Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Changed LDAP directory, cannot access Application Access page to change Groups

clementinebuschtetz September 9, 2019

I changed my LDAP server (different IP address, different users/groups), and now I cannot access the Application Access page to modify the groups in Jira.

I am getting an error saying that one of my "old" groups does not exist anymore, and the only available button is "Refresh", when I click on it, it brings me back to the error page.

I am not sure what to do ..

1 answer

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 10, 2019

Hi,

I understand that your LDAP server recently changed it's address and since that time Jira is unable to change group access.

First, I want to make sure that you can login to Jira as an admin account.  It might be necessary to use a user that comes from the internal user directory instead of the LDAP network.  If you don't have such an account yet, there are steps in Retrieving the Jira Administrator, as to how you can add this kind of localadmin to your system.

Once that is done, I would want to make sure that the user directory in Jira is setup correctly.  You can do this by going to the Cog Icon -> User management -> User Directories.  From this page you can edit the LDAP entry there and update the address or credentials that might have changed there.  Once this is done and saved, the Jira should be able to sync those groups back over again correctly.

Try this and let me know if you run into any problems.

Cheers,

Andy

Luca Andreatta
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 13, 2020

Hi, we have quite the same issue, but this is caused by some groups renaming done in LDAP.

Now I cannot do anything in that page.

Is there a workaround?

Can I use some REST API to delete unexisting groups in the application access page?

Or can I delete them from the database?

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 16, 2020

@Luca Andreatta I would still recommend following the steps in Retrieving the Jira Administrator.  However in your case, you would have to first determine if there are any local system administrator accounts in Jira here (non-LDAP users).  If not, then you will need to create one.  That guide does have steps on how to do this.

If you have to create an account in the internal user directory, then you might also need to create the proper group as well.  This can all be done via SQL.  That guide does have steps you can follow to do this.

Once you can login as a system administrator, you can then adjust which other groups are granted access to login to Jira.

Andy

Luca Andreatta
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 16, 2020

Hi Andy, the problem has gone away yesterday. Maybe there were some jobs that removed the missing groups automatically.

Thanks for your answer.

Like Andy Heinzer likes this

Suggest an answer

Log in or Sign up to answer