Thursday, 2014-01-23

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid13:14
estrangerPOC is going well, everything works (Watchguard SSL VPN + AD/NPS + WiKID).  I just want to put a signed cert in for the https site for the ADRegister.  Easy to swap out in a keystore? or easier to slap a proxy in front?14:27
nowenthe keystore is /opt/WiKID/conf/tomcatKeystore14:29
nowenbut a proxy would work too14:30
estrangeris that just for the https? I didnt want to just start messing w/ that file14:30
nowenit is just for the https of tomcat14:30
estrangerperfect14:30
nowennot related to the intermediate or localhost cert14:31
estrangerok, yeah, that was my only concern. thanks14:31
nowenand just so you know, those are also separate from the domain/token keys14:33
estrangeryeah the last thing I wanted to do was start messing with the internal trust stuff going on in the background.. thats why I was considering the proxy :)14:35
estrangerthe other question I had, licensing.. each seat is a device? so if one user has a iphone and the local java app registered, that is two seats.14:47
noweneach unique username in a domain is a seat, so 2 tokens, 1 username = 1 seat14:48
nowenquestion: if we added the ability to reset an AD password via a token, would it be of interest?14:48
estrangerExcellent on the licensing!  And yeah, I would be interested in that I'd say14:51
nowencurrent thinking is that it would set the OTP as the password and flag it to be reset14:52
estrangerwonder if it can solve an issue we have, users don't change their password and end up being locked out via expired password, then have to call us14:54
nowenthat's what were trying to fix14:55
estrangerhuge interest then :)14:56
nowenthose calls are quite expensive and as you know, annoying ;-)14:56
estrangerexactly :)14:57
*** Mike (1827fd3e@gateway/web/freenode/ip.24.39.253.62) has joined #wikid16:16
*** Mike is now known as Guest7199116:17
Guest71991guess i get a new nickname, oh well16:17
Guest71991quick question if anyone has a minute16:17
Guest71991before I start installing wikid on my server for testing are there any particular ports I would need open to connect to a seperate network for wikid to work16:18
Guest71991my current server that I'm thinking of installing wikid on will be on one internal lan and the pc we want to secure will be on another internal lan16:19
*** Guest71991 has quit (Quit: Page closed)16:35
nowenoops, stepped away for a bit16:38
nowenpeople need a bit more patience on irc ;-)16:38
*** WiKIDLogBot (~WiKIDLogB@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid18:20
card.freenode.netTopic for #wikid is:  The topic for #wikid is: wikid WiKID's IRC support channel.  Logs are here: http://www.wikidsystems.com/webdemo/irclogs/index.html.  If no one is here use the forums: http://www.wikidsystems.com/support/support/wikid-forums.18:20
card.freenode.netUsers on #wikid: WiKIDLogBot coolacid @nowen estranger qu3sti0n Teck7 joevano18:20
*** merlin_ (1827fd3e@gateway/web/freenode/ip.24.39.253.62) has joined #wikid18:30
merlin_hey all18:30
nowenhi merlin_18:30
merlin_Hi nowen, I'm having an issue, I think with an existing apache website on my server that I'm trying to install wikid on18:31
merlin_is there a way to change what ports wikid listens for?18:31
nowenyeah, that will be harder18:31
nowenyou really need apache on the same server?18:31
merlin_its on the same server, but I'm using scrollout f1 for spam and I can't seem to get to WikidAdmin18:32
merlin_the scrollout f1 login always comes up instead18:32
nowennot sure what that is18:32
merlin_no problem, I'll try removing wikid and install on a different machine18:32
nowenthat's best b/c a flaw in your web app could give an attacker control of your auth server18:33
nowenseparation of duties, FTW18:33
merlin_true18:33
merlin_X235bZ4aCL18:33
nowenoops ;-)18:33
merlin_oops18:33
nowenbeen there, done that18:34
merlin_now only need to search a billion places to see what that goes to18:34
merlin_thanks for your help, I'll be off to build a test machine for just wikid now18:35
nowenok.18:35
merlin_oh, and change a password18:35
nowenI'll be around until about 4ish today. leaving early18:36
*** merlin_ has quit (Quit: Page closed)18:36
*** WiKIDLogBot (~WiKIDLogB@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid18:53
card.freenode.netTopic for #wikid is:  The topic for #wikid is: wikid WiKID's IRC support channel.  Logs are here: http://www.wikidsystems.com/webdemo/irclogs/index.html.  If no one is here use the forums: http://www.wikidsystems.com/support/support/wikid-forums.18:53
card.freenode.netUsers on #wikid: WiKIDLogBot coolacid @nowen estranger qu3sti0n Teck7 joevano18:53
*** nowen has quit (Quit: Leaving.)20:33

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!