Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

[SOLVED] LDAP / AD group name not synchronized

Matthias Fleschütz
Contributor
August 21, 2018

We have a AD / LDAP User directory configured. It is working so far, also new groups and memberships seems to be synced at least after click on sync.

Due to AD re-org the names of groups have now changed, but these changes are not synchronized.

I read a lot about different issues, there is one question here very similar, but 2 years old and pointing to a non-existing issue.

Is there really no way to keep this in sync?

1 answer

0 votes
Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

I think sync should work - unless you've not reconfigured your filters.

Sync works best based on your own AD/LDAP Sync filters.

Obsolete groups synced already would be crossed out if not available in AD anymore - new one should sync back provided your filters are not blocking them.

Matthias Fleschütz
Contributor
August 21, 2018

Unfortunately it’s definitely not.

new groups are synced, but a rename of an already synced group is not causing the name of the group changing in Confluence.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

@Matthias Fleschütz Oh ! you mean you want the old groups to be RENAMED ?

Matthias Fleschütz
Contributor
August 21, 2018

Yes sure...it is called sync...not import ;-)

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

I'm not quite sure if that happens - it is sync in the sense that what is there in the AD shall show up on JIRA as well.

I have not seen a parameter in the AD Configuration - that would actually compare and replace entities based on old and new names.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

Sync - if there are 40 objects on AD , it would show up 40 in JIRA too ( based on filter)

Out of 40 - 1 gets a new name , JIRA syncs it - strikes the old name ( non-existent) - creates the new group.   JIRA will show 41 GROUPS now - but still 40 are active - the one with old name stays there but remains inactive.

That's how JIRA sync has been working as per my experience.

Matthias Fleschütz
Contributor
August 21, 2018

That’s strange as it is not behaving like this here. The number of groups stays the same and all renamed have still their old names.

Whi is Confluence doing it like you described anyway? All objects in LDAP / AD have unique identifying IDs. Why not just using these for mapping / updating?

It often seems that Atlassian is doing it in another way then everybody else...;-)

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

@Matthias Fleschütz Matthew - I'd just like to correct myself.  I was talking all the time about JIRA.

Ok - now getting back to Confluence. I just did a rename of Group in AD - reconfigured my GROUP Filter, my new group was created in Confluence and the old group removed as it is no longer in AD.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

Also - I hope you've changed the group name correctly in AD - both " Group Name " and " Group name ( pre-Windows 2000) "

Changing Group name ( pre-Windows 2000) alone won't work.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

I did a couple of quick changes - ran syncs and it worked perfectly fine.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 21, 2018

I hope your GROUP Filter is not blocking the new name from being synced.

Matthias Fleschütz
Contributor
August 21, 2018

Hi Vickey,

it was non of that...it seems that Confluence chocke itself with Incremental Sync Setting.

I just checked all settings back and forth: no change
Then I disabled Incremental Sync: all renamed groups were updated!
I enabled Incremental Sync again: a new test-rename was now synced...

What the hack...thanks a lot for your support.

Best,
Matthias

Steve Letch June 11, 2019

Hi @Matthias Fleschütz 

 

I have a need for something similar, we have 

  • (&(objectClass=group)(cn=jira))

Set up in our group object filter and a few of the groups are named "IT - blah blah" so dont have 'jira' in them and therefore arent synching.

 

So does it look like it should be as simple as renaming the AD group or will that just sync a whole new group down? Also the client I'm working at has a lot of validators so want to make sure they get broken by the existing group disappearing.

Matthias Fleschütz
Contributor
June 12, 2019

Hi @Steve Letch 

yeah look similiar to my issue...it was solved "magically" at some point after just changing things forth and back. Maybe some internal caching stuff...?

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events