Friday, 2014-04-18

*** Rudy6 (~Rudy6@213.132.115.194) has joined #wikid11:50
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:53
*** Rudy6 has quit (Quit: Leaving)16:33
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid16:45
AccentureDanhey Nick quick question16:45
nowenok16:45
AccentureDanworking on getting the flow of traffic going via the firewall16:45
AccentureDanso we opened 1812/1813 for RADIUS between the firewall and the NPS box, works great16:46
AccentureDanwhere does 8388 communicate?16:46
nowen8388 is for our API.16:46
AccentureDanalso, do we need LDAP enabled for any reason?  the NPS box authorizes locally so dont think so16:46
AccentureDanokay so that is local, that doesnt need to communicate to anything16:46
nowenSo, if you have a wAuth client it uses 838816:46
nowencorrect16:46
AccentureDanawesome16:46
nowenI would not enable LDAP16:46
AccentureDanare there any ports WiKID needs to use to communicate anything back to NPS?16:47
AccentureDani am getting an access denied error on the WiKID box16:47
nowenthe tokens use port 8016:47
nowenand the WiKIDAdmin uses 44316:47
AccentureDangot that, one time passwords work great16:47
AccentureDangot that, i can access the website without issue16:47
nowenwhat port is giving you an access denied?16:47
AccentureDani am getting an Access Denied error16:47
AccentureDanlemme check16:48
nowenoh, you mean for radius?16:48
AccentureDan5039216:48
AccentureDanit says this16:48
AccentureDan<1> Access-Request(1) LEN=82 10.67.109.246:50392 Access-Request by daniel.m.greer Failed: AccessRejectException: Access Denied16:48
nowenare you enabled?16:48
AccentureDanHAH16:48
AccentureDanlemme try again16:48
AccentureDan:-P16:48
AccentureDanno go16:49
AccentureDan2014-04-18 09:49:28.960INFOcom.wikidsystems.radius.access.WikidAccess4Access denied for daniel.m.greer, domain code: 010067123060 client: /10.67.109.246  2014-04-18 09:49:28.960INFOcom.wikidsystems.radius.log.DBSvrLogImpl<2> Access-Request(1) LEN=82 10.67.109.246:50392 Access-Request by daniel.m.greer Failed: AccessRejectException: Access Denied  2014-04-18 09:49:25.234INFOcom.wikidsystems.server.DeviceTransactionExecI16:49
AccentureDanso passcode works great, but when i enter my username in to the field, then the password it fails16:50
nowendaniel.m.greer is the username?16:50
AccentureDanyup16:50
nowen10.67.109.246 is nps?16:50
AccentureDanyup16:50
AccentureDanwait16:51
AccentureDanthink i may know16:51
AccentureDan1812 and 1813 need to be enabled between NPS and WiKID right?16:51
nowenwell, it looks like WiKID is getting the radius requests fine, so I don't think it's the ports16:51
AccentureDangotcha16:51
AccentureDanany reason it would reject?16:51
nowen010067123060 is the correct domain?16:52
AccentureDanthe username in AD is the same as the username in WiKID16:52
AccentureDanyup16:52
nowenset your logs to debug and try again.  http://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-can-i-set-radius-logging-to-debug-how-can-i-see-if-wikid-is-getting-the-radius-requests16:53
AccentureDan2014-04-18 09:54:26.749INFOcom.wikidsystems.radius.log.DBSvrLogImpl<4> Access-Request(1) LEN=82 10.67.109.246:50392 Access-Request by daniel.m.greer Failed: AccessRejectException: Access Denied  2014-04-18 09:54:26.748INFOcom.wikidsystems.radius.access.WikidAccess4Access denied for daniel.m.greer, domain code: 010067123060 client: /10.67.109.246  2014-04-18 09:54:23.088DEBUGcom.wikidsystems.server.WikidCode3AESPasscode16:54
nowenthere should be more detail in their somewhere.16:54
nowenpost it all to pastebin.com if you want16:55
AccentureDansure16:55
AccentureDanwhere on pastebin?16:56
AccentureDanjust paste it in then send you the link?16:56
nowenyep16:56
AccentureDanhttp://pastebin.com/qEKhyvRR16:56
nowenwhich loggers do you have set for debug?  I think you are missing some16:57
AccentureDancom.wikidsystems, com.wikidsystems.server.wauth, com.wikidsystems.radius.access.WiKIDAccess416:58
AccentureDanjust added the radius one16:58
nowenok16:58
nowentry again16:59
AccentureDangotcha one sec16:59
AccentureDanhttp://pastebin.com/ygshj9iy17:01
nowenadd com.wikidsystems.client.wClient too17:01
AccentureDanhttp://pastebin.com/n2XnidnA17:03
nowenhmm17:04
AccentureDanalso NPS gives me a unique error17:04
nowennot much difference is there17:04
nowenwhat's that?17:04
AccentureDanThe RADIUS Proxy received a response from server 10.67.123.60 with an invalid authenticator.17:04
nowencheck your shared secrets17:04
AccentureDanyou got it17:04
AccentureDanWORKS!17:07
AccentureDanwoot!17:07
AccentureDanproduction IN17:07
AccentureDanLINE17:07
AccentureDan:-D17:07
AccentureDanthanks for all of your help sir!17:07
nowenI note that's still an internal IP you're using for the domain17:07
AccentureDanyes sir17:52
AccentureDanwe limited all this stuff17:52
AccentureDanill send you our design doc so your mind can be scrambled eggs17:52
AccentureDanbeyond complicated...but the more complicated it is for us, the harder it should be for a hacker to get through all the walls of Fort Knox17:52
AccentureDan:-D17:52
nowensounds good18:16
*** AccentureDan has quit (Quit: Page closed)18:22
*** coolacid has quit (Ping timeout: 258 seconds)18:24
*** AccentureDan (3f7c1664@gateway/web/freenode/ip.63.124.22.100) has joined #wikid19:26
AccentureDanokay got it all working, real quick question though19:27
AccentureDanwe are hardening up the servers19:27
nowenok19:27
AccentureDanwhen the user is presented to the WiKIDAdmin page, and they go to log in19:27
AccentureDanwe nly have 443 enabled...but it times out logging in...do we need wAuth open as well?19:27
AccentureDanis that what it is used for?19:27
nowenwhat page are the users going to?19:28
nowenis this for Admins or the users?19:28
AccentureDannope just for the admin console19:28
AccentureDanjust for the admins to add users and such19:28
nowenwill they be on the inside network?19:28
AccentureDanyup no outside access19:29
AccentureDanall internal19:29
AccentureDanand only our domain controllers can talk to the WiKID Admin console19:29
nowennot sure why it would time out19:29
nowen8388 is not needed19:29
nowenjust 44319:30
AccentureDangotcha19:32
AccentureDanlemme check19:32
AccentureDangoing to restart the server, needs it any way after all the testing crap we have done today19:33
AccentureDansolved it19:35
AccentureDanhaha19:35
nowencool19:36
AccentureDanquestion, again haha19:37
nowen;-)19:38
AccentureDanwhat version of Java would you recommend we have user's utilize for the JAR non-installable token client?19:38
AccentureDanthis will be going on the client PCs19:38
nowenthe latest19:38
AccentureDangotcha, good to know19:39
AccentureDanas for the proxy19:40
AccentureDanfor the token client19:40
AccentureDani see HTTP, SOCKS, and System...we opened a random high-end TCP port that is being port-forwarded to 80...would System be the one to use?19:41
AccentureDannot sure which one would be the best haha19:41
nowensystem just uses the one that the OS uses19:42
AccentureDanokay so probably HTTP...that would mimic a TCP port, correct?19:42
nowenit's not for a random port, it's for a proxy19:42
AccentureDanhm i used it before on a random port worked fine...just trying to test if Verizon opened that port on their Internet gateway19:43
nowenthe smartphone tokens don't support proxies, just so you know19:44
AccentureDanthats fine no one will be using those haha19:44
AccentureDandoesnt look like they have made their changes just yet...we just filed the ticket yesterday, no worries19:46
AccentureDanwill keep ya updated, should be good to go19:46
nowenok19:46
AccentureDanall the internal testing is done, works like a charm19:46
AccentureDangoing to table this til Monday, thanks again for your help man have a great weekend!19:46
nowenyou too!19:47
*** AccentureDan has quit (Ping timeout: 240 seconds)19:51
*** nowen has quit (Quit: Leaving.)21:52

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!