Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

is it possible configure two identical AD in Confluence

Davida February 24, 2022

Hello everyone

Today we have had a problem accessing the AD due to a certificate issue that we have solved by pointing to a second active directory identical to the first

We currently have two identical LDAP with distinct domains in our company and I wanted to know if we can configure both in our Confluence access as two directories in case one fails, use the other.

The confluence user would have to remain independent of which of the two domains/directories is accessed

Best regards

2 answers

2 votes
Radek Dostál
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 24, 2022

Authentication is first in order depending on where the user trying to log in exists. To make use of both ext. directories, each user would need to have an account in both of them.

So when you're logging in, Confluence "scans" directories top to bottom and authenticate you against the first match. This means that you will always be using the first directory you have your user in. Regardless of whether that directory times out or fails. The failover/redundant AD support is on the roadmap - https://jira.atlassian.com/browse/CONFSERVER-8867

I believe you would be able to set this up in Crowd, at least from initial looks, just not in Confluence out of box https://confluence.atlassian.com/crowd/configuring-directories-for-failover-authentication-890749126.html

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 24, 2022

This won't work - Confluence considers each directory you configure as a different source.  So even if they are the same, "directory 1: nic" would not be the same user in Confluence as "directory 2: nic"

You can't use Confluence's directories for directory fail-over (yet)

You need to do one of

  1. Implement failover recovery on the directories, not Confluence
  2. Use something that abstracts the directories away from Confluence 
  3. Wait for failover to be implemented in Confluence

Points 2 and 3 here are better explained by @Radek Dostál 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events