Friday, 2014-04-04

*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:59
*** nowen has quit (Quit: Leaving.)13:24
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:28
*** nowen has quit (Quit: Leaving.)13:34
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:54
*** nowen has quit (Ping timeout: 240 seconds)14:09
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid14:14
*** Troy (329b98a8@gateway/web/freenode/ip.50.155.152.168) has joined #wikid14:47
TroyGood morning Nick14:49
nowenmorning14:49
Troyreguarding the upgrade to latest wikid server14:49
nowenyes?14:49
Troyregarding14:50
Troyrpm -Uvh wikid-...14:50
Troythen  rpm -ivh wikid-utilities...14:50
Troyof course we will back db first14:51
nowenshouldn't that last one be -U also>?14:51
Troyyes.14:51
TroyI plan to turn off replication and setup both servers as stand alone14:52
nowendo you guys use the ADRegister or example.jsp pages?  You will want to back those up14:52
TroyI will upgrade the secondary first.. I will need to regenerate all the certificate14:52
Troyyes.. i believe last time we upgraded, the whole /opt/WiKID/tomcat/webapps/wikid was overwritten14:53
Troywhich surprised me14:53
Troydo you recall if the the webapp folders are overwritten with the rpm?14:54
Troyor when tomcat is started14:54
nowenI think that is a tomcat thing.14:54
nowenthe WAR file unzips and overwrites14:54
Troywhen upgrading, do I keep wikid service running.. then restart ?14:54
nowenrunning the rpm command will stop the server14:55
Troyok14:55
nowendid you test this in your lab?14:55
Troyi'm testing in the lab today14:55
Troyi plan to upgrade production next week if all goes well in the lab14:55
nowenok - got another rpm for you.  It includes an update to push domain changes to the PC tokens, for your name change14:56
Troyok. i have 1542 build i think14:57
Troyyes.. it's 3.5 b1542-114:57
nowenok - this one is 154514:57
nowenhttp://wikidsystems-dl.com/wikid-server-enterprise-3.5.0.b1545-1.noarch.rpm14:57
Troyok. cool.. let me know in e-mail where I can download and I'll use14:57
Troythanks14:58
nowenI think you will like this one. DB improvements, User page and log page improvements14:58
Troyso once I have the secondary upgraded.  I will then use the secondary as the master (stand alone)14:58
Troythen upgrade the old master14:59
Troyyes.. we are running a very old build.. i've been wanting to upgrade for awhile14:59
Troyonce both are upgraded, I will then setup replication again14:59
nowenok14:59
Troyi hope that will work14:59
nowenit should.15:00
Troyhttp://wikidsystems-dl.com/wikid-utilities-3.4.3-1.i386.rpm15:00
Troyis that the current utilities?15:01
nowenyes15:01
Troyok15:01
nowenis that what you have installed?15:01
Troycurrently i think we have a much older version15:06
Troybut I plan to use the 3.4.3 when upgrading15:06
nowenok15:06
nowenyeah, 1216 has the older version of tomcat.15:06
nowenthe new one has a binary file to start it. it is in the utils rpm15:06
Troyok15:09
nowenI'm thinking this one will last you for a while too.  It's a really good release, I think15:10
*** coolacid has quit (Ping timeout: 265 seconds)15:11
Troygood deal.. looking forward to the upgrade15:24
nowenbiab - lunchtime15:55
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid15:56
*** coolacid has quit (Read error: Connection reset by peer)16:08
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid16:09
nowenhey coolacid16:22
nowenhow's it going?16:22
coolacidFan died on one of my GPUs.. and for some reason my computer shut down.. twice..16:23
nowengotta lay off the mining16:47
coolacidIt's all about the defcoin now baby16:49
nowenlol16:49
nowendid you convert any bitcoins to loonies?16:50
coolacidNope.16:50
coolacidUS Dollars.16:50
noweneven better16:51
coolacidGot a Target, Childreans Place, Target and Amazon Gift cards Via Gyft.16:51
coolacidSo when wife went shopping while we were in the US, we used those for the bulk of the payments..16:51
coolacidThe Amazon gift card went to a new ipad mini ;)16:51
nowensweet16:52
coolacidyeah.. I'm a happy camper.16:52
coolacidand because I used BTC with Gyft, I ended up with 2025 Gyft points towards another card.. which turns out to be $20 free ;)16:53
nowendamn, you're really rolling in it16:53
coolacidMeh, I wouldn't say rolling..16:54
coolacidIf I hadn't of tried to day trade, it would have been 5x better off.. But, chalk it up to learning that I can't day trade ;)16:54
nowenno one can, unless you're an HFT16:54
coolacidlol.. fair enough16:58
coolacidWhen nanoseconds.. oh.. wait..16:58
*** nowen1 (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid18:09
*** nowen1 is now known as nowen_lappy18:09
*** bang (40813d32@gateway/web/freenode/ip.64.129.61.50) has joined #wikid18:34
*** bang is now known as Guest3680018:34
Guest36800Hello, guess I'll be called guest for now..18:36
Guest36800Anyways I am running into some pre-installation issues hoping to get some of my questions answered.18:37
Guest36800I am trying to setup up wikid for vpn access using AD credits.18:39
Guest36800Setting up wikid server and then NPS is complete. How would I be able to test it?18:40
nowen_lappyhi18:40
nowen_lappyhave you tried logging in?18:41
nowenI can give you a command to run on the WiKID server to see if the radius requests are reaching it18:42
Guest36800ok,18:42
nowen'tcpdump -vv port radius'18:42
*** coolacid has quit (Ping timeout: 265 seconds)18:43
Guest36800i get an output of "tcpdump: listening on eth0... "18:44
nowenok - then did you try to login?18:44
*** nowen_lappy has quit (Quit: Leaving.)18:45
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid18:45
nowendid you set up the NPS server as a network client in WiKID?18:46
Guest36800No I did not, I'll go ahead and do that now18:47
nowenok- and did you create a localhost cert and enable the radius protocol?18:48
Guest36800Yes, that I have completed.18:48
nowenok18:48
Guest36800The network client IP is that of the DC and the protocol will be Radius?18:49
nowenis nps running on the DC?18:49
Guest36800yes18:49
nowenthen yes18:49
Guest36800OK, I've just added the network client.18:50
nowenrestart wikid with 'wikidctl restart18:51
nowen'18:51
Guest36800ok, done.18:53
nowenok - try that tcpdump command and login again18:53
Guest36800thing is I am alreadly logged in the VPN now, if I run that command and exit out, I will lose connection to the server18:55
nowensome vpns allow you to test a radius login from their admin console18:55
nowenotherwise, IDK18:56
nowencan you have someone else test it?18:58
Guest36800to test the VPN i would first have to add the configuration on the cisco.19:01
nowenso, do you want another radius testing tool?19:01
Guest36800For now I want to test if the parts from wikid server to the DC is working.19:01
Guest36800I understand that the configuratiion goes from wikid > NPS > cisco19:02
nowenwell, sort of the other way19:02
nowenCisco >> NPS >> WiKID19:02
nowenI use this for radius testing: http://www.iea-software.com/products/radlogin4.cfm19:03
nowenyou need something to create the radius requests19:04
Guest36800Is there something that I can read to get a better grasp of what needs to be done? I am just going around in circles..19:09
nowenhave you seen our eGuide?19:09
Guest36800yes19:10
Guest36800Sorry it wasn't much of a help19:10
nowenok - so, here's what happens19:10
nowenthe user logs into the Cisco.  The cisco sends the AD username and OTP to NPS.19:11
nowenNPS does the authorization (does the user have the right to login) based on the username19:11
nowenif that passes, NPS sends the OTP and username to WiKID19:11
nowenIf that passes, WiKID sends an ack back to NPS say "Good".  Then NPS tells the Cisco "Good"19:12
nowenand they are logged in19:12
Guest36800aye, fairly straight forward I say. More or less it's the configurations that's bugging me..19:15
nowenwell, NPS is a pain in the but19:15
nowent19:15
nowenstart simple19:15
nowencan you get the Cisco talking radius to NPS using AD creds?19:15
Guest36800im not really that far ahead now.19:16
nowenwell, that's where I would start19:16
Guest36800I'm just cautious as to not break things...19:16
Guest36800thanks nowen.. ill be back if I need anything19:25
nowenok19:25
*** Guest36800 has parted #wikid (None)19:35
TroyHi Nick19:43
nowenHi Troy19:43
Troyupgrade in the lab secondary system went fine19:43
nowennice19:43
nowenlike the UI improvements?19:43
Troymostly.. just a few things are kinda strange19:43
nowen?19:44
Troywe have tons of devices.. so the user page is stretched out19:44
nowenhmm - can you send me a screen shot?19:44
Troybut not a big issue.. just have to scroll a bit over from the initial page19:44
Troyalso, the enable/disable (or status) is now 0 or 119:45
Troywhich is fine.. do you know if that value has changed in the db?19:45
nowenno - it was always 0 or 119:45
Troyok.. cool.. shouldn't be any issue with our re-enable scripts then19:45
nowenno - the api uses 1s and 0s.  should be the same19:46
Troyok.. sent you shot of the users page19:48
nowenthanks19:49
Troymaybe cut a line break after a certain amount of pages19:50
Troyalso, would be nice to have a ALL to show all19:50
Troyjust for sorting .. i know you can filter19:50
noweni see.  we need to cap the number of pages and add a Next or something19:51
Troyyea.. no biggie.. just cosmetic19:51
nowenI think if you tried to show all on one page, it would freeze the server19:51
nowenI'll create a ticket for it.  We'll get to it19:52
Troyyea.. that's true.. it does take a long time on the current production instance19:52
Troyone other question regarding the domains/network clients19:52
nowenthe db improvements will help, but I would still worry.  It might crash your browser too ;)19:53
Troycan you have multiple network clients assigned to different domains?19:54
Troyexample, we have a vpn box pointing to wikid using radius19:55
Troybut we need to have two different wikid domains setup for the sslvpn19:56
Troyit allows me to set it up this way.. just need to test if it works19:56
Troyi hope that makes sense..19:57
nowenhmm20:00
nowento have two radius network clients they would need to have different IP addresses20:00
nowenthe radius listener gets a radius packet from the vpn and it matches the IP to the WiKID domain.  If there are two NCs, it will get confused20:02
Troyok.. i have two radius clients setup with same IP20:02
nowencan you setup multiple networks or virtual IPs20:02
nowen?20:02
Troythat's a possibility..20:03
Troynext, I need to work on creating new intermediate / localhost certs20:05
Troythen ultimately new network client certs to copy out to the saml servers20:06
nowenyes20:08
Troyfor our production wikid servers, do I need to get a permanent production certificate from you?20:31
Troyor can I use the automated processs?20:31
nowenyou can just use automated one20:31
Troyok.. thanks..20:31
nowenok - time for me to check out. been a long week21:22
nowenyou guys have a great weekend21:22
nowenTroy: you doing ok?21:22
Troyyes.. thanks Nick.. have a good weekend21:22
nowenyou too21:22
*** nowen has quit (Quit: Leaving.)21:22
*** Troy has quit (Ping timeout: 245 seconds)21:26

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!