*** ricardoamaro has quit (Ping timeout: 246 seconds) | 11:05 | |
*** ricardoamaro (~ricardoam@drupal.org/user/74228/view) has joined #wikid | 11:19 | |
*** ricardoamaro has quit (Ping timeout: 265 seconds) | 11:24 | |
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid | 13:18 | |
mo__ | hi nick | 13:44 |
---|---|---|
nowen | morning mo | 13:45 |
mo__ | so before i continue with my fix from yesterday i would like to know how does wikid work if i lose an isp | 13:46 |
mo__ | that is i have two isp feeds into my office | 13:46 |
nowen | and that would require a change of IPs? | 13:46 |
mo__ | yes | 13:47 |
nowen | we can create a DNS entry in our DNS that would point the tokens to the new IP | 13:47 |
mo__ | can i do that on my own dns | 13:49 |
mo__ | we dyn | 13:49 |
mo__ | we use dyn | 13:50 |
nowen | only if you are only using PC tokens and it would require pushing out changes to all the tokens | 13:50 |
mo__ | if i use yours would i need to change teh dns settings anywehere in my systems | 13:54 |
nowen | no | 13:54 |
*** Troy_SANM (3286cb7f@gateway/web/freenode/ip.50.134.203.127) has joined #wikid | 14:01 | |
Troy_SANM | Good morning Nick | 14:02 |
nowen | morning | 14:02 |
Troy_SANM | if I get a interCA from the ca license site for my lab.. can I do it again for the production boxes? | 14:02 |
Troy_SANM | it will be the same FQDN domain | 14:03 |
Troy_SANM | unless you think I can just copy the /private folder over after upgrade is done.. | 14:04 |
nowen | I'm thinking either should work, but let me check | 14:04 |
Troy_SANM | of course I would need to re-create the localhost and network client certs again | 14:04 |
Troy_SANM | we came up with 6533 unique licenses in use in our current prod environment | 14:05 |
nowen | what does the server say? | 14:05 |
Troy_SANM | the latest version is unfortunately showing 7096 in users with Registered Devices: 33366 | 14:10 |
nowen | hmm | 14:10 |
nowen | mo__: is your licensed users correct now? | 14:11 |
Troy_SANM | i sent you a screenshot Nick | 14:15 |
nowen | oh | 14:16 |
nowen | hmm, is this with the eval cert? | 14:16 |
nowen | because the latest has a new look | 14:17 |
Troy_SANM | yes.. i was waiting on your reply on the certificate request before installing the new cert | 14:18 |
nowen | ok | 14:18 |
nowen | give me a sec | 14:18 |
Troy_SANM | 500+ difference is quite a bit on user counts | 14:18 |
nowen | yes | 14:18 |
Troy_SANM | we got to figure this out | 14:18 |
nowen | yes | 14:19 |
Troy_SANM | i know some users are all CAPS and or some users have a first letter caped | 14:19 |
Troy_SANM | capped | 14:19 |
Troy_SANM | is there a limit of the amount of devices per user? | 14:19 |
nowen | oh yeah - we went through that before - I hope it's not a regression | 14:20 |
Troy_SANM | i can tell you that after the upgrade, the license count did drop from 7993 to 7096.. so some dups are dropping correctly | 14:22 |
mo__ | sorry had to put out a few fires | 14:26 |
mo__ | i'm back now | 14:26 |
mo__ | yes the license count is correct | 14:26 |
nowen | mo__: ok good to know | 14:27 |
mo__ | but i have to renwew the cert | 14:27 |
nowen | yep | 14:27 |
mo__ | because yesterday we had the temporary license | 14:27 |
nowen | Troy_SANM: the plan is to upgrade one of the productions servers - java and rpm and then copy over the /private contents? | 14:27 |
Troy_SANM | after the last few failed upgrades.. my plan is to do what Nick tells me to do :) | 14:28 |
nowen | ok | 14:28 |
Troy_SANM | i just want this to work | 14:28 |
nowen | checking on some things | 14:28 |
nowen | I hear ya | 14:28 |
Troy_SANM | so if re-creating the certs on both servers manually is the solution.. i will do that | 14:29 |
Troy_SANM | it does not take very long to do.. as long as I get the certs back from wikid ca quickly | 14:29 |
Troy_SANM | maybe a temporary license or 60 day license for the 7100 or so until we the upgrade done.. if there is another upgrade to correct the licnse counts.. that's fine as i feel the minor upgrades should go quick after this big jump | 14:31 |
nowen | I'm testing the copy of /private now | 14:31 |
Troy_SANM | ok | 14:32 |
Troy_SANM | brb.. coffee calling | 14:32 |
mo__ | i've added 60 licenses and submitted a purchase order | 14:33 |
mo__ | nick can you take care of on your side as per our discussion from yesterday | 14:34 |
mo__ | thanks | 14:34 |
nowen | yes | 14:34 |
nowen | mo__: just confirming - I have your renewal date as Aug 23rd 2015 | 14:37 |
mo__ | yes that is correct | 14:37 |
nowen | ok - | 14:38 |
nowen | you need to logout of the CA site and log back in | 14:38 |
nowen | then you should see that you order is processed. click on the Certificate link under Servers and install that cert | 14:38 |
nowen | let me know! | 14:38 |
nowen | Troy_SANM: I moved the contents of /private to a new server and all the licenses moved. I was able to manually add a user and added one through the example.jsp api | 14:45 |
nowen | actually, I added a second token to the existing user | 14:45 |
Troy_SANM | ok.. are you able to add a new user? | 14:45 |
nowen | es | 14:45 |
nowen | yes | 14:45 |
Troy_SANM | ok | 14:46 |
Troy_SANM | ok.. sorry.. through you said "added token to existing user" | 14:46 |
mo__ | perfect that worked | 14:47 |
nowen | Troy_SANM: did both, actually | 14:47 |
nowen | mo__: great! so you see 60 users on that server? | 14:47 |
mo__ | yes | 14:47 |
nowen | sweet | 14:47 |
Troy_SANM | to send you a message directly, do I just do @nowen at the beginning of the line? | 14:48 |
mo__ | but i still cannot get to example.jsp | 14:48 |
nowen | what about your adduser.jsp? | 14:49 |
mo__ | or adduser.jsp | 14:49 |
nowen | Troy_SANM: just start typing nowen and hit tab | 14:49 |
nowen | or do you mean a private message? | 14:49 |
Troy_SANM | nowen: thanks | 14:49 |
nowen | not sure if the web interface can do private messages | 14:50 |
Troy_SANM | ok.. that's fine.. just curious | 14:50 |
nowen | some windows IRC clients: http://www.makeuseof.com/tag/top-7-free-irc-clients-windows-7/ | 14:51 |
*** test__ (32c2f97d@gateway/web/freenode/ip.50.194.249.125) has joined #wikid | 14:52 | |
mo__ | if i list i still see the adduser.jsp but can browse to it | 14:53 |
mo__ | do i need to copy it somewhere | 14:53 |
mo__ | else | 14:53 |
nowen | is it in /WiKIDAdmin? | 14:53 |
mo__ | cd /WiKIDAdmin doesnt seem to work | 14:55 |
mo__ | when you are you going to get a gui.. :-) | 14:55 |
nowen | try ' cd /opt/WiKID/tomcat/webapps/WiKIDAdmin/ ' | 14:55 |
nowen | haha | 14:55 |
nowen | well, we are making a better one | 14:56 |
nowen | not sure if we can include example.jsp in it, but we will make it so you can add more tokens to a user without the api | 14:56 |
*** test__ has quit (Ping timeout: 246 seconds) | 14:56 | |
mo__ | ok i see example.jsp but not adduser.jsp | 14:57 |
mo__ | but i can't browse to example.jsp | 14:57 |
nowen | did you copy adduser someone else before the update? | 14:57 |
mo__ | in the root i have a adduser.jsp | 14:58 |
mo__ | must've copied it before | 14:58 |
nowen | ok - so you can copy that back to WiKIDAdmin using 'cp /root/adduser.jps /opt/WiKID/tomcat/webapps/WIKIDAdmin ' | 14:59 |
nowen | then browse to it | 14:59 |
mo__ | ok copied but am getting | 15:00 |
mo__ | The wClient connection to the server was NOT successfully established | 15:00 |
nowen | try wikidctl restart | 15:00 |
*** Mark____ (44715d76@gateway/web/freenode/ip.68.113.93.118) has joined #wikid | 15:01 | |
Mark____ | morning | 15:01 |
Mark____ | Is Nick here? | 15:01 |
nowen | morning Mark____ | 15:02 |
Mark____ | Hello | 15:02 |
nowen | hi | 15:02 |
Mark____ | just wanted to pop in here incase there were any questions on the email Troy sent this morning | 15:02 |
Mark____ | i went through the report manually as well removing duplicates | 15:02 |
nowen | good to have you. I think we are on target for everything | 15:02 |
Mark____ | and ended with the same numbr | 15:02 |
Mark____ | number | 15:03 |
Mark____ | we have employees that use John Smith, JOHN smith, JOHN SMITH, John SMITH, john smith as examples but they are all the same employee | 15:04 |
Mark____ | was ot sure how you programmed it to remove the duplicates | 15:05 |
nowen | and were they registered as such, because I feel like we fixed that a while back | 15:05 |
Mark____ | they still show up though | 15:05 |
Mark____ | our current uniques user names in wikid is 6532 and on your latest release it still shows 7096 | 15:06 |
mo__ | getting same thing | 15:06 |
mo__ | The wClient connection to the server was NOT successfully established | 15:06 |
nowen | mo__: can you check the code and see if the passphrase is correct? | 15:07 |
mo__ | yes | 15:10 |
nowen | hmm | 15:11 |
mo__ | not sure if i canged it to something else | 15:11 |
mo__ | i will change it then test it. | 15:11 |
nowen | you can test it on the command line | 15:11 |
nowen | https://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid | 15:12 |
nowen | use the localhost one with the passprhase from the file | 15:12 |
mo__ | i can't get out of the edit mode :q does not seem to work | 15:20 |
nowen | hit the esc key a few times | 15:20 |
mo__ | did not work | 15:20 |
mo__ | disconnected | 15:21 |
mo__ | now reconnecting | 15:21 |
mo__ | that worked | 15:22 |
mo__ | password is not an issue | 15:22 |
nowen | great | 15:22 |
nowen | mo__: you're soon to master Linux! ;-) | 15:22 |
mo__ | lol... i wish | 15:24 |
mo__ | still can't connect to adduser.jsp or example.jsp though | 15:24 |
mo__ | still getting | 15:24 |
mo__ | The wClient connection to the server was NOT successfully established | 15:24 |
nowen | oh - I thought you had it working :( | 15:25 |
nowen | can you check the WiKIDAdmin logs? | 15:25 |
nowen | but it is either going to be the passphrase or maybe there's an extra space or carriage return in the file | 15:26 |
mo__ | 2015-03-17 11:05:38.813 ERROR com.wikidsystems.client.wClient ERROR: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate | 15:29 |
mo__ | 2015-03-17 11:05:38.804 ERROR com.wikidsystems.server.wAuth Couldn't validate the client certificate. Verify the validity and dates of the client cert. | 15:29 |
mo__ | i may have to redo the cert | 15:30 |
nowen | go ahead and create a new local host cert | 15:30 |
mo__ | done | 15:32 |
nowen | restart wikid and try again | 15:32 |
nowen | Mark____: here's what I don't get, if I register nowen via example.jsp and then go and add a token to NOWEN, it all goes on nowen | 15:34 |
Mark____ | so if you register nowen then two days later register NOWEN and then two days later register NOwen do you get the same results? | 15:36 |
Mark____ | remember we use self registration and on our end we overcame the caps issue | 15:37 |
Mark____ | just not sure in your DB it is differentiating between all the different variables someone may register with | 15:38 |
mo__ | same thing | 15:39 |
mo__ | here is the error | 15:39 |
mo__ | ERROR: java.io.IOException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded | 15:39 |
nowen | mo__: hmm | 15:40 |
nowen | Mark____: I mispoke. the user shows up as NOWEN, nowen and NoweN, but the license count doesn't change | 15:42 |
nowen | mo__: can you run both the keytool commands? | 15:42 |
nowen | from https://www.wikidsystems.com/support/wikid-support-center/troubleshooting-faq/how-do-i-know-if-my-certificate-is-valid | 15:43 |
nowen | Mark____: is it something besides just caps? | 15:44 |
mo__ | ok i ran both | 15:47 |
nowen | any errors? | 15:47 |
mo__ | i don't see any | 15:51 |
mo__ | do i need to recreate the cert just in case a typo was introduced to teh password | 15:55 |
nowen | for the localhost? | 15:55 |
mo__ | no the intermediate | 15:56 |
nowen | the example.jsp only uses the localhost | 15:57 |
mo__ | same thing | 16:06 |
nowen | ok - let's set up a teamviewer session | 16:07 |
mo__ | 417 541 466 | 16:15 |
mo__ | 5050 | 16:15 |
Mark____ | Nick i think it is only caps | 16:17 |
nowen | ok | 16:17 |
Mark____ | when i manually sorted the report that is all i removed | 16:17 |
nowen | mo__: got to update to 10 | 16:18 |
mo__ | me or you? | 16:18 |
nowen | me | 16:18 |
mo__ | ok | 16:19 |
nowen | ok | 16:19 |
nowen | Mark____: what function did you use to count? | 16:33 |
Mark____ | so i did it two ways | 16:36 |
Mark____ | i highlighted column a then went to remove duplicates | 16:36 |
Mark____ | and the other process was i manually went through each line manually removing uplicates | 16:37 |
Mark____ | duplicates | 16:37 |
Mark____ | then it is simply a matter of counting the lines left which excel handles | 16:37 |
*** mo__ has quit (Quit: Page closed) | 16:40 | |
nowen | Mark____: are you counting disabled users? | 16:43 |
Mark____ | i am not excluding them form the report | 17:44 |
nowen | so, we look at them as 'likely to be re-enabled' | 17:44 |
Mark____ | so you are stating if we had a nowen and Nowen and the Nowen was disabled it would count as 2 licenses? | 17:46 |
nowen | just looking at these, it seems like many are disabled and have no enabled devices | 17:48 |
nowen | these are users that are disabled | 17:49 |
Mark____ | I am not excluding them from my report | 17:51 |
Mark____ | the report Troy sent you is the same one i removed the duplicates from | 17:51 |
Mark____ | regardless if they were disabled or not | 17:51 |
Troy_SANM | i don't think 2 licenses should be consumed if 2 user has some enabled and some disabled devices | 17:52 |
nowen | when we run SELECT count( distinct( lower(userid) )) FROM test; we get 7096. If we remove disabled users we get 6529 | 17:53 |
nowen | there are users in this list with no enabled devices, they count as one license | 17:53 |
nowen | so, if you delete your disabled users - not devices, just users, we would show you at ~6530 licenses | 17:59 |
laszlof | ok cool | 18:46 |
laszlof | I can match that | 18:46 |
laszlof | no iOS token listed in there? | 18:47 |
laszlof | oh I see | 18:47 |
laszlof | it was doing something silly.. | 18:47 |
nowen | there's more | 18:48 |
nowen | stupid, let me send you the whole thing | 18:48 |
laszlof | lol. wrong window too | 18:48 |
laszlof | my bad | 18:48 |
nowen | np | 18:48 |
nowen | Sausage is being made! | 18:49 |
*** ricardoamaro (~ricardoam@drupal.org/user/74228/view) has joined #wikid | 19:40 | |
*** ricardoamaro has quit (Ping timeout: 240 seconds) | 19:48 | |
Troy_SANM | Nick.. how do I set the JAVA env variable over Oracle Java or default? | 20:33 |
Troy_SANM | isn't there a script? | 20:33 |
nowen | isn't it /etc/alternatives? | 20:33 |
Troy_SANM | the setenv.sh doesn't move it over | 20:34 |
nowen | does java -version show 8? | 20:35 |
Troy_SANM | yes | 20:37 |
Troy_SANM | but the JAVA_HOME is still showing OpenJDK | 20:37 |
nowen | and what's the problem? | 20:37 |
nowen | ok | 20:37 |
Troy_SANM | i don't want to start this unless it's pointing to the correct version | 20:37 |
Troy_SANM | or will the startup script correct it? | 20:37 |
nowen | yeah | 20:38 |
nowen | what is java home now? | 20:38 |
nowen | I mean exactly the path | 20:38 |
*** MO (4084d7c2@gateway/web/freenode/ip.64.132.215.194) has joined #wikid | 20:39 | |
nowen | As per echo $JAVA_HOME | 20:39 |
nowen | /usr/java/default | 20:39 |
*** MO is now known as Guest79795 | 20:39 | |
Guest79795 | hi nick | 20:39 |
Troy_SANM | didn't work | 20:39 |
Guest79795 | this mo again | 20:39 |
nowen | hi Mark____ | 20:39 |
nowen | hi mo | 20:39 |
nowen | Troy_SANM: 'echo $JAVA_HOME' didn't work? | 20:40 |
Guest79795 | so i just ran yum update on a machine rebooted worked fine | 20:40 |
nowen | mo - good news | 20:40 |
Guest79795 | then i deleted the snapshot | 20:40 |
Guest79795 | and rebooted and the kernel is now afued | 20:41 |
nowen | afued? | 20:41 |
Guest79795 | all f'ed up | 20:41 |
Guest79795 | kernel panic | 20:41 |
Guest79795 | any idea | 20:41 |
nowen | did you take a snapshot? | 20:41 |
Guest79795 | yea but then i deleted teh snapshot | 20:42 |
Guest79795 | as it was not needed | 20:42 |
nowen | why? | 20:42 |
Guest79795 | i use hyperv | 20:42 |
nowen | hyperv is a pain in the butt | 20:42 |
Guest79795 | not good to leave snapshots in place | 20:42 |
nowen | do you get an option to choose the kernel? | 20:43 |
nowen | Troy_SANM: echo $JAVA_HOME' didn't work?? | 20:43 |
Guest79795 | yes | 20:43 |
nowen | can you choose the oldest kernel | 20:44 |
Guest79795 | do i pick centos or wikid linux | 20:44 |
nowen | pick wikid linux | 20:44 |
Guest79795 | theres so many .el5 .el5pae .el5xen | 20:45 |
nowen | Troy_SANM: you can always set java home using export JAVA_HOME=/usr/java/.... | 20:45 |
Troy_SANM | i'm going to have to install b1821 first i think | 20:46 |
Troy_SANM | this went fine on my previous attempt | 20:46 |
Guest79795 | i see 2.6.18-274.3.1.el5 | 20:46 |
Guest79795 | i will pick that | 20:46 |
nowen | sure - keep notes as you may have to try them all | 20:47 |
Guest79795 | do i change anything | 20:47 |
nowen | just start by trying to find the old kernel | 20:48 |
Guest79795 | that version worked | 20:48 |
Guest79795 | it booted and i can login | 20:48 |
nowen | good - do not reboot the server again | 20:48 |
nowen | ever | 20:48 |
Guest79795 | ha ha ha | 20:48 |
nowen | not joking | 20:49 |
nowen | https://www.centos.org/forums/viewtopic.php?t=14786 | 20:49 |
nowen | we recommend against hyper-v | 20:49 |
nowen | you don't need to reboot linux like you do Windows | 20:50 |
Guest79795 | ok sometimes you can't help it it needs to be shutdown | 20:50 |
nowen | why? | 20:50 |
Guest79795 | if windows server reboot sometimes it may shutdown the server | 20:51 |
Guest79795 | i have it on save | 20:52 |
Guest79795 | but if it crahses for soem reasons it will have to be started | 20:52 |
Guest79795 | let me try that fix | 20:52 |
nowen | google up "hyper-v centos kernel panic" | 20:53 |
nowen | take a snapshot now that it is working too | 20:53 |
nowen | Troy_SANM: can you back up and tell me what you did/did differently? | 20:54 |
*** ricardoamaro (~ricardoam@drupal.org/user/74228/view) has joined #wikid | 21:20 | |
*** ricardoamaro has quit (Remote host closed the connection) | 21:20 | |
*** ricardoamaro (~ricardoam@drupal.org/user/74228/view) has joined #wikid | 21:21 | |
Troy_SANM | Hi Nick.. we upgraded to b1821.. tried to copy over the /private and bring it up | 21:22 |
Troy_SANM | now I get insuffient licenses | 21:22 |
nowen | did you delete any of the disabled users? | 21:22 |
Troy_SANM | copied from b1902 to b1821 maybe is the issue | 21:23 |
nowen | no | 21:23 |
Troy_SANM | i could not get b1902 to work | 21:23 |
nowen | most likely the users | 21:23 |
nowen | why not? | 21:23 |
Troy_SANM | You do not have sufficient user licenses. Used 33467 of 7100 allowed. Delete 26367 users or purchase another licence | 21:23 |
nowen | huh | 21:24 |
nowen | that's what you had on 1902? | 21:24 |
Troy_SANM | the java env variables never switched over | 21:24 |
Troy_SANM | after installing the java 8 rpm and setting the alternatives | 21:25 |
nowen | is it still java 6 or 7? | 21:25 |
Troy_SANM | openjdk 1.6 i think | 21:27 |
nowen | can you do a teamviewer session? | 21:27 |
Guest79795 | nick you still available | 21:47 |
nowen | yep | 21:48 |
Guest79795 | so i loaded the old kernel but i can't connect to wikid server | 21:48 |
nowen | hmm, it should have auto-started | 21:49 |
nowen | run 'wikidctl start' | 21:49 |
Guest79795 | no this one is different | 21:49 |
Guest79795 | auto start was not setup on this one | 21:49 |
nowen | this is a different server? | 21:49 |
Guest79795 | yes | 21:50 |
nowen | do you get an error when you start wikid? | 21:50 |
Guest79795 | no it starts | 21:51 |
Guest79795 | but i cant reach it | 21:51 |
nowen | not sure what that means | 21:52 |
nowen | can't get to the server or the page won't load? | 21:52 |
Guest79795 | page won't load | 21:52 |
Guest79795 | actually i can't ping the server | 21:52 |
nowen | run 'netstat -anp | grep 443' | 21:52 |
nowen | ping is blocked the firewall | 21:52 |
Guest79795 | no | 21:53 |
nowen | I mean that it is blocked at the firewall that runs on WiKID | 21:53 |
nowen | can you ssh to the server? | 21:54 |
Guest79795 | no | 21:54 |
nowen | run 'ifconfig' | 21:54 |
Guest79795 | i don't see any configured addresses | 21:56 |
Guest79795 | should i stop wikid server then rerun setup | 21:56 |
nowen | just run 'service network restart' | 21:56 |
Guest79795 | device seth0 does not seem to be present delaying initialization | 21:57 |
Guest79795 | failed | 21:57 |
nowen | hmm | 21:57 |
nowen | you mean device eth0 | 21:58 |
nowen | sounds like your hyper-v network is missing | 21:58 |
nowen | you can try to rerun setup. if there's no eth0, then it won'twork | 21:58 |
Guest79795 | is there a way to backup the data | 22:03 |
Guest79795 | just in case i need to rebuild the whole system | 22:03 |
nowen | cd /root | 22:05 |
nowen | tar -czvf wikid.backup.tar.gz /var/lib/pgsql/data/* | 22:05 |
Guest79795 | will have to pick up tomorrow | 22:10 |
Guest79795 | for not will make a backup | 22:10 |
Guest79795 | thanks. | 22:10 |
nowen | ok | 22:10 |
Guest79795 | thats a lot of backup | 22:13 |
Guest79795 | thanks | 22:13 |
nowen | np | 22:13 |
*** ricardoamaro has quit (Remote host closed the connection) | 23:08 | |
*** ricardoamaro (~ricardoam@drupal.org/user/74228/view) has joined #wikid | 23:13 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!