Wednesday, 2014-01-15

*** KORG has quit (Read error: Connection reset by peer)03:47
*** KORG (~kvirc@crytek.dream.net.ua) has joined #wikid03:47
*** KORG has quit (Read error: Connection reset by peer)09:25
*** KORG (~kvirc@crytek.dream.net.ua) has joined #wikid09:25
*** KORG has quit (Read error: Connection reset by peer)09:45
*** KORG (~kvirc@crytek.dream.net.ua) has joined #wikid09:45
*** KORG has quit (Read error: Connection reset by peer)09:46
*** KORG (~kvirc@crytek.dream.net.ua) has joined #wikid09:46
*** KORG|2 (~kvirc@crytek.dream.net.ua) has joined #wikid12:09
*** KORG has quit (Read error: Connection reset by peer)12:09
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:58
*** Mark____ (44babf6d@gateway/web/freenode/ip.68.186.191.109) has joined #wikid14:10
Mark____Good morning14:10
Mark____Nick are you here?14:10
nowenmorning14:10
nowenyes14:10
Mark____got a question14:12
nowenok14:12
Mark____we have some users that we are trying to put on 2FA14:12
Mark____However, when they are in the plant they have to set up there proxy settings in the client14:12
Mark____to make it work14:12
Mark____but when they go home they then have to remove those settings14:12
Mark____any suggestions on how we can work around this?14:13
nowenhmm14:13
nowendo their laptops automatically detect the proxy for their browsers?14:14
nowenmaybe we could auto-detect too14:14
Mark____It seems that the 2FA application is unable to fully detect the IE proxy settings automatically, but if user manually enters proxy in application it works.14:15
Mark____they have their browsers set to auto detect14:15
nowenok - let me see what we can do to auto-detect14:15
Mark____and they even entered the 2FA site as an exception under their settings but still did not work14:15
nowenhmm14:16
Mark____it is a company we bought so not truly on our network yet14:16
nowenok14:16
Mark____but if you could get 2FA to auto detect that might be the best solution14:16
nowenyeah. let me get some feedback14:16
Mark____okay thanks14:18
*** estranger (~russ@209.183.177.118) has joined #wikid15:01
nowenhi estranger15:08
estrangerhey :) just trying out wikid figured I'd join the channel while I start my journey15:09
nowengood idea ;-)15:09
estrangerthink I'm going to need enterprise if I am understanding right, I want to hook in 2factor with our watchguard vpn which auths using Radius15:14
nowenyes, we use  a 3rd party lib for radius that we can't release as open source15:15
nowenyou can download it here http://www.wikidsystems.com/downloads/how-to-test-and-get-wikid15:16
estrangeryup, no problem, still a heck of a lot cheaper than tokens :)15:16
estrangeryeah i got the iso, about to fire it up on vcenter15:16
nowenthe smart phone tokens also use commercial libs for encryption15:16
estrangertrying to fire it up at least, if people would stop bugging me at work :)15:17
nowen;-)15:18
estrangerI miss a step on the ISO? tomcat blows up starting with:  org.postgresql.util.PSQLException: FATAL: role "tomcat" does not exist15:57
nowendid you run 'wikidctl setup'?15:58
estrangeryup.. that stepped through everything, built the cert.. I didnt config sit0, just eth0, is the only thing I could think of?15:58
nowenhmm15:59
nowenthat should be it15:59
estrangerIt's a fresh setup, ill just blow it out, try again... if it does the same thing I'll install with packages like I did with the CE earlier16:00
nowenare you logged in as root?16:00
estrangeryup16:01
estrangeroh.. not sure if this is messing up something weird, I still have my VM set to "Debian 5" not "CentOS 5".  Let me fix that and reinstall before going down this rabbit hole16:02
nowenok16:02
estrangersame deal.. did I maybe grab the wrong iso version?  wikid-enterprise-3.5.0-b1472-install.iso16:17
nowenno, that should be fine16:17
nowenlet me boot it up and see16:17
nowenat the boot prompt, you just hit enter, correct?16:18
estrangercorrect16:19
estrangerboot to the disk, hit enter.. it does it's thing, login root/wikid and run wikidctl setup, plug in my network info and gen the cert.. wikidctl start .. it starts .. going to the admin page gives a 404 and i get that in the tomcat logs16:20
nowenin catalina.out?16:20
estrangercatalina.err actually .. .out was blank16:20
estrangerhttp://pastebin.com/LFwv3a1N16:21
estrangeri do see a chown error on /opt/WiKiD/log/*.pid when it does the Applying Cumulative schema updates after the setup16:25
estrangercan't cut and paste out of the damn vcenter local console where I have it16:25
estrangerI ignored it at first assuming it's just because there is no pid file.. but it IS relating to the schema so maybe it's more than that16:26
nowenworking for me.16:26
estrangerheh ok, ill just install w/ packages.. i have no idea why mine isn't16:27
nowenfor vmware, I think you need legacy ethernet and lsci scsi16:27
nowenseems unlikely16:28
estrangeryup, got those.. no biggie16:28
nowenwell, it would be better to be on centos 616:29
nowenwe use 516:29
nowendo you have a standard?16:29
estrangerwe use debian for most internal stuff, but I have no issue running centos6 on this if you say it would be best16:29
nowenmost likely, it's our standard ;-)16:30
estrangercentos6 it is, then :) 32 or 64?16:30
nowenyour call, but I would say 6416:31
nowenhow many users will you have?16:31
nowenI ask b.c you might see better performance with oracle java16:32
estrangerlike 100 users16:35
nowenok, well, your choice. that won't stress anything.16:35
estrangeryeah I don't think it will be too intensive, prob just using it for VPNing in at least at first16:36
estrangerand yeah I'll go 64, only asked because I noticed the ISO was 3216:44
estrangerfor what it's worth, centos6 + rpms installed just fine20:31
nowenstill a mystery about the iso. hmm20:33
estrangeryeah.. when I ran the setup w/ the RPMs the screen scrolled all the UPDATE/ALTER/ect for the DB, that never happened on the ISO for me20:34
estrangerfor ADRegister, I can login, but where do I get the Token Registration Code? I can register a device w/ wikidtoken.jar, but using that reg code doesn't seem to be the right thing I am looking for?21:45
nowenit should be21:45
nowendo you get an error?21:46
estrangernevermind :) ID-10T error typoing the domaincode in the jsp21:47
nowenlol21:47
estrangerworks like a charm21:47
estrangerawesome21:48
nowenI gotta run pick up my kid.21:50
nowenI'll be in again tomorrow21:50
*** nowen has quit (Quit: Leaving.)21:52
*** Mark____ has quit (Ping timeout: 272 seconds)22:41

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!