Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira LDAP integration

Marek Ochab December 10, 2018

Hello,

I am preparing to integrate jira with our Active Directory. Currently I am testing functionality on test enviroment and I have a few question

 

1. I have the same username on Jira Internal Directory and Active DIrectory.  I read this article:

"If you have the users in both directories using the same username, you can simply put the LDAP on the top in the User Directories screen, and JIRA will start to use it instead of the internal. The issue association is based in the username, so it will not be a problem.

If you don't have all internal users in your LDAP, take a look at the following link, it can be helpful:

https://confluence.atlassian.com/display/JIRA/Migrating+Users+between+User+Directories#MigratingUsersbetweenUserDirectories-Usingthe'Migrateusersfromonedirectorytoanother'functionality

 

It is work fine, but I am wondering what is going on with user in Jira User Directory when I "map" his from LDAP? (practically he is still exists in jira internal directory) This is enough or should I do something to match user (e.g to prevent double users)?

 

2. Is there any possible to match default jira groups? (I mean jira-software-users / jira-servicedesk-users, jira-administrators)? 

1 answer

0 votes
Thomas Deiler
Community Champion
December 10, 2018

Dear @Marek Ochab

1) Nothing will happen to the internal user accounts, they are just overlayed. This works only if the user name matches. In the end you have a fall back solution. If LDAP is down, Jira waits for the timeout and then asks the internal directory. So important message: Never place you admin account on LDAP, only.

2) I don't get you. Can you be more specific?

So long

Thomas

Marek Ochab December 11, 2018

I mean that I could not manage groups from LDAP which are currently exist in jira internal directory (default groups in internal directory like jira-software-users which give Jira Software access, etc. - same as Users LDAP-Jira Internal Directory) but after restart jira instance now I can manage them. Also I think I found "small bug" with LDAP groups. When I create group in LDAP and push synchronization, group will appear in jira, but when I remove it still exist until to restart jira instance.

 

Thanks for advice.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events