Tuesday, 2013-11-05

*** Ravi__ (ca419303@gateway/web/freenode/ip.202.65.147.3) has joined #wikid09:31
Ravi__Hi everybody09:31
Ravi__can anybody help Wikid Integration with OpenVPN09:45
Ravi__any pointers or URLs in this regard will be quite helpful09:45
*** Ravi__ has quit (Quit: Page closed)12:05
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid14:11
*** Elmar_ (2e2250b8@gateway/web/freenode/ip.46.34.80.184) has joined #wikid15:47
Elmar_Hi Nick, just a quicky as I started to setup my wikid server. Somthing wrong with the update function?15:49
Elmar_first got, cannot resolve hostname, filled  the resolv.conf witrh my name server, then I got a 120 secs timeout.15:50
nowenElmar_: we do updates via rpm now15:50
Elmar_thanks, whish you good luck! ;-)15:51
nowenwait, what are you trying to do?15:51
nowenare you trying to update the ISO?  via yum?15:51
Elmar_had a fresh install and tried the button Configuration, Update the WIKID Server, was just curious.15:52
nowenahh, ok.15:53
Elmar_I installed the ISO into a VMware guest yesterday.15:53
nowenany issues?15:53
nowenother, I mean ;-)15:54
Elmar_3.5 0-b1472, probably no update available ;-)15:54
nowenhehe, correct. ;-)15:54
Elmar_Got my Token Client on the iPhone working already.15:55
Elmar_Now I have to setup some network clients.15:55
nowencool.  we just had to update it, thanks to Apple15:55
nowenradius is your friend15:56
Elmar_never had to deal with radius before, so many new things for me ;-)15:56
nowenwell, the most complex thing about it is the vague terms.15:57
nowenwill you run the authentications through your directory?15:57
Elmar_need to run 2factor authentication for MS Exchange OWA, openVPN, Lotus notes web interface, maybe single sign on if possible.15:57
nowenso, radius will work with all of those.   You can point them directly to WiKID or you can point them to the MS radius plugin NPS and it will authorize the users based on their AD username and proxy the creds to WiKID if they authz ok15:58
Elmar_just somewhere inbetween our project to move from Lotus Notes to Outlook/Exchange15:58
Elmar_and suddenly dealing with 2 ADs, our won plus the one from the mother company :-(15:59
nowenhmm16:00
nowennot sure what to do about two ADs16:01
nowenSo, will some users of these services be on different ADs?16:02
Elmar_the PC is in the one domain and needs another authentication for Exchange in the other domain, not nice for the user.16:02
nowenwow, yeah, I don't know. Maybe the MS federation product would help?16:03
Elmar_no, no, keep them seperatly for the moment, enough hassle with Exchange ;-)16:04
nowenlol16:04
Elmar_can I ran auth.against 1st domain for openVPN and auth.  for WebAccess to the 2nd domain on the same wikid server?16:05
nowenyou can certainly have more than one WiKID domain, but you might be better off doing that logic in a real radius server, ie, NPS16:06
nowenor freeradius16:06
nowenBecause then your AD admins or HR people can quickly disable people.16:07
nowenFor example, with NPS, you can have a policy that says 'if it comes from WebAccess IP, make sure it is in Group X and if it does, send the creds to WiKID too'16:08
Elmar_yes, need to setup the NPS, too, just for the wireless clients.16:11
nowensadly, MS has made it a bit more complex that how I describe it16:12
Elmar_thanks, will keep this in mind.16:13
nowenand while you will most likely need MS docs, we have an overview eguide here: http://www.wikidsystems.com/learn-more/white-papers16:14
nowenand we have docs for openvpn community and AS16:14
Elmar_maybe I could start with an easier thing, apache authentication for reverse proxy against one AD?16:15
nowenwell, you are right - start simple.16:17
nowenmaybe:  1.  test a network client to wikid radius auth.16:17
nowen2.  test network client to NPS auth using AD creds16:17
nowen3.  test Network client to NPS to WiKID16:17
Elmar_yes, will start with small steps ;-)16:19
Elmar_thanks for all the hints, will leave now :-)16:21
nowenlater!16:21
Elmar_cu!16:21
*** Elmar_ has quit (Quit: Page closed)16:22
*** nowen has quit (Quit: Leaving.)22:53

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!