Monday, 2014-04-07

Satheesh_hi00:11
Satheesh_??01:41
*** Satheesh_ has quit (Ping timeout: 245 seconds)02:26
*** Satheesh_ (6a3300ba@gateway/web/freenode/ip.106.51.0.186) has joined #wikid02:37
Satheesh_hi02:38
*** Satheesh_ has quit (Ping timeout: 245 seconds)03:09
*** Satheesh_ (67fb6c04@gateway/web/freenode/ip.103.251.108.4) has joined #wikid05:13
Satheesh_hi05:13
*** Satheesh_ has quit (Ping timeout: 245 seconds)05:28
*** Rudy6 (~Rudy6@213.132.115.194) has joined #wikid12:17
*** Satheesh_ (6a3300ba@gateway/web/freenode/ip.106.51.0.186) has joined #wikid12:24
Satheesh_hi12:25
*** coolacid has quit (Read error: Connection reset by peer)13:15
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid13:16
Satheesh_hi13:21
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:29
*** Rudy6 has quit (Quit: Leaving)13:44
Satheesh_hi13:46
Satheesh_nowen13:46
*** coolacid has quit (Remote host closed the connection)14:04
nowenHi Satheesh_14:05
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid14:06
Satheesh_Hi14:07
Satheesh_regarding GoogleSSO configuration14:07
nowenok14:07
Satheesh_I have created NC14:07
Satheesh_and uploaded the certificate in Google application configuration14:07
nowenok14:08
Satheesh_whenever I login to google web mail14:08
Satheesh_it redirects to wikid/GoogleSSO for authentication14:08
Satheesh_post providing credentials I get page not found error14:09
Satheesh_address bar is https://SERVER/wikid/GoogleSSOServlet14:09
nowenwhat did you put as your GoogleSSO acsURL?14:09
Satheesh_https://www.google.com/a/freedomhack.in/acs14:10
nowendid you restart wikid after adding the network client?14:12
Satheesh_yes multiple times :(14:12
nowenlet me do some testing14:15
Satheesh_sure14:15
*** immotus (~immotus@rrcs-24-153-193-34.sw.biz.rr.com) has joined #wikid14:25
immotusWiKid is having trouble starting up... http://paste.opensuse.org/2216845814:27
nowenimmotus: what version?14:27
immotusmay be because of the rsync error?14:27
immotusv3.5.014:28
immotusdon't laugh ;^)14:28
immotusnowen: we do have a support contract14:28
nowenwho are you with again?14:28
immotusGenares14:28
nowenahh yes14:28
immotuswe keep pestering ya'll ;^)14:28
nowenyou need to update the server and create new certs14:29
nowenour CA expired.  The new one expires in 2023 or something14:29
immotusahh.. so the rsync is copying stuff from your severs?14:29
nowenno,14:30
nowenwauth uses the certs14:30
nowenhmm14:30
nowenis the other server up and running?14:31
immotusI believe so..14:31
* immotus checks now14:31
immotuschecking "service wikid status" says that it is not functioning properly14:32
immotusbut I have java processes running14:32
nowenyou have to edit a file for status to work14:32
nowenthere shouldn't be any java services on the secondary14:33
immotusright now I'm not quite sure which of the two is the master :^)14:34
nowenhmm does status not say master or slave?14:34
immotusno.. it just says "Error: WiKID services not functioning properly."14:34
*** coolacid has quit (Remote host closed the connection)14:35
immotushowever.. I see a master_ip_old=XXX.XXX.XXX.XXX in the /opt/WiKID/conf/setup.conf file14:35
nowenthat could be because of the old code14:35
nowenI think upgrading is required14:36
immotusnowen: my boss is out for the week, so we won't be able to discuss it with him until then :^|14:36
nowenSatheesh_: do you have 'Use a domain specific issuer' checked or not?14:37
nowenimmotus: can you ssh from one to the other using the keys that are in /opt/WiKID/private ?14:37
immotusnowen: I'll try ssh'ing from the master server (the one that is down) to the slave with the keys I find there14:38
immotusnowen: what user should I ssh as ?14:39
immotuswikid?14:39
nowenroot14:39
immotusnowen: I'm using the "replication.ssh" key and our WiKID slave is asking for a password anyways.. maybe PAM isn't letting it get to the login.. ssh as root being bad14:41
nowenwhat changed on the sever?14:41
immotusnowen: these two servers don't change very often.. I don't know of any recent changes14:42
immotusnowen: this morning I saw a Nagios alert saying that the WiKID master server had an exceptionally high load.. WiKID java processes were having a party14:43
nowenwell, you need to update them ;-)14:44
immotusnowen:  :^)14:44
immotusnowen: I'm looking forward to updating them more and more :^)14:44
nowenthe latest one is great, IMO14:44
immotusnowen: if the biggest problem with the current one is the SSL cert.. would I be able to copy the correct cert in place and restart WiKID?14:46
noweni think try to take it out of replication and start it14:46
nowenI'm thinking this is actually a replication issue14:47
*** Satheesh_ has quit (Ping timeout: 245 seconds)14:49
immotusnowen: so, take the current wikid slave, comment out the "master_ip_old" line, restart the slave, and then restart the previous master?14:50
nowenhow about this.14:51
nowenre-run setup on both14:51
immotusrun this "/opt/WiKID/sbin/wikid_setup"  ?14:53
nowen'wikidctl setup'14:53
immotusnowen: I've never done a WiKID installation.  What things will I need to do during/after the setup?14:56
immotuswill I need to keep track of any config files or pass phrases?14:56
nowenimmotus: I'm guessing that your passphrase is in /etc/WiKID/security14:57
immotusnowen: yes14:57
nowenso, you will be prompted to set up the network, I recommend you run through that to check it14:57
nowenthen prompted to set up replication, run through that too14:58
nowenthen try to restart14:58
immotusnowen: what does "set up the network" entail?  This isn't a dedicated WiKID server14:59
nowenyou're running other software on it?14:59
immotusnowen: yes.. it's also one of our DNS servers15:00
nowenyou shouldn't need to change any settings15:01
nowenwe recommend that WiKID be stand-alone.  a bug in bind could allow an attacker to take over the server15:01
immotusnowen: so running wikid_setup launches a wizard that will pick up the current settings from the WiKID config files?15:01
nowenyes15:02
immotussounds like an excellent recomendation.. running WiKID standalone.. I wish I could re-do it right now :^)15:02
nowenwell, you probably can if you want.  Is 'none' an option for replication?15:04
immotusI've discussed running through the WiKID re-config with a superior (who is in charge until the boss comes back) and he's asked me to hold off on fixing WiKID until the boss comes back15:05
immotushe hinted that there was some custom configuration that we have in place that may also break15:05
nowenoh.15:05
* immotus is asking what that custom configuration is15:05
immotusasking my superior.. not you :^)15:06
immotusnot that you aren't superior in WiKID knowledge.... n/m15:06
immotus:^)15:06
nowen;-)15:06
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid15:06
*** coolacid has quit (Remote host closed the connection)15:07
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid15:11
nowenimmotus: did you try to restart?15:20
immotusI tried a restart on the WiKID master, but it hung with the error I pastebin'd earlier15:58
immotusnowen: I was hesitant to try a restart of the slave after that :^)15:58
nowenI doubt it matters since your service is down anyway15:59
immotusnowen: the master is currently down..   rather.. the wikid.pl process is running, waiting for wAuth to come back15:59
immotusnowen: good point :^)15:59
immotusnowen: I'll restart the wikid slave, then15:59
nowendid you try to set the master as stand alone or just reset for replication?16:00
immotusnowen: I have not tried setting any of them up as stand-alone16:01
nowenI think trying to set the master up without replication would be the fastest way to recover16:04
nowenwhat were the options for replication when you ran setup?16:04
nowenalso, are there java processes running ?16:06
nowenmight need to 'killall -9 java'16:06
immotusnowen: I haven't run setup yet.   I don't know what options where used the last time16:10
nowenyou didn't run 'wikidctl setup'?16:11
immotusnowen: true.  we'll feel more comfortable working with this when my boss comes back.  since he has a better idea of what was done during the setup last time16:12
nowenso, are you just going to leave it down?16:12
immotusnowen: yeah, I'm afraid so.. unless something minimal like restarting the WiKID slave resolves the problem.  But since it's hanging on wAuth I doubt it will16:13
nowenlook, there's no magic in running setup.  your service is down. why not?16:13
immotusnowen: I got a little bit more feedback on the custom setup.. apparently our Puppet server adjusts some WiKID config values (I don't know what yet) for our environment.  And if I'm going to have to reconfigure the network interface then I'd rather not risk messing with the first DNS server in /etc/resolv.conf on most of our machines16:17
nowenyou don't have to reconfigure the network interface.  you have to get past that part to setup replication.  they are both in the same script16:17
immotusnowen: so what sort of network interface configuring does WiKID need to do, then?  Or does it simply need to know which network interface to use for what?16:26
nowenjust knowledge. I doubt that the network has changed, but why not look?16:26
nowenrunning the command won't change the network settings16:34
immotusnowen: the network settings haven't chagned16:38
immotuss/chagned/changed16:38
nowenok - do you want to turn off replication?16:38
immotusnowen: as a temporary measure?16:39
nowenwell, you can try to turn it back on, but it's not working so...16:40
immotusnowen: let me see what changes puppet is making first.  Our installation was installed by a clever person who had a prediliction for customizing.16:46
nowenthere's really not much that puppet can do to wikid. it's almost all done through the web UI16:47
immotusnowen: heh.. speaking of which, I've never logged into the web ui.  I don't think I have access to that. .just the OS stuff16:48
immotusnowen: sry, I keep getting pulled away17:21
immotusI'll be back in about an hour.. hopefully less17:21
nowenok17:27
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid17:57
AccentureDanSir Nicholas!17:57
AccentureDanquestion17:57
nowenhi dan17:57
AccentureDanso im filling out a runbook for the prod WiKID server I built on Friday...do you guys have any information on back ups?17:57
AccentureDanlike what to back up if we needed a disaster recovery solution17:58
nowenwell, the big ones: /etc/WiKID/, /opt/WIKID/ /var/lib/pgsql/data17:58
AccentureDanThanks man :)18:00
AccentureDangotta run to a meeting, have a good one!18:00
*** AccentureDan has quit (Client Quit)18:00
*** immotus has quit (Quit: Konversation terminated!)21:32
*** nowen has quit (Quit: Leaving.)22:35
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid22:55
*** AccentureDan has quit (Client Quit)22:55
*** Satheesh_ (6a3300ba@gateway/web/freenode/ip.106.51.0.186) has joined #wikid23:35
Satheesh_hi23:37
Satheesh_Is Nick available in chat23:38
Satheesh_I have queried Nick on Google SSO connection issue23:44
Satheesh_can somebody who is online can help me on that23:45
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid23:51
nowenSatheesh_: can you paste the 404 error here?23:52
nowenSatheesh_: are you here?23:53
Satheesh_yes23:54
nowenok23:54
nowencan you post the 404 url here?23:55
Satheesh_https://<servername>/wikid/GoogleSSOServlet23:55
nowenno, the actual url23:55
nowenmine was https://ec2-54-83-42-36.compute-1.amazonaws.com/GSSO/?SAMLRequest=fVJNT%2BMwEL0j7X%2BwfG%2FSsJUAqwnqgtBW4iOiYQ97c5xp6uLMFI%2FTwr%2FHTUGwh63kg%2FXmed5745levnZObMGzJcxlloylADTUWGxz%2BVTdjM7lZfHjZMq6cxs168MKH%2BGlBw4ivkRWQyGXvUdFmi0r1B2wCkYtZne36jQZq42nQIacFPPrXK6XrtUrqtdQI2Fn0bnnNTzXzUrXddsZRO32Vyn%2BfNo63duaM%2FcwRw4aQ4TG2WQ0juesyiZq8lNNLv5KUX4o%2FbJ4SHDMVn0gsfpdVeWofFhUQ4OtbcDfR3YuW6LWQWKo28uXmtluI7zUjkGKGTP4EA1eEXLfgV%2B23:56
Satheesh_https://<servername>/wikid/GSSO?SAMLRequest=fVLLbtswELwXyD8QvFuSnQQtCEuBmyCogbQVYqWH3mhyJdMiuSqXstu%2FLy0nSHpoAJ6Gw3ksd3nz21l2gEAGfcnnWcEZeIXa%2BK7kT8397BO%2FqS4%2BLEk6O4jVGHf%2BEX6NQJGll57EdFHyMXiBkgwJLx2QiEpsVl8fxCIrxBAwokLL2fqu5HIPuN2h67Hr5dDv%2B71tvdZt11p0Urf9Xlvltj1nP15iLU6x1kQjrD1F6WOCivnVrEjnY7O4FNdXorj%2ByVn97PTZ%2BHOD92JtzyQSX5qmntXfN80kcDAawrfELnmH2FnIFLqTfS2JzCHBrbQEnK2IIMQU8BY9jQ7CBsLBKHh6fCj5LsaBRJ4fj8fsVSaXeRsANLqdVH1mf23:57
nowenwhat is your server name?23:57
Satheesh_Actually it is internal now23:57
Satheesh_I have disabled external access23:57
nowenok - how will Google reach it?23:57
Satheesh_I am connected to VPN23:58
nowenyeah, but google isn't23:58
nowengoogle needs to talk SAML to your serer23:58
Satheesh_it does23:58
Satheesh_from gmail.com page when I try to login23:58
Satheesh_it redirects to wikid server with SAML request23:59
nowenok and what is that url?23:59
nowenI need to go to it23:59
Satheesh_ok let me enable outside access23:59

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!