AccentureDansup man14:52
nowenhey AccentureDan14:52
noweneea: Alternately, we could have them prefix the domain code with D.14:53
noweneea: I like that because it is only you that is affected so far14:53
eeathat would work aswell14:54
AccentureDanokay here we go, so i am trying to VPN in here14:54
AccentureDani get through, then i get to verifying username and password14:54
noweneea: but, it might confusing to PC users14:54
AccentureDani checked the debug logs on the wikid server and it is saying MS-CHAP authentication failed14:54
AccentureDanand one other thing14:54
AccentureDanlemme get that14:54
AccentureDanAccess is denied for WiKID\TestUser1 (WiKID is my domain)14:54
eeaour PC users don't create the domains themselves. "we prepare distribution packs" wityh all options in jw.properties14:55
nowenAccentureDan: is WiKID\TestUser1 the name listed on the Users page in WiKID14:55
AccentureDani redid a few things, got my environment to fully mimic my current environment for remote access14:55
AccentureDanwell, it is just TestUser1...should i have it WiKID\TestUser1?14:55
eeai'm sure we can manage using the D prefix just for mobile tokens14:55
nowenAccentureDan: yes, or strip the domain before it is sent to wikid.  easier to test changing the user name14:56
noweneea: I think it sounds good14:56
AccentureDanabsolutely lemme do that, one sec14:56
AccentureDanstill failing15:02
AccentureDanhave it matching completely15:02
AccentureDan:-/15:02
nowencan you pastebin the logs?15:02
AccentureDansorry for being a tard, but how do i do that?15:03
eeanowen: can you let us know when there is progress with this? I have to go now. Thank you!15:03
nowenare you using the WiKIDAdmin logs?15:03
noweneea: will do15:03
eeabye15:03
noweneea: have a nice weekend15:03
AccentureDanyup using those15:04
eeayou too15:04
*** eea has quit (Quit: Page closed)15:04
nowenAccentureDan: just copy the pertinent logs, paste them here: http://pastebin.com/ and post the resulting url back here.  Then i can see them all there.15:04
AccentureDangotcha one sec15:07
AccentureDanhttp://pastebin.com/DFXX96ua15:09
AccentureDansorry if that looks like crap15:09
AccentureDanif you need me to format it just let me know15:09
nowenare your logs set to debug?15:17
nowenhttps://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests15:19
nowen2013-10-10 19:58:15.878 INFO com.wikidsystems.radius.log.DBSvrLogImpl <9> Access-Accept(2) LEN=387 192.168.1.143:62894 Access-Request by TestUser1 succeeded  15:22
nowenthat's interesting15:22
nowenbut then15:22
nowen2013-10-10 20:03:13.008 INFO com.wikidsystems.radius.log.DBSvrLogImpl <11> Access-Request(1) LEN=394 192.168.1.143:62894 Access-Request by WIKID\TestUser1 Failed: AccessRejectException: Microsoft MS-CHAP failed authentication.  15:22
nowenI wonder if the the WiKID\ part is the issue15:26
nowenyes it15:27
nowenis15:27
nowenyou will need to strip the domain15:27
nowenAccentureDan: why is it being sent?15:27
nowenon my server WiKID\nowen becomes WiKIDowen15:27
nowenAccentureDan: is this request coming from the vpn or NPS?15:34
AccentureDanmy bad15:38
AccentureDanhmmmmm15:38
AccentureDanNPS15:38
AccentureDani have all requests coming in to VPN pass through my NPS, then it forwards all requests on to the WiKID server i have set up15:39
nowenok, that's good15:39
AccentureDangood thing is WiKID is seeing it this time, did not before15:39
AccentureDanbut for some reason it is failing ,where i am stuck15:39
nowenwe just need to strip the domain name15:39
AccentureDanahhhh okay let me give that a shot15:39
AccentureDanalso15:39
AccentureDanwhen i do that, and then try to log in via VPN, do i just type the username and password and leave the domain blank?15:40
nowenhttp://technet.microsoft.com/en-us/library/cc731342%28WS.10%29.aspx15:40
nowenhmm - if you just enter the username and password, do you get authenticated?15:40
nowenif you don't enter it, you may not have to strip it15:40
AccentureDani tried last time and it didnt work15:40
nowenwhat was the error?15:40
AccentureDansame error :(15:40
AccentureDanlet me try again just to be 100 percent sure15:41
AccentureDanhere is a good question15:41
AccentureDanwhen i set up my VPN client, should i be using a certain auth method?  I only selected MS-CHAP-V2 since that is what we are using in our environment15:42
AccentureDanvia L2TP over IPSec15:42
nowenshouldn't matter.  ms-chapv2 is supported15:42
AccentureDanfantastic15:43
AccentureDangood to know15:43
AccentureDanokay lemme give this a shot. one sec15:43
AccentureDanhmmmm15:44
AccentureDanit worked15:44
AccentureDan:-P15:44
nowenyay!15:44
AccentureDanleft the domain out and it worked!@15:44
AccentureDanWOOT!15:44
AccentureDan:-D15:44
AccentureDanso that is a wrap? hahahaha15:44
nowenalright - that is awesome15:44
nowenlol!15:44
AccentureDan:-D!15:44
AccentureDanwow months of hair-ripping-out torture! hahahahahha15:45
nowenhehe15:45
nowenall we had to do was just do it right ;-)15:45
AccentureDanperfect man, perfect15:45
AccentureDanyou got it pal!15:45
AccentureDanreally appreciate all of your help throughout all of this :)15:45
nowenso, what's next?15:46
AccentureDannow i have the task of creating a design document and submitting it for project approval and then implementing it15:46
AccentureDanshouldnt take too long15:46
nowenwhen is your go-live deadline?15:46
AccentureDanwe recently bumped up our virtual environment quota and user estimates so we are looking at around 150-175 users (eventually)15:47
AccentureDanhmmmmmm15:47
AccentureDanlemme ask real quick15:47
nowenhave you played with example.jsp or adregister.jsp?15:49
*** qu3sti0n (~QQQ@50.115.165.16) has joined #wikid15:54
qu3sti0ndigging through community download page15:54
qu3sti0nhttp://sourceforge.net/projects/wikid-twofactor/files/WiKID_Server/3.5/15:54
qu3sti0nno .deb for the latest -utilities15:54
qu3sti0nmust i build from tarball?15:55
qu3sti0n& will a .deb be made, sometime?15:55
qu3sti0nwill be running on Ubuntu 12.04 LTS x64 or 14.04 LTS x64 once it is released15:57
nowenhmm16:00
nowenqu3sti0n: checking16:01
qu3sti0nkk16:01
nowenhttp://sourceforge.net/projects/wikid-twofactor/files/WiKID_Utilities/16:01
qu3sti0ni have no problem building if i have to, but would appreciate any insight into building it for 64-bit arch ahead of time16:01
qu3sti0nah16:01
nowenhttp://downloads.sourceforge.net/project/wikid-twofactor/WiKID_Utilities/wikid-utilities_3.4.3-1.deb?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fwikid-twofactor%2Ffiles%2FWiKID_Utilities%2F&ts=1381507315&use_mirror=softlayer-dal16:02
qu3sti0nthanks for direct link too ;)16:02
qu3sti0neasy to wget16:02
nowen;-)16:02
nowenqu3sti0n: how did you hear about us? our traffic is up recently, but I don't know why16:03
qu3sti0ni was looking into different ftp servers. found a how-to on setting up vsftpd to auth with ssh&wikid. That got me looking into wikid, for ssh shell logins, which i am going to setup16:04
qu3sti0nin test environment, first16:04
nowengotcha16:04
qu3sti0nis there a way to setup redundancy for the wikid servers? i would probably set it up on a small VPS, but would like redundancy so I could log in if that provider goes offline16:09
qu3sti0nwhich happens more often then it should16:09
nowenreplication is real time, but you have to manually promote the secondary in case of failure16:10
nowenand it needs to get the IP address of the old server16:10
qu3sti0nso i would log into 'backup' wikid server, and run some command(with offline primary server IP)  to promote it16:11
nowenyes, some people have scripted this16:11
qu3sti0nk. im looking for some docs on setting this up. are there any on http://www.wikidsystems.com/support/support/wikid-support-center16:12
nowenyes, https://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server16:13
nowenhttps://www.wikidsystems.com/support/wikid-support-center/installation-how-tos16:13
qu3sti0nah thanks, found this16:15
qu3sti0nhttps://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-configure-wikid-for-replication16:15
nowenyep16:35
AccentureDanokay im back17:01
AccentureDansorry about that17:01
AccentureDanjust did a test and walkthrough with my infrastructure lead...he really likes it and we are going to be implementing it17:01
AccentureDando you know much about prices?17:02
AccentureDango-live is immediate, so figure after i submit my design document for approval i will throw it in line in the next few weeks17:03
nowen_http://www.wikidsystems.com//pricing17:05
nowenit is pretty much $24/license/year17:15
nowena license being a username in a domain17:15
noweneach username can have more than one token17:15
AccentureDanawesome man17:17
AccentureDan:)17:17
AccentureDani dont think that will be a problem17:17
nowentoo low. pondering some increases17:17
AccentureDanwe are looking at around 175 users17:17
AccentureDanfor now that is17:17
nowenespecially for mega consulting corps17:18
nowen;-)17:18
AccentureDanyeah dude you guys have any huge contracts?17:19
nowenyeah, but it's not too much of our thing17:19
nowenwe don't respond to RFPs for example17:19
AccentureDanthis is getting some massive exposure here...the county of Los Angeles security officers are looking in to it, might set it up for them if they like it, that would be tens of thousands17:19
AccentureDanahhhhh i see17:19
nowenwe have some close to that17:19
AccentureDanso basically give it to the users and let them set it up, then just charge for licensing17:20
AccentureDansick gig man17:20
nowenwhat tends to happen is that they form a committee17:20
nowenthe committee comes up with scenarios - "We need tokens for people that don't have PCs"17:20
nowenetc17:20
AccentureDanreally like this solution, really really secure...will allow us to open up our VPN so we can allow different traffic...right now we just have VNC ports open17:20
AccentureDanahhhhhh i c i c17:21
nowenWhat I see often is that we get a small deal at a large corp and it grows17:21
AccentureDanyeah dude i cant even imagine...what is your role within this company?  Are you the main tech support lead?17:21
nowenAccentureDan: yeah, so then they want to know if we support SMS, which we don't because it is not secure or securable17:21
nowenAccentureDan: ;-)17:21
nowenyea17:21
nowenand mroe17:21
AccentureDantotally dude i completely understand...i really really like the fact we can use this for more than just VPN access...can use it for mutual auth and such, can grow with the solution over time as the application developers need it17:22
AccentureDansecure stuff internally as well17:22
AccentureDanit's really solid man17:22
nowenthanks ;-)17:22
AccentureDanyou guys absolutely nailed it17:22
nowentell your friends and twitter followes!17:22
AccentureDanhopefully i can get you guys more exposure...Accenture signed on with Symantec, friggin garbage17:22
nowenlol17:23
nowenyou do know this channel is logged, right?17:23
AccentureDanbut i know security is a huge thing now, and clients are always looking at ways to secure theirr data, so this might grow beyond our project and walls17:23
AccentureDanwe shall see17:23
AccentureDani dont mind17:23
qu3sti0nsymantec is garbage lately17:23
nowen;-)17:23
AccentureDan;-)17:23
nowenyour using the symantec authentication service?17:24
AccentureDanput it this way. we put it in line to be our next vpn solution, and even though it went go-live it still doesn't work on our managed PCs17:24
AccentureDanyup, just for VPN access to Accenture managed stuff17:24
AccentureDanwe still have some hard token stuff with RSA but that is getting phased out17:24
nowenyeah, we're getting a lot of ex-rsa users17:25
AccentureDanyeah man17:26
AccentureDanhard tokens are just a pain17:26
nowenI don't think rsa is investing much in the platform. they say the server hasn't changed in decades17:27
qu3sti0nwell even RSA says to not trust their stuff at this point17:28
AccentureDansad, EMC used to OWN in multi factor auth17:28
qu3sti0nafter NSA revelations17:28
AccentureDanLOL17:28
nowenyeah, btrust17:28
nowennot so much17:28
qu3sti0nopen-source in security related software is KEY17:28
nowenbut, to be honest, if they are in the  RNGs of the operating systems, we and everyone has isssues17:28
AccentureDani agree with question17:29
AccentureDanespecially having this located on a linux OS17:29
nowenalso, since our keys are generated on the token devices there's no risk to you if we get owned17:29
AccentureDaneven though it will be facing externally i can sleep better at night17:29
AccentureDanexactly17:29
AccentureDanand they need a pin and passcode JUST to get the OTP17:29
AccentureDanand then and ONLY THEN can they gain access17:29
AccentureDancombine that with a strong NPS policy and you have a secure solution17:29
AccentureDanreally like how it flows17:30
AccentureDanwont be too difficult to implement17:30
nowenright - better to notice excessive PIN attempts on the auth server than on the access server17:30
AccentureDanexactly, those can be logged, including logs on the authentication servers for AD and whatnot17:30
AccentureDanjust easier from a systems admin standpoint17:30
AccentureDanokay question17:43
AccentureDanso for pleasant aesthetics how would we go about letting users put in the domain, and having it work17:44
AccentureDanyou mentioned stripping it?17:44
nowenmany radius servers provide the option of stripping the realm or domain17:45
AccentureDanahhh okay17:46
AccentureDanso that document you sent me will show me17:46
AccentureDannot really familiar with variables17:46
AccentureDanwill take a look17:46
nowenyeah.17:46
nowenthe key is to have it be  nowen@domain.com17:46
nowenand not domain\nowen17:46
nowenCheck out ADRegister too17:46
nowenhttp://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-let-users-add-themselves-using-ad-credentials17:47
nowenand example.jsp http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly17:48
noweni highly recommend this!17:48
nowenI have a meeting - I'll be back in a about 1.5 hours17:48
AccentureDankk you got it man17:49
AccentureDanthanks again17:49
nowenglad it is working17:49
AccentureDanworking on adregister now :)17:50
nowenok17:50
nowenbiab17:50
*** nowen has quit (Quit: Leaving.)17:50
*** nowen (~nowen@172.56.4.84) has joined #wikid17:54
*** nowen has quit (Client Quit)17:54
*** nowen_ has quit (Ping timeout: 248 seconds)17:58
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid19:59
nowenAccentureDan: occurred to me: if your users are registered as username@domain.com in adregister, then that is how they would need to login to the VPN20:05
AccentureDanhey man20:11
AccentureDanyeah was just gonna say20:11
AccentureDanim having issues with that JSP20:11
AccentureDanit keeps erroring even though i have it set up right in the file20:11
nowenwhat's the error?20:11
AccentureDantheoretically they log in that way with the VPN already...isnt WiKID\user the same as user@WiKID.local?20:12
AccentureDanone sec lemme get it for ya20:12
AccentureDanauthentication to the directory failed for user@WiKID.local20:12
AccentureDanalso does LDAP have to be enabled as a protocol within WiKID?20:14
nowenno it doesn't20:14
AccentureDanokay i will disable it20:14
nowenwhat is the error in AD?20:14
AccentureDani also added my DC as a network client as recommended since this JSP will exist on the WiKID server20:14
AccentureDanlemme check20:14
nowenadding as a network client just forces the firewall to open the port20:15
AccentureDanyeah dide that just in case20:15
nowencan that user login to windows with that password?20:15
AccentureDanhavent tried, lemme give it a shot20:15
AccentureDanyup20:19
AccentureDani can20:19
nowenhm20:21
nowendid you restart wikid after adding AD as the network client?20:21
*** nowen_ (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid20:30
nowenyou can run 'iptables -L -n' to see if the port is open for your AD server20:37
AccentureDanyup i did20:42
AccentureDansorry about that20:42
AccentureDanokay lemme check one sec20:42
AccentureDanyep its open20:43
AccentureDanlemme restart wikid20:43
nowenhmm20:44
nowenif the port is open, no need to restart20:44
*** nowen_ has quit (Quit: ZNC - http://znc.in)20:45
AccentureDanman weird20:48
AccentureDanyeah keep getting errors20:48
AccentureDanokay lets walk throug hthis20:49
AccentureDanthe config file20:49
AccentureDanso i can access the JSP file from outside the domain, good to go there20:49
AccentureDanin the file itself is this20:49
AccentureDanhttps://<yourWiKIDServer>/wikid/ADRegister/ADRegister.jsp20:50
AccentureDanwoops20:50
AccentureDanwrong thing20:50
AccentureDansorry20:50
AccentureDandirectorydomain suffix is "WikID.local"20:50
AccentureDanldapURL = "ldap://WikIDServerTest.WikID.local:389"20:51
*** wikiduser (26536222@gateway/web/freenode/ip.38.83.98.34) has joined #wikid20:51
AccentureDandomainCode = "010067106071"20:51
AccentureDanWikidIPAddress = "127.0.0.1"20:51
wikiduserany known issues with the new 3.7 update to the WiKID iPhone app?20:51
AccentureDanleft the cert location alone, gave the cert password the one i set up in the beginning20:52
nowenwikiduser: seems to be20:52
AccentureDanmy domain is WikID.local, my domain controller's name is WikIDServerTest.WikID.local20:52
wikiduserany workarounds or ETA for a fix or anything?  guess we should have users generate new tokens with a different client for now..20:53
nowenare you with gdsx?20:53
wikiduseryes20:53
nowenwhat is your domain identifier?20:54
*** wikiduser has quit (Ping timeout: 250 seconds)20:57
nowenWiKIDLogBot: what is your domain identifier?  I need to know if it is ip based or dns based.21:01
nowenit is not part of the security of the system as it is public on the internet, pretty much21:01
nowenoops, here I am chatting with the logbot.21:03
AccentureDanLMAO21:04
AccentureDanyeah, logbot, WHAT IS IT?!?!?!?!21:04
AccentureDan:-P21:05
nowenWiKIDLogBot: ANSWER ME!21:05
AccentureDanLMAO!21:05
AccentureDansorry did you need my domain identifier?21:05
nowenclearly ready for coctail hour21:05
nowenhehe  - no not yours21:05
qu3sti0nit is what records me going on the official record saying 'Symantec sucks now'21:05
AccentureDanwe all are :)21:06
AccentureDanLOL21:06
AccentureDani again happen to agree with qu3sti0n :)21:06
nowenAccentureDan: try this, try using the IP address of your AD server instead of the name21:07
nowenI hope he got his iphone working, because I can't imagine they have the same problem as the eu guys21:07
qu3sti0ni was looking at the 'droid app, and not like i put much stock in reviews from anonymous people on the internet, but most recent reviews reporting problems with that version too21:08
nowenyeah. some are legit, but many are people that don't know you need a server for it21:09
nowenalso, while I'm pissed that apple forced us to make an update for ios7, I'm also pissed at google for all the versions they have21:11
AccentureDanLOL21:13
AccentureDanwait, we need a server?!?!?!21:13
AccentureDan:-P21:13
nowenwhile I'm raging, the worst are the blackberry errors.  they send them from the BB and most are from countries where we don't have any customers21:14
AccentureDanBlackberry is also garbage21:15
nowenwe've been dealing with them for a long time.  they never gave a crap about devs21:16
nowenthat being said, we can do better on the mobile front21:17
nowenqu3sti0n: did you see this: http://www.wikidsystems.com/support/wikid-support-center/faq/whats-the-difference-between-the-community-release-and-enterprise-release21:18
AccentureDantrue but BB, honestly21:19
AccentureDanlook at them now21:19
AccentureDandown the tubes...they were supposed to wow us with 10 and all they did was make the same product, very disappointing21:20
AccentureDananywho, any idea about the JSP problems?21:20
nowenyeah.  we tried to get them to drop rsa tokens for something that ran on their own devices.  they did not comprehend21:20
AccentureDanLOL21:20
AccentureDanthe big wigs got scared that something might work ;-)21:20
nowentry using the IP of your domain server instead of the dns21:20
AccentureDanfor the ldap?21:20
nowenyeah21:21
AccentureDankk one sec21:21
AccentureDanyup worked21:23
AccentureDani kind of thought21:24
AccentureDanseeing as there was no way to decipher my DNS name in Linux21:24
AccentureDangood man Nick!21:24
AccentureDantwo problems solved in one day, you need to mark this one down in the record book hahahahaha21:24
qu3sti0nyeah i looked at that. just 3rd party code that can not be released under gpl21:27
qu3sti0nwhich is fine w me21:27
qu3sti0ni wont know what im missing ;)21:27
nowen;-)21:27
AccentureDanalright man i have to prepare documentation for this solution so i am heading out of here, have a great weekend21:35
AccentureDanill keep you posted on how things go :)21:35
AccentureDanthanks agian for all of your help!21:35
nowenno problem.21:35
qu3sti0nsee ya21:35
AccentureDanlater fellas!21:35
nowenlater21:35
*** AccentureDan has quit (Quit: Page closed)21:35
nowenI'm gonna check out too.  today has been unusually busy21:40
qu3sti0nkk21:42
qu3sti0nsee ya21:42
nowenlaer21:42
nowenlater21:42
*** nowen has quit (Quit: Leaving.)21:42

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!