Monday, 2014-02-10

*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:52
*** immotus_ (~immotus@rrcs-24-153-193-34.sw.biz.rr.com) has joined #wikid17:13
immotus_I need to modify an old version of WiKID for PCI compliance (password form on login page does not have the "autocomplete='off'" attribute).  I believe i've found the file to change (/opt/WiKID/tomcat/work/Catalina/localhost/WiKIDAdmin/org/apache/jsp/protected_/login_jsp.java).. but  restartin the WiKID service doesn't pick up the change17:16
nowenimmotus_: what version are you running?17:17
immotus_nowen: don't laugh.. it's wikid-server-enterprise-3.4.1.b3314-117:17
immotus_and no, we're not ready to upgrade yet17:17
immotus_:^)17:17
nowenis your license up to date?17:17
immotus_I believe it is17:18
nowenwhat company are you with?17:18
immotus_I'm not sure how to verify, though17:18
nowenit could be cached in /opt/WiKID/tomcat/work.  stop wikid, delete that dir and see17:20
nowenhere's the changelog, btw17:21
nowenhttp://www.wikidsystems.com/downloads/changelogs/enterprise-changelog17:21
immotus_nowen: is the "work" directory automatically recreated with tomcat starts?17:22
nowenyes17:22
* immotus_ is trying it now17:24
immotus_no change :^|17:24
immotus_am I not editing the correct file?17:25
nowenoh, yeah,17:25
nowentry /opt/WiKID/tomcat/webapps/WiKIDAdmin/protected/login.jsp17:26
immotus_nowen: hey!  it worked that time :^)17:27
nowenyay!17:27
immotus_nowen: didn't even have to restart.. or escape any quote marks in the source file17:27
immotus_will I have to make that modification on every restart?17:28
nowenno, but it might get overwritten in an upgrade17:28
nowendoesn't seem like a concern ;-)17:28
nowenbut I'm surprised that version is passing pci17:28
immotus_nowen: heh.. we do want to upgrade.. we ran into a major snag the last time we tried, though.17:28
immotus_hopefully soon we'll try again17:28
nowenwhat?17:29
immotus_I don't remember all of the details right now.. someone else was doing the upgrade17:29
nowenok,17:29
immotus_they used this chat room for help, though.. and I gave a quick stab at trying to figure it out with ya'll as well.. so it's probably in the IRC logs somewhere..17:30
immotus_a problem for another day, though :^)17:30
immotus_nowen: thanks for helping me out with todays problem! :^)17:30
nowennp17:30
*** tmg_ has quit (Remote host closed the connection)17:35
immotus_nowen: I checked the changelog you sent me a link to.  I'm not sure if this particular PCI compliance issue is mentioned there.. unless it is "Enforce password complexity on WiKIDAdmin for PCI Compliance"    It is such a minor thing, though, that it probably isn't worthy of being on that changelog :^)17:41
nowenI don't think the latest version has autocomplete='off'17:42
nowenWe'll have to add it17:42
immotus_nowen: I'm actually assuming that that will be enough to cover the PCI compliance scan..  the actual concern that was raised was "Autocomplete enabled for sensitive HTML form fields"..  I don't know if "autocomplete=off" is sufficient, but I can't think of any other way... nevermind the browser can override it pretty easily :^)17:43
nowentrue17:45
nowenI've never had the autocomplete come up before17:51
immotus_nowen: neither had we.. this is the first PCI scan we've had that asked us to 'fix" it17:58
immotus_nowen: These guys pointed it out to us.. http://www.alertlogic.com/18:00
nowenhmm18:05
estrangernowen: Hey.. we're still having paypal issues. Can I just use the contact us form for that Stripe PO, or another address?19:27
nowenyes, just let me know the number of seats, proper email address19:27
estrangercool, just sent it in thanks19:29
nowenok19:30
nowensend it to your email?19:30
estrangerit's my bosses info, send it there, he's ready for it19:30
nowenok19:30
nowenon it's way!19:37
estrangerthanks! I'm sure he'll do it today or tomorrow19:38
nowenok - gotta run.  my wife had to go to a funeral and I'm doing double-duty the next couple of days.19:38
estrangerok, take care, gl19:38
nowenlater19:38
*** nowen has quit (Quit: Leaving.)19:38
*** immotus_ has quit (Quit: Konversation terminated!)22:34

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!