Wednesday, 2014-01-29

*** nowen has quit (Quit: Leaving.)14:35
*** immotus (~immotus@rrcs-24-153-193-34.sw.biz.rr.com) has joined #wikid17:23
immotusI have an unusual question... A PCI audit scan has indicated to us that our WiKID 3.4 server has a password field on the login screen form that doesn't tell the browser to never remember what password was entered.  What would be the best way for me to add the autocomplete="off" HTML attribute to the password field without upgrading?  (the last upgrade didn't turn out so well)17:26
joevanoimmotus: nowen isn't here at the momont. My guess is that he is stuck at home or between work and home due to the storm in the southern US.19:11
joevanos/momont/moment/19:12
immotusquite a storm, I hear20:35
immotusjoevano: thanks for the update20:35
immotusjoevano: I hope he gets back safely.. for his own sake :^)20:35
*** dystonicka (c631b428@gateway/web/freenode/ip.198.49.180.40) has joined #wikid22:03
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid22:04
dystonickahi stranger22:04
nowensorry, sledding22:04
dystonickanp.  when is better?22:06
joevanonowen: in your car? ;-)22:06
nowenlol.  no, i grew up in Va and know how to drive in snow. around here it's mainly avoid the idiots.22:07
nowendystonicka: now is fine.22:07
nowenI don't understand how anyone was surprised by this.  Been on my weather app for a week22:07
dystonickai am cuonfused by this snow thing22:08
dystonickabut i have not left the house yet today, so.22:08
dystonickachecking my window.22:08
nowenha!  I worked from how yesterday, but did have to go get the kids at school.22:08
dystonickayeah, we aren't impacted.22:08
dystonickai'm discovering the joys and pitfalls of wfh.  like the cat has opinions.  as does the dog.22:09
dystonickaso.  yes.  omgmigration.22:09
*** immotus has parted #wikid ("Konversation terminated!")22:10
dystonickacan i have two wikid servers permitting authentication?  like.  can radius handle that?22:10
joevanoI was snowed in for the 4 days in Indiana (over the past week)... 3 foot drifts on the roads22:10
dystonickablink.  that is a lot of snow.22:10
joevanoyep, it sucked22:11
joevanowe've had 78" so far this year22:11
dystonickawhere are you?22:12
nowenmore than us22:12
nowendystonicka: a radius server can handle that.  what is your network client again?22:13
dystonickanetwork client?22:13
dystonickanot sure what you're referencing.  is windows implementation22:14
dystonickaoff the domain controllers22:14
nowenfrom WiKID's perspective your  VPN  or whatever is a client22:14
nowenis it some remote access software?22:15
dystonickawikid server version is - wikid-server-enterprise-3.5.0-b134222:15
dystonickawikid is used to authenticate to openvpn and to some linux boxes that take wikid tokencodes22:15
nowenok22:15
nowenand each one of those is listed as a network client?22:15
nowenon the WiKID server22:15
dystonickathere are four network clients listed22:19
dystonickatwo domain cntrollers22:19
dystonickaand two vpn servers, which operate in failover.22:19
nowenrunning some quick tests22:24
dystonickakk.22:24
dystonickaafk a few, nuking noms22:26
nowenso, the problem with your current set up is that you can't have two network clients with the same IP address associated with different domains22:28
nowenso, option 1:  stay where you are and re-register the iphone clients that have issues.22:34
dystonickait's iphone, android, we had a windows client reported22:35
dystonickawhat's option2 2?22:35
nowenoption 2:  give all your network clients 2 ips and associate the new ips with the new domain22:35
dystonickafor the vpn that's not a problem22:36
dystonicka'new domain' - splain in context the domain concept22:36
dystonickacus im thinking active directory22:36
nowennew wikid domain22:36
dystonickacan you have more than one domain on w wikid box?22:38
nowencertainly22:38
joevanodystonicka: South Bend, IN22:38
dystonickawould it still authenticate against the same network clients?22:39
nowenalso, it is likely that some if not all of your android and PC issues were due to dns propagation issues22:39
nowenno, that's what you cause confusion22:39
nowenoption 3 is to re-register all the tokens22:39
dystonickayeah.  which is a admin hell.  i'd been thinking about making them switch to locked or phone22:40
dystonickabut i don't want to deal w/ it now.22:40
dystonickadunno what it would take to give the machine alternate ways to talk to the auth sources.  like.  an aditional ip, beause then we could just transition folks.22:41
dystonickagive them 2-3 weeks instead of all at once.22:41
dystonickathe dns thing is a point.  i haven't gotten yelled at today yet.22:41
nowenhow many issues have you had?22:41
dystonicka522:42
nowenout of how many users?22:42
dystonicka100ish.22:42
dystonickathat's a lot of work.22:43
nowendo you think you crossed a line today re the DNS?22:43
dystonickai don't.   i'm also a bit uncomfortable leaving it out there just as a dns redirect - but you mentioned you're working on a upgrade that would allow dns?22:43
dystonickafor the servername?22:43
nowenyes, it's an entirely new product line.22:44
nowenIt would also have global load-balancing and fail-over22:44
dystonickathat's really cool.22:44
dystonickai hate to ask, but you know i have to - is there a release date?22:44
nowen;-).  No, not yet.  We are still working through some kinks on the replication, testing it in various scenarios, etc.22:45
dystonickaunderstand.22:45
nowenit's important for us that things work pretty well22:45
dystonickaalright.  i'll let it bake till monday and see how it goes - this isn't going to be trivial.   its' either put new ips on the authenticatoin sources/network clients which involves some eingeering and then add a new domain22:46
dystonickaso changing 5 things and then telling people to reregister.22:46
dystonickaor delete/regen the domain and require all the tokens to be reregistered22:47
dystonickaone phased one takes time.22:47
dystonickawas there a self-registration option?22:47
nowenyeah, based on AD creds.  There's script on the server you can use.22:47
dystonickak.  i dno't code at all - how would that be used?22:48
dystonickawould it be - build webpage w/ form?22:48
nowenhttp://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-let-users-add-themselves-using-ad-credentials?searchterm=ADRegis22:48
nowenyou can just edit it22:49
nowenit might be over-written in an upgrade, but it's like example.jsp, you can just edit it22:49
nowenthat page should be internal only, of course22:50
dystonickaAbsolutely.22:50
dystonickabut it would be nice to have.22:50
dystonickaiif we were to add a new domain and a extra ip for each of the network clients22:51
dystonickaoh we just map them in the network client stuff22:51
dystonickaso add domain then map22:51
dystonickaand then set up a self reg.22:52
dystonickagah.  i'll see if things ust work first, but this helps.22:52
nowenit would be nice to get the benefits of the new server if you have to re-reg people.22:52
dystonickait would.  let me know when you're close to release.22:53
dystonickai don'tw ant to change a lot right now, because the acquisition is making everything shake up22:53
nowenwe are very close to beta22:53
* nowen crosses fingers22:54
dystonickaw00t!22:54
nowenbut i've said that for a long time22:54
dystonickai understand.  is the bane of making good software22:55
dystonickaalright.  i'll go  chew on this;  i'll check in and let you know hwo it goes22:55
nowenok22:55
dystonickabye.  "_22:55
*** dystonicka has quit (Quit: Page closed)22:55
*** nowen has quit (Quit: Leaving.)23:37

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!