Tuesday, 2014-03-11

*** coolacid has quit (Remote host closed the connection)01:43
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid01:55
*** coolacid has quit (Remote host closed the connection)02:06
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid02:12
*** coolacid has quit (Remote host closed the connection)03:02
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid03:07
*** KORG (~KORG@crytek.dream.net.ua) has joined #wikid08:43
*** KORG is now known as dkorzhevin08:44
*** dkorzhevin has quit (Quit: Leaving)13:12
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:41
*** coolacid has quit (Remote host closed the connection)14:14
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid14:28
*** coolacid has quit (Remote host closed the connection)14:33
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid14:36
*** coolacid has quit (Remote host closed the connection)14:37
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid14:42
*** mark_burger (8f74fa7d@gateway/web/freenode/ip.143.116.250.125) has joined #wikid14:53
mark_burgerGood morning14:53
mark_burgerNick are you here14:54
nowenyes14:54
nowengood morning14:54
mark_burgeri ran the report15:00
mark_burgerremoved duplicates15:00
mark_burger6417 is what wikid shows15:00
mark_burger5929 after i remove duplicates15:01
nowen6417 is from the home page?15:02
mark_burgeryes15:02
mark_burgermy steps are i go in to reports15:06
mark_burgerrun a csv report and include disabled tokens15:06
mark_burgerthen open in xls15:07
mark_burgerand remove the duplicates15:07
nowenthis is all one domain?15:08
mark_burgeryes15:09
mark_burgerwe only have the one domain in production15:09
nowenduplicates are based on username, I assume.15:09
mark_burgeryes15:09
mark_burger19427 devices15:10
mark_burgerso as you see based off of that we have loads of duplicates when eported15:10
mark_burgerexported15:10
nowendid you guys upgrade the server yet?15:14
nowenmark_burger: what is your unregdevicettl? it's under Configuration / Set Parameters15:24
mark_burgerno15:28
mark_burgerwe did not upgrade15:29
mark_burger28 unregistered15:29
*** PC_CTi (4589565b@gateway/web/freenode/ip.69.137.86.91) has joined #wikid15:33
PC_CTi'ello15:34
nowenhi PC_CTi15:35
PC_CTiI'm just here for now. i'm setting up a Radius and WiKID server this morning, and just haning out if I need a pointer or two15:36
nowenok - sounds good15:36
nowenwhat radius server?15:36
mark_burgeryou think the upgrade will fix it?15:38
nowennot sure.  I did replicate it, but now I can't. There's nothing in the upgrade that should15:38
nowenwe might be able to get some additional reports in that help us figure it out15:38
mark_burgerokay15:39
PC_CTiServer 2008R2 for Radius. Freshly installed DC + NPS15:39
nowenPC_CTi: I assume you're using the enterprise version15:40
PC_CTiI downloaded the ISO and installed it15:41
nowenmark_burger: if we had a report that listed unique users and their tokens would that help?15:42
PC_CTiClient plans on purchasing, I'm just doing the inital setup15:42
nowenok15:42
PC_CTiWhen they purchase I assume we just swap the Certificate with a permanent one?15:49
PC_CTinowen: how long does it take to get Certificate requests usually?15:54
PC_CTican I move onto setting up the local certificate without installing the cert from you guys (least until I get it)15:54
nowenPC_CTi: they should be returned in the same pop-up15:55
PC_CTihrm, IE11 strikes again15:55
nowenI'll email it15:55
PC_CTigot it thanks16:00
PC_CTiCan you restart the wikid services from the web admin, or is console the only way16:03
nowenconsole is the only way16:03
PC_CTiwhen setting up the Network Client, its asking for an IP Address. your demo video with bank.com is using a public IP. what IP do I put here?16:11
nowenuse an internal IP16:11
PC_CTifor the WikID server?16:12
PC_CTithis is for authenticating firwall users (watchguard) for vpn.16:12
nowenno, the network client would be your VPN or whatever device ..16:12
PC_CTikk so the firwall16:12
nowenyeah ,the watchguard ip16:12
PC_CTiokay so I'm confused now.16:14
PC_CTiI've setup Radius on the 2008R2 box, and created the shared key for it16:14
PC_CTiwhen do I enter that key?16:14
nowenoh soory16:14
nowenthe NPS is your network client16:14
PC_CTiahh okay16:15
nowenit should go watchguard >> NPS >> WiKID16:15
mark_burgerYes Nick that would help so that duplicates did not have to be removed16:15
nowenmark_burger: ok16:16
PC_CTinick, what values should be returned to auth with a Watchguard?16:17
nowenPC_CTi: I would not use return attributes unless you know what you're doing.16:18
PC_CTikk. I dont :D16:18
PC_CTiwell I do, but not to that extent yet16:18
nowenI can't really help on them16:19
PC_CTiwell I'm not to that point yet either way.16:22
nowenalways best to start simple16:23
PC_CTiso I've setup Radius, and there are no users yet, how should I start to test it?16:23
PC_CTiI assume I can't try from my android device16:23
PC_CTisince I used the 12 digit IP 0 padded16:24
nowenwell, you can run 'tcpdump -vv port radius' and see if the auths even get to the server16:24
nowenyou used an internal ip?16:24
PC_CTishould I use the publicly available?16:24
nowenif you want users from the outside to get otps16:25
PC_CTilet me back up a bit16:25
nowenyou can NAT the server, but the external IP should be used for the domain id16:25
PC_CTiwhat do I need to NAT for it16:26
PC_CTiright now, its a VM, single Nic on the internal network16:26
nowenok - so the tokens talk to the WiKID server.  PINs go in (encrypted) and OTPs get returned.16:26
PC_CTiah, I would have thought your server would sort of be man in the middle.16:27
PC_CTitokens to your server, to internal server16:28
nowenno, no, we don't want that responsibility!  ;-)16:28
PC_CTiwell for licensing purposes16:28
PC_CTianyways. So what is the recommended configuration16:28
PC_CTiwhat do I need to NAT from the public IP to the wikid server16:29
nowenok16:29
PC_CTiprefer to not do a blanket 1-to-116:29
nowenso, your tokens will contact your server.  over port 80 (since we use asymmetric encryption).  You want an externally routable IP address for the server16:30
nowenso16:30
nowenyou're firewall would route those packets to your internal IP.16:30
PC_CTiso just port 80 needs to talk to wikid16:30
nowenyea16:30
PC_CTiallright16:31
nowen443 is the admin, so you want it locked to the inside16:31
nowensame with radius16:31
PC_CTiand configure the Domain with the padded 0s public IP16:31
nowenyeah, exactly16:33
nowenok - I gotta run for a lunch meeting.  bbib16:47
*** nowen has quit (Quit: Leaving.)16:48
*** PC_CTi has quit (Ping timeout: 245 seconds)17:33
*** mark_burger has quit (Ping timeout: 245 seconds)18:12
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid18:43
*** evfenij (~evfenij@195.78.108.76) has joined #wikid19:16
*** evfenij has quit (Remote host closed the connection)19:24
*** mark___ (8f74fa7d@gateway/web/freenode/ip.143.116.250.125) has joined #wikid19:35
mark___Hey Nick you back?19:35
mark___by the way we have it set up I am showing 5842 licenses being used19:36
mark___which after i scrub the duplicates seems to align19:37
mark___however i do have a question19:37
mark___we have some employees when they registered used lower case one time and upper case another time19:37
mark___even though it is the same user would your main dashboard interpret that as two users?19:38
nowenhi19:51
nowenhmm19:51
nowenwhat did you do to change the licenses in use? clear out some dead ones?19:52
nowenmark___: ?19:55
mark___sorry20:01
mark___i am here20:01
nowenNP20:01
mark___yes the licenses in use did go down some as we had some inactive accounts i removed20:01
nowenI was on the phone with amex discussing my wife's supposed charges to maturesingles.com20:02
nowenI think you are right about the caps20:02
nowenwe used to be cap-sensitive, but changed it - was it for you'll?20:07
nowenmark___: could be tough - on AD they would be the same user, but not on linux20:15
nowenmark___: is there a way you can you count the dupes due to caps?20:16
*** dystie (c631b428@gateway/web/freenode/ip.198.49.180.40) has joined #wikid20:17
mark___maybe20:18
dystiehey.20:18
mark___and yes we had to do some changes on our registration side to make it work20:18
dystienick, i am having a bad wikid day.20:19
dystiei can't get the phone client to let me enter my passphrase, so i'm blocked out of production20:19
nowendystie: what's going on?20:19
nowenwhat? how is that?20:20
dystieand my nonprod instance you gave me the dns redirect for is timing out on requests, so i have people who can't get into servers that use wikid.20:20
dystiestarting with phone.  lemmie see if i  can get a screenshot20:20
nowenlet's start with the first.20:20
dystieiphone client.20:20
nowenmine's working20:27
dystieyeah.  see screenshots.20:27
dystieme = locked out of production w/ no one to reset the tokens till tomorrow.20:27
dystieeveryone is in australia or poland.20:27
dystierebooting phone20:27
dystiek.  rebooted and the text moved around and i can now log in20:30
dystiesending you a screenshot so you can log this as a known issue.20:31
nowenok20:31
dystienext.20:31
nowenok20:31
nowencan you also set up another token somewhere else?20:31
dystiei'd have to use the api, right20:31
dystie?20:31
nowenyes20:31
dystiei can't do that through the gui.20:31
nowenexample.jsp would do it20:31
dystiei think we've covered that I don't code.20:31
nowencan you edit in vi? or whatever?20:32
dystiei can edit files, yes.20:32
dystieif you walk me through it.20:32
nowenhttp://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-test-if-the-server-is-working-correctly20:32
dystie(not the editing, what i'd need to do.)20:32
nowenjust follow that doc20:32
nowenall you need to do is change the domain identifier and the loclhost passphrase20:32
*** PC_CTi (4589565b@gateway/web/freenode/ip.69.137.86.91) has joined #wikid20:33
dystiek.  let's come back to that, because the other issue is more urgent.20:33
dystiefor our nonproduction (call it dc1) wikid, we had a ip change, and worked w/ you to put in a dns rule to redirect to the new ip address.20:34
dystiethe problem is that w/ the redirect timeouts happen.20:34
nowenwhat's the new ip?20:34
nowenI have a 135.39 address20:34
dystieand today it is especially bad;  i can't register a token, people who use wikid to sudo on linux systems can't, etc20:35
dystieso it has to be fixed.20:35
nowendoesn't look like it is dns20:35
nowenI can get to it fine20:35
nowenhttps://199255083008.wikidsystems.net/WiKIDAdmin20:35
dystieit is however not letting me register a token.20:35
dystieso that is not so cool.20:35
dystieso if not dns, the redirect timeouts from the old domain, to you, to our new ip.20:36
nowenhmm I just registered 4b4w3ASR20:36
dystiecould not obtain configuration for:  old.20:36
dystieonesec20:36
dystiek.  so i have corp vpn, which backhauls to california and back to the server in dc120:37
dystieso that explains some of the latency, but we still have people who can't work.20:38
nowenwhat happens when you go to http://199255083008.wikidsystems.net/wikid/servlet/com.wikidsystems.server.InitDevice4AES?a=0&S=199255083008&CT=120:38
dystiemessage HTTP method GET is not supported by this URLmessage HTTP method GET is not supported by this URL20:38
dystienot on vpn, that.20:38
nowenthat the WiKID server responded20:38
nowen'ding20:38
nowensounds like you have routing issue on your vpn20:38
dystieif i were to take one of the dc's it's talking to20:40
dystieso it only has one dc, instead of two dcs.20:40
dystieand create a new domain.20:40
dystiewhat would be the impact?20:41
dystie[3/11/14 4:39:36 PM] Sarah Clarke: where are you connecting to dc1 from? [3/11/14 4:39:53 PM] Sarah Clarke: office hard connection, corp vpn, ? [3/11/14 4:40:46 PM] khusbu chhadwa: office [3/11/14 4:41:19 PM] Sarah Clarke: plugged into a wire at your desk? [3/11/14 4:41:33 PM] khusbu chhadwa: plugged in20:41
dystiethat's the pro services lady who reported it;  the hardwire is corp network, so it's latency i can't get around.20:42
nowenI don't understand.  what is a dc?20:44
dystiedomain controller20:45
nowenok20:45
dystieright now the dc1 domain is talking to both dc1 domain controllers20:45
dystieif i were to disassociate one of the domain controllers and point it at a dc1-new domain (for examples)20:46
dystiewould i then have two useable domains20:46
dystieand what would be the risks/benefits?20:46
dystiei want to transition people to a domain that doesn't require the dns redirect, because we have been experiencing problems we hadn't seen before since we had to put it in.20:46
dystiethe other issue would be the vpn servers, and i can't cut those over because they're in HA / not standalone.20:47
dystiebut if i can transition people to the new domain for wikid, then i know which problem kids are still using that vpn,and can take it away from them.20:47
nowenI'm not sure what's causing the issue20:48
nowenit seems to be a routing issue on your end, right?20:48
nowenif so, then, there must be a better way to solve it, right?20:48
nowenif it is a dns issue, can you create a DNS entry in your own dns servers?20:48
dystiecall me?20:49
nowenI cannot - I have 4 chat windows up20:50
dystiek.  i want to show you, so ping me when you're avail.20:50
dystiei have gotomeeting.20:50
nowenagain, can you tell this is not an issue with your networking?20:50
dystiethinking through how to test that.20:54
nowenIDK, with some kind of networking tools?  ;-)20:54
dystiei just moved the user to a phone based token.20:54
dystie[3/11/14 4:49:26 PM] Sarah Clarke: token is associated. [3/11/14 4:49:31 PM] Sarah Clarke: please test and make sure you can get into csdev and sudo [3/11/14 4:50:31 PM] khusbu chhadwa: does not work [3/11/14 4:53:23 PM] Sarah Clarke: is your phone on office wireless? [3/11/14 4:53:56 PM] khusbu chhadwa: nope20:54
nowenok - so you're saying that you have a user that cannot get an OTP?20:54
nowenI didn't get that20:55
nowenwhat does "does not work" mean?20:55
nowendoes the token not work?20:56
dystieshe could get a code but it wouldn't work for auth20:57
nowenok20:57
nowenthat's more useful info20:57
dystiei just tried to add the domain to my iphone - got a unable to add domain to token20:57
nowenwhich issue do you want to focus on?20:57
*** PC_CTi has quit (Ping timeout: 245 seconds)20:58
nowenon your phone - try pre-pending the domain with an asterisk20:58
dystiethe issue as i understand it is that people can't auth via wikid to systems that use wikid.20:58
noweni see two issues - you can register and someone authentication is failing.20:58
nowenis that someone's authentication request getting rejected by the wikid server?20:59
nowenis that user enabled on the wikid server?20:59
nowenis the authentication request even getting to the WiKID server?20:59
dystiechecking logs21:00
nowenyou can also run 'tcpdump -vv port radius' to see if the requests are getting to wikid.  I'm assuming radius21:15
*** PC_CTi (32f1ca0a@gateway/web/freenode/ip.50.241.202.10) has joined #wikid21:21
PC_CTinowen: Trying to delete a user, but it is not showing up in the list21:21
PC_CTiwas a user I manualy validated, but haven't actually used21:21
nowenand you're saying it's no longer showing up on the user tab?  did you ctrl-shift reload?21:21
PC_CTihas never shown up on the users tab21:21
nowentell me how you registered them?21:22
PC_CTiwhen I try to delete the Domain, it shows 1 user, gota delete first21:22
PC_CTiused android token, which worked, and clicked the manually validate user21:22
nowenhuh, so no users showing but you can't delete the domain?  is there an outstanding reg code?21:23
*** mustafa (~mustafa@91.213.72.152) has joined #wikid21:23
PC_CTino21:23
PC_CTiI checked back, and there is none21:23
PC_CTiI only tried once21:23
PC_CTiI'm changing the public IP21:23
PC_CTiwhich is why I'm doing this21:23
nowenhmm, well you don't have to delete the domain, but you should be able it. I just did this yesterday21:23
*** mustafa has quit (Remote host closed the connection)21:24
*** effekt (~effekt@91.217.162.251) has joined #wikid21:35
*** effekt has quit (Remote host closed the connection)21:36
PC_CTimkay21:36
PC_CTiso I created a new one21:36
PC_CTiwhen I look under Manualy Validate21:36
PC_CTiI see the reg code that matched the tolken21:36
PC_CTihowever the21:36
PC_CTiEmbededID is blank21:36
PC_CTiis that normal?21:36
nowenhold on21:40
nowenyes.21:41
*** coolacid has quit (*.net *.split)21:43
*** Qasker has quit (*.net *.split)21:43
*** nowen has quit (*.net *.split)21:49
*** joevano has quit (*.net *.split)21:51
*** PC_CTi has quit (*.net *.split)21:52
*** dystie has quit (*.net *.split)21:52
*** mark___ has quit (*.net *.split)21:52

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!