Thursday, 2014-04-17

*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:30
*** Salik (45f6d450@gateway/web/freenode/ip.69.246.212.80) has joined #wikid15:32
*** ddreggors (~ddreggors@199.227.2.200) has joined #wikid15:33
Salikhi nick. you there15:33
nowenhi Salik15:33
nowenyes I am15:33
Saliki am here with my coworker, David15:33
Salikwe were going through the install15:33
nowengreat15:33
Salikwe were trying to login to the web interface but it doesnt seem to accept the pw we set15:33
nowentry WiKIDAdmin/2Factor15:34
Salikok15:34
Salikoh ok.  that worked.  we didnt see that in the install documentation15:34
nowenonce you have it installed, go to the full manual: http://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server15:35
Salikoh ok.  i think we were looking at quick start15:36
nowenthat works too15:36
ddreggorsno we are on this page15:37
ddreggorshttp://www.wikidsystems.com/support/wikid-support-center/installation-how-tos/how-to-install-the-wikid-enterprise-rpms15:37
ddreggorsand that did not say anything about 2Factor for password...15:37
Salikok nick, so next question I had..15:37
Salikthe screen shot I sent you yesterday for network clients15:37
ddreggorsthanks, we just did not know where to look15:38
Salikit showed 2 entries15:38
Salikone for a NPS server and one for the gateway server15:38
nowenI'll add a link to the manual form that page15:38
ddreggorsthanks, we appreciate your help15:39
nowenSalik: yes, one of those will probably not work ;-)15:39
Saliki have a feeling our current setups are not correct.  We currently have 2 wikid servers at different datacenters15:40
Salikboth are configured pretty much like that screenshot I sent you15:41
nowenhmm15:41
SalikI logged into the NPS server15:41
Salikand looked at the logs15:41
Salikand i dont see anything in them15:41
Salikthis was all setup maybe 5 years ago by a team that is no longer with the company15:41
Salikour second wikid server was configured the same way but pointing to another domain controller local to that data center15:42
Saliki logged into that server and it doesnt even have NPS installed on it15:42
nowenwell, I'm glad you're looking into ti15:42
Salikso i have no idea how either of these working15:42
nowenwell, let's do a couple to things15:42
Salikok15:43
nowendo you use both servers or just one?15:43
Salikwe use both15:43
Salikboth are at different data centers15:43
Salikwe will be shutting one datacenter down15:43
Salikand moving to a new datacenter15:43
Salikand that is the new server I am building15:44
nowenok15:44
Salikwe want a seperate wikid server / NPS at each location15:44
nowenon the server you're going to keep, run 'tcpdump port radius'15:44
nowenand then login15:44
nowenie - login to your vpn to create a radius requst15:48
nowenthat command will show you which network client IP is being used15:48
Salikok running the command now.  trying to get a user who has wikid installed to try logging in15:49
Saliki do believe we ran this before and saw no traffic15:50
Salikbut we will verify right now15:50
Saliki dont know if you remember, but 2 weeks ago, we were talking about an issue where users were able to use AD credentials instead of wikid token and were able to connect fine15:51
Salikso maybe this is all related?15:51
nowenI think that was your PAM config.15:51
Salikok.  we never really made changes to PAM so that issue still exists15:52
nowenhuh? I thought it was fixed?  the /etc/pam.d/ssh file was the issue15:52
Salikwe made a change and nobody could login15:52
Salikso we changed it back as it was15:52
nowendo you have access to that server?15:53
Salikyes15:53
nowencan you tell me what is in /etc/raddb/server?15:53
Salikso it has the IP for itself and a password and 315:55
Salikso our gateway server and wikid are running on the same server15:55
nowenok15:55
nowenso that makes me think that NPS is not in the middle15:56
nowenbecause PAM is just talking straight to wikid15:56
nowennote that it is using the IP and not localhost - b/c wikid itself is using localhost for radius15:57
Salikmaybe that is why we are seeing no RADIUS traffic15:57
nowenmakes sense15:57
nowenI'm thinking that we should setup the new DC the way you want to work and then copy that set up to the existing one15:59
Salikyeah i think that is the best way16:00
Salikso we dont currently have a NPS server setup in the new DC16:00
Salikso that should be the next step?16:00
Saliki can install that role on one of our domain controllers16:00
nowenIf you want to use AD for authorization, then you need NPS16:04
nowenSalik: is KOlson2 still the correct billing person?16:08
Salikhmm i dont think so16:09
Saliki will try to get an updated name for you16:09
nowenoh - wait sorry16:09
nowenwrong window and account ;-)16:09
Salik:)16:10
Salikok i just got the NPS role installed.  is there any documentation I can follow to configure that?16:10
nowenwe have this: http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps16:10
nowenbut MS might have something better16:10
Salikwe should get NPS configured completely first prior to configuring wikid?16:11
nowendoesn't matter.16:11
Salikok16:11
nowenwhat you should think about is how to test it16:12
nowenso, you might want to have PAM talk radius to NPS using AD creds first16:12
nowenthen add WiKID to NPS and test with an OTP16:12
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid16:17
AccentureDanhey Nick question for ya16:17
nowenAccentureDan: ok16:17
AccentureDannot sure how familiar you are with the Cisco ASA firewall and SSL VPNs, but more or less, I saw the instructional video that showed authenticating directly with WiKID16:18
AccentureDanI want to use the existing Network Policy Server framework I have set up so users are not directly communicating with WiKID, and credential routing is being done by NPS for AD and WiKID, then back out the ASA16:18
AccentureDando you have any understanding of how this would work?16:19
AccentureDanor know someone that would? haha16:19
AccentureDanhave already opened a TAC with Cisco, but just want to see if you would know anything16:19
nowenit's all NPS today16:19
AccentureDanHAH16:19
AccentureDani love NPS16:19
nowenhttp://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps16:19
AccentureDanI have the RADIUS server set up in NPS as the ASA16:19
nowenalso this: http://www.wikidsystems.com/learn-more/white-papers16:19
nowenso WiKID will be a radius server on NPS16:20
AccentureDanbut I think the question is, how to route the requests from the ASA to the NPS16:20
nowenoh16:20
nowenThe NPS will be a radius server on the ASA16:20
nowenjust replace the WiKID IPs that you see in that video with the NPS ip16:21
AccentureDanyup got that set up as well, sweeeeeeet16:21
AccentureDani thought so just wanted to reach out first16:21
AccentureDan:-D16:21
nowenand you have WiKID setup in NPS as a server?16:22
*** AccentureDan has quit (Quit: Page closed)17:05
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid17:10
AccentureDanso security question for ya17:11
nowenok17:11
AccentureDanthere is a discussion going on right now about security of one-time passcode distribution...user's needing to request one-time passcodes would essentially hit our WiKID server via a port forward from our external-facing Internet IP address, pass through an IPS, then hit the WiKID server17:11
AccentureDanhow do most of your customers do this to keep things as safe as possible?17:12
nowenseems pretty clean. I would block any traffic that is not going to /wikid/ from the outside17:12
AccentureDanprecisely...during the NAT/Port forwarding, only the one port (random) on the outside gets forwarded to one port (internal) HTTP port on the WiKID server for one-time passcode requests17:13
AccentureDan figured this is the most safe...in between there an IPS analyzes traffic17:13
nowenyeah17:13
AccentureDanawesome just wanted some affirmation that you thought this was normal/safe17:14
*** AccentureDan has quit (Quit: Page closed)17:24
Saliknick, when we are generating the intermediate CA, we didnt receive any email17:54
Salikhow is it sent out?17:54
nowenit should have come back in the same pop-up17:55
nowenhold on17:55
Salikoh ok never mind17:56
Salikmisread something17:56
Salikwe did get it in the popup17:56
nowenI have emailed it17:56
ddreggorsI think again we misunderstood. The text on the page was saying it would email, but in fact as you said it was in the pop up18:23
nowenSalik: ddreggors: how goes the install?19:33
ddreggorswe are still going but we got sidetracked by other issues19:37
nowenok19:38
*** ddreggors has quit (Quit: Leaving)21:24
*** nowen has quit (Quit: Leaving.)22:38

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!