Monday, 2013-10-14

*** humanSupafly has quit (Quit: Page closed)07:23
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:35
*** nowen has quit (Quit: Leaving.)14:04
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid14:04
*** AccentureDan (0cfa9442@gateway/web/freenode/ip.12.250.148.66) has joined #wikid18:57
AccentureDanhowdy Nick!18:57
AccentureDanquestion for ya18:57
nowenhi18:57
nowenok18:57
AccentureDanfirst, which ports need to be opened for the WiKID server to authenticate domain requests?18:58
nowenthe tokens use port 8018:58
AccentureDanokay awesome, same with the auto-authentication?18:58
AccentureDanadding themselves to the WiKID domain as users18:58
AccentureDanwith that java applet via web browser18:58
nowenthat uses 44318:59
nowenbut - you most likely want that locked down internally anyway18:59
AccentureDanokay so externally facing the Internet 80 and 443 need to be opened18:59
AccentureDanyup18:59
AccentureDanjust trying to map out what ports we need opened through our internet gateway and router/firewalls18:59
nowenwell - 443 is both the registration and WIKIDAdmin.  I recommend only 8018:59
AccentureDanokay so 80 only facing the Internet, gotcha19:00
AccentureDaninternally, what would it need open?19:00
AccentureDani know radius19:00
nowen443, 181219:00
AccentureDanawesome19:00
nowenif you are using wauth, 838819:00
AccentureDanyup. just to be clear19:01
AccentureDanwhat exactly is wauth used for again?19:01
nowenit is our API.  Example.jsp and ADRegister use it, but the do it locally.  you could move those scripts to another server19:01
nowenbut that server would need to be a wauth network client19:02
nowenand use their own cert19:02
AccentureDanyeah better off just to leave it there, it is going to be isolated anyways19:02
nowenyou don't want your ADRegistration exposed on the internet19:02
AccentureDanreason i need these port mappings19:02
AccentureDanmakes sense19:02
AccentureDanso would you suggest moving the ADRegistration to another server that isnt facing the Internet?19:03
AccentureDansince our WiKID server will19:03
nowennot if you block 443 from the internet19:03
AccentureDanyep that is the plan. only to have 80 open19:04
nowenI think that is sufficient, but you'll might think otherwise19:04
AccentureDanshouldnt be too difficult to host somewhere else, can look in to it19:04
AccentureDanso even though 443 is blocked, and 80 opened, will users still be able to reach the ADRegister.jsp from the wikid server?19:05
nowensome have created mini-CSR apps out of example.jsp19:05
nowenno - the idea is that they need to be internal to register19:06
AccentureDanso theoretically users would register internally inside of our network first, not from the Internet19:07
nowenit is an additional layer of security19:07
nowenyes, again, that's what we recommend19:07
AccentureDani completely understand19:07
AccentureDanso internally to our Wikid server 443 would be opened internally, along with 80 and wauth19:08
AccentureDanand only 80 would need to be open externally to allow domain requests to go through19:08
nowenand radius19:08
nowenyes19:08
AccentureDanyup and 181219:08
AccentureDanokay gotcha19:08
nowenI think that is it19:08
AccentureDansorry for all the questions, just want to get a handle on this19:08
AccentureDanawesome let me document this19:09
AccentureDanso the domain controller does not need to be added as a network client, that was only to bypass adding a port exception to our firewall right?  for ADRegister.jsp19:16
nowencorrect19:16
AccentureDanwhat port was that again?  sorry for all the questions19:16
nowenotherwise, we have to tell people how to use iptables ;-)19:17
nowen38919:17
AccentureDanthought so, thanks man19:17
AccentureDanLOL19:17
AccentureDanthat would go over like a fart in church19:17
AccentureDan:-P19:17
nowenit's alright - good docs will help19:17
nowenlol19:17
AccentureDanyeah man something we have been falling behind with20:02
AccentureDanjust have to keep up on it20:02
AccentureDanespecially when network design is going to change with this20:03
AccentureDan;-)20:03
nowenyep20:03
AccentureDanquick question20:15
nowenok20:15
AccentureDanremember how we were talking about stripping the domain from the logon request20:15
nowenyes20:15
AccentureDanit would only work if the username matched EXACTLY to what was in Wikid20:15
AccentureDanwould you find most users leave that attribute out?20:16
AccentureDani mean customers*20:16
nowenyes, I think so20:16
AccentureDanright now they just log in with their username, instead of the domain20:16
AccentureDanokay kind of figured20:16
nowenless typing20:16
AccentureDanit doesnt matter much here20:16
AccentureDanexactly20:16
AccentureDanmakes it easier :)20:16
nowenbut some may have more than one domain20:16
AccentureDanless things for them to mess up hahaha20:16
AccentureDanyeah we only have one20:16
*** nowen has quit (Quit: Leaving.)21:16

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!