Monday, 2014-07-21

*** nowen (~nowen@2600:1003:b120:e7cd:4b2:5293:6a90:39b7) has joined #wikid14:01
*** Salik (45f6d450@gateway/web/freenode/ip.69.246.212.80) has joined #wikid14:56
Salikhi nick.  you there?14:56
nowenyes14:56
nowenwhat's up?14:57
SalikI was able to successfully set up our "new" wikid server.  We are seeing some issues with the "old" server today.  Getting a "The wClient connection to the server was NOT successfully established" message at example.jsp page14:57
Salikwe have tried restarting wikid but that didnt seem to help14:58
nowenhmm - did you upgrade that server? If so, it may have been overwritten.  you might have to re-edit it14:58
Salikno the old server was not touched.  a completely new server was built14:58
Salikwe were going to retire the old server once we got users moved to the new server14:59
nowencheck the file and make sure that the passphrase for the localhost wasn't changed14:59
Salikwhat file am i looking at?15:00
nowen/opt/WiKID/tomcat/webapps/WiKIDAdmin/example.jsp15:00
Salikthis server was setup long before me... so don't know the passphrase.  anywhere else I can look to check if the passphrase here matches?15:10
nowenwell, it is says 'passphrase' then it's been over-written.  The other possibility is that your localhost cert is expired15:10
nowenhttps://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid15:11
nowencheck it via the command line as per that page.  if it is expired, just create a new one via the Config tab.15:11
Salikyeah it doesnt say "passphrase"15:11
Salikok15:11
nowenif you use the same passphrase as you saw in that page, then you don't have to edit the page ;-).  but it would be good to change it if people have left, etc.15:12
Salikdoes passphrase have to be in quotes when you run those commands in the link?15:29
Salikto check cert15:30
nowenI don't think so15:30
Salikmy passphrase has special characters.  when i run it without quotes it gives syntax error15:30
nowenhmm could be then15:30
nowenif you do, does it work?15:31
Salikwhen i run with quotes, i get "keytool error: java.io.IOException: PKCS12 key store mac invalid - wrong password or corrupted file."15:31
nowenwhat's the date on that file?15:31
Saliki am using the passphrase that was in that file15:31
Salikone sec15:31
nowenno harm in just creating a new localhost cert, reall15:31
noweny15:31
Salikapril 3 201315:31
nowenso, it's probably expired.15:32
nowenso - it could be that the passphrase is wrong too15:32
nowenI say just create a new one with the passphrase you want anyway15:32
Salikok.  any documentation on how to do that part15:33
nowenhttps://www.wikidsystems.com/support/wikid-support-center/manual/how-to-install-the-wikid-strong-authentication-server/how-to-install-the-wikid-strong-authentication-server-enterprise-edition-page-215:34
Salikthis is a live production system right now.  i cant do anything to "break" it.   users are able to connect right now.  just cant register new accounts15:34
nowenlook for Step 4: Generate a Localhost Certificate15:34
nowenit won't break anything. but you will need to restart the server15:34
nowenis this the only script you have running?15:35
nowenare you using ADRegister?15:35
Saliki have no idea :)15:35
Saliki know nothing about how this was setup :)15:35
nowenwell, ADregister allows users to register their own tokens after logging in to the script with their AD creds15:36
nowendo you guys do that?15:36
Salikno we are not using that I think.  we have to manually register the accounts15:36
nowenwell, that's the only other script we provide that uses localhost.p1215:36
nowenso, you create the new localhost cert and and soon as you restart, example.jsp should work.15:37
Salikand it doesnt matter what I use for passphrase?15:38
Salikit doesnt need to be updated anywhere else?15:38
nowenit shouldn't.15:38
Salikit needs to match the passphrase in example.jsp, right?15:39
nowenyes - they need to match.15:39
*** nowen1 (~nowen@2600:1003:b115:f1fb:4b2:5293:6a90:39b7) has joined #wikid15:42
*** nowen has quit (Ping timeout: 240 seconds)15:44
*** nowen1 is now known as nowen15:45
SalikClient PKCS12 Passphrase is the one that needs to match example.jsp passphrase?15:47
nowenyes15:47
Salikand then any way I can find the server keystore passphrase?  not sure what that is since this was all setup long ago15:48
nowenif you are not prompted for it on every restart, then it is in /etc/WiKID/security15:48
Salikok15:48
nowendid it work?16:06
Salikyeah that worked.  thanks for the help16:33
nowenok16:43
*** nowen has quit (Ping timeout: 240 seconds)19:06
*** Salik has quit (Quit: Page closed)20:15
*** nowen (~nowen@2600:1003:b126:6305:4b2:5293:6a90:39b7) has joined #wikid20:22
*** nowen has quit (Ping timeout: 240 seconds)20:39

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!