Thursday, 2014-04-03

*** WiKIDLogBot (~WiKIDLogB@ec2-174-129-6-100.compute-1.amazonaws.com) has joined #wikid17:36
barjavel.freenode.netTopic for #wikid is: two-factor authentication.  If no one is here, you can try the forums: http://www.wikidsystems.com/support/support/wikid-forums.  Please lurk around - your question may not be answer immediately. This channel is logged:  http://www.wikidsystems.com/webdemo/irclogs/index.html.17:36
barjavel.freenode.netUsers on #wikid: WiKIDLogBot @nowen TXRH-Richard coolacid Qasker joevano17:36
TXRH-RichardNick I keep getting "The wClient connection to the server was NOT successfully established"19:01
TXRH-Richardis a firewall issue?19:01
*** TXRH-Richard has quit (Quit: Page closed)19:03
*** TXRH-Richard (d8f800fe@gateway/web/freenode/ip.216.248.0.254) has joined #wikid19:03
TXRH-RichardNick, I keep getting "The wClient connection to the server was NOT successfully established" is this a firewall issue?19:04
nowenTXRH-Richard: did you edit the example.jsp page?19:05
nowenwas it working before and stopped?19:05
TXRH-Richardwell I the AD register page was working but hasn't in a while19:06
nowenI bet its your localhost cert19:06
TXRH-RichardI have been manually adding users in the web interface19:06
nowenRun the command here on your localhost http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid?searchterm=keytoo19:07
TXRH-Richardbut i need to add 2 tokens for some users19:07
nowenwhat version are you running?19:07
TXRH-Richardwikid-server-enterprise-3.4.88-b126919:09
TXRH-Richardis my -storepass the same one I use to start the service?19:10
nowencould be. but localhost can have a different one.19:10
nowenhttp://www.wikidsystems.com/downloads/changelogs/enterprise-changelog some updates, including a new WiKID CA.19:10
nowenalso: http://www.wikidsystems.com/support/wikid-support-center/faq/how-can-i-restart-the-server-without-being-asked-for-the-passphrase19:11
TXRH-Richard-bash: !fxg: event not found19:12
TXRH-Richardis the result of keytool19:12
nowenhmm19:12
nowenmaybe a typo?19:12
nowentry running the other one19:13
TXRH-Richardsame thing if I type another password I get a java error19:15
TXRH-Richardshould I upgrade?19:15
TXRH-RichardI just want to be able to register 2 tokens to 1 user19:15
nowenrun 'ls -all /opt/WiKID/private/'  and see if they are both there19:16
nowenbut, yet, I say upgrade and create new certs19:16
nowenI can get you the rpm links19:16
TXRH-Richardok the certs are there19:17
nowenwhat are the dates on them?19:18
TXRH-Richardif I upgrade will I have to re-register users19:18
TXRH-Richardsep 11 2012 and sep 12 201219:18
nowenhmm, do you guys buy a three year license?19:21
TXRH-Richardyes 25 seat - 3 years19:22
nowenodd, I can't find it. oh well19:23
nowenhere's the links19:23
nowenwhat we'll do is upgrade the RPMs, restart wikid, create new certs and restart again19:23
TXRH-RichardE=RIchard.Fox@texasroadhouse.com,C=US,ST=KY,L=Louisville,O=Texas Roadhouse,OU=IT,CN=trdualauth.texasroadhouse.local19:24
nowenone thing - the localhost passphrase you used should be in ADRegister.jsp19:24
nowenahh = thanks19:24
nowenYou many want to copy your ADRegister.jsp in case it gets over-written19:25
nowenwhich it surely will19:25
nowenIt should be in /opt/WIKID/tomcat/webapps/wikid19:25
TXRH-Richardok19:27
nowendo you need any help copying it or tar'ing it up?19:32
TXRH-RichardI made a copy of the file and also have info in notepad19:33
nowenok19:33
nowenis this our ISO?  I need to know if it is 32 bit or 6419:33
TXRH-Richardbtw I used the that password in the keytool and get a java.io.IOException19:34
nowenthat's odd. it should just show an expired cert19:34
nowenbut anyway a new cert should fix it19:34
TXRH-RichardIt's a VM on esx I think I built it from the iso19:35
nowenhttp://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1542-1.noarch.rpm19:35
TXRH-Richardhow can I tell if it is x6419:35
nowen'uname -a'19:35
nowenhttp://wikidsystems-dl.com/wikid-utilities-3.4.3-1.i386.rpm19:36
nowenthe iso is 32 bit19:36
TXRH-RichardLinux trdualauth.texasroadhouse.local 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 EDT 2010 i686 i686 i386 GNU/Linux19:36
nowenyeah, those two rpms19:36
nowenyou can download them on the server by running 'wget http://wikids....19:36
TXRH-Richardok working on it now19:37
TXRH-Richardok done19:37
nowenok note that this will stop the server.19:38
nowenrun 'rpm -Uvh wikid-*'19:38
nowenthat will stop wikid and do the upgrade19:39
nowenwhen finished, run 'wikidctl start'19:39
TXRH-Richardok starting19:40
nowenok - then go to the WiKIDAdmin Configuration and create a new intermediate CA and a new localhost and then copy your ADRegister back and then 'wikidctl restart'19:42
nowendid you get the cert back in the pop-up ok?19:49
TXRH-Richardyes restarting now19:50
TXRH-Richardok it is back up19:53
nowenok - browse to the ADReg page and cross your fingers19:54
TXRH-Richardok well I get Authentication to the directory failed for "myuser"19:54
nowenok - so it sounds like the AD connection is working19:55
TXRH-Richardseem to always have to stop iptables19:55
nowenoh19:55
nowenI have a solution for that.  Create a network client using radius using the IP Address of your AD server.19:56
nowenit will open a hole for that IP.19:56
TXRH-RichardI do have that19:57
nowenhuh19:57
TXRH-RichardI just did iptables stop and it is working now19:57
nowenyou can run 'iptables -L -n' to see if that IP is listed19:57
TXRH-RichardChain INPUT (policy ACCEPT) target     prot opt source               destination  Chain FORWARD (policy ACCEPT) target     prot opt source               destination  Chain OUTPUT (policy ACCEPT) target     prot opt source               destination19:58
TXRH-Richardlooks like nothing19:58
nowendid you restart iptables?19:58
TXRH-Richardoh ok19:58
TXRH-RichardChain INPUT (policy DROP) target     prot opt source               destination ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTAB                                     LISHED ACCEPT     all  --  127.0.0.1            0.0.0.0/0           state NEW ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           multiport dports 22                                     ,443,80,49 state NEW DROP       all  --  019:59
nowenhmm19:59
TXRH-Richardnot sure if that is readable but it looks like all 0.0.0.0/020:00
nowentry:  'iptables -I INPUT -p tcp -s 10.1.1.2 --dport 389 -j ACCEPT'20:00
nowenchanging the IP for your ad server20:00
TXRH-Richardok seems to be working20:02
noweno20:02
nowenok20:02
nowennow do 'iptables-save /etc/sysconfig/iptables' and it should stick after a restart20:02
nowendo you want to setup wikid to start automatically?20:03
TXRH-RichardI get unknown argument found on commandline20:04
TXRH-Richardyes, and Can I use the AD page to register a 2nd token if the user already has one?  or should I use the example20:08
TXRH-RichardI have a security file the first line is WIKID_USER20:10
nowenIIRC, the AD reg page should send you to a 2nd page to reg another20:10
nowenyeah20:10
nowenadd a 2nd line20:10
nowenwith 'WAUTH_PASSPHRASE='yourpassphrase'20:10
nowenthen:  cp /opt/WiKID/conf/templates/wikid /etc/init.d/wikid20:11
nowen chmod +x /etc/init.d/wikid 20:11
nowenchkconfig wikid on20:11
TXRH-Richardok I fixed that it restart without prompting now20:13
TXRH-Richardok the AD page let you register 2 if you don't already have a token is there a way with out deleting the first and doing both at the same time20:22
nowenyou would have to edit the page20:22
nowenit's a different function20:23
nowenyou can use example.jsp20:23
TXRH-Richardok I am not much of a programmer, I see the Add additional device do I copy that into another file and save as .jsp20:26
nowenme neither ;-)20:27
nowendo you want to edit the AD page?20:27
TXRH-Richardyes that works20:28
nowenif you go straight to ADRegister2.jsp it might do it20:29
TXRH-Richardok editing that page now20:31
TXRH-Richardthat works! Awesome20:37
TXRH-RichardI have another issue if you have time, we have 2 internet connections and use a dns device to fail over if one goes down20:39
nowenok20:40
nowenso, when that happens, users can't get to the WiKID server?20:41
nowenwe can create a DNS entry in wikidsystems.net and point it to your DNS20:44
*** nowen has quit (Read error: Connection reset by peer)20:47
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid21:05
nowenhmm, didn't notice I was gone21:05
nowenTXRH-Richard: I have to go - taking my daughter to the airport for a 3 month exchange.21:16
*** nowen has quit (Quit: Leaving.)21:19
*** TXRH-Richard has quit (Ping timeout: 245 seconds)21:24

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!