Friday, 2014-03-21

*** coolacid has quit (Read error: Connection reset by peer)02:06
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid02:07
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:57
*** bgeorge (41739342@gateway/web/freenode/ip.65.115.147.66) has joined #wikid13:44
bgeorgeGood morning.13:44
nowenmorning13:45
bgeorgeI have a bit of an problem. I updated to the newest release yesterday, and now my ADRegister.jsp isnt working. getting wClient connection errors13:46
nowenyou may need to re-edit it if it was over-written13:46
bgeorgeI made a backup, and I tried starting from scratch, no luck13:47
nowenahh - what version were you on before?  You may need to create new certs13:48
nowen3.5.0-b1428 had a new CA Cert.  the old one had expired13:49
bgeorgeYeah, I went through that process13:49
nowenhmm13:50
bgeorgeThe LDAP wauth_server code is all zeros in the GUI13:50
bgeorgeis that normal?13:50
nowenyou don't need the ldap protocol to be enabled to user ADRegister13:51
nowencan you run keytool on the localhost cert? http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid13:52
bgeorgethe second one is expired13:54
nowenlocalhost?  you can just create another one13:54
bgeorgeWhelp, that worked.13:56
nowengood to hear, sorry for the confusion13:57
bgeorgeAll good, thanks for the help13:57
*** bgeorge has quit (Quit: Page closed)13:58
*** Qasker- is now known as Qasker19:20
*** tschenk (40813d32@gateway/web/freenode/ip.64.129.61.50) has joined #wikid19:55
tschenkI have a question about Wikid and Active directory authentication19:55
tschenkI want to know if it is required to setup a RADIUS server in order to use AD as the authentication source or if you can just point to the AD host as a LDAP server19:56
nowenhold on  - on the phone ...19:57
tschenkthanks19:57
*** bang (40813d32@gateway/web/freenode/ip.64.129.61.50) has joined #wikid19:58
*** bang is now known as Guest8721719:58
nowentschenk: ldap won't proxy, only radius will.20:03
nowenIt's not a wikid thing, it's an AD/LDAP thing20:05
tschenkproxy?20:06
nowenthe radius plugin nps will do authorization in AD using the username.  then proxy the creds to wikid20:06
tschenkso basically, the answer is yes, we have to have a radius server20:07
nowenyes, but NPS is free20:08
tschenkcost in this case is immaterial...I just didn't want to have to set up RADIUS if we didn't have to20:08
nowenwell, you can have everything talk to wikid directly, without AD integration20:09
tschenkwell, here is what I'm trying to accomplish20:10
tschenkWe have an ASA VPN box20:10
tschenkwe need two factor authentication ONLY for that20:10
tschenkit can talk directly to AD without RADIUS20:10
nowenCan the ASA do authorization to AD and then proxy the request to WiKID for authentication?20:12
tschenkI'm not sure20:12
nowenit might be able to do, but i'm guessing that it would want the AD password and OTP, plus username20:12
tschenkthanks for your help....I'll continue to research this20:13
*** tschenk has quit (Quit: Page closed)20:14
*** Guest87217 has quit (Quit: Page closed)20:29
*** nowen has quit (Quit: Leaving.)21:30

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!