Hi,
I have the following problem: my Jira 8.13 DC is stuck on the user directory sync (LDAP). It happened twice already, right now it is stuck for 5 days. At first time reboot helped, but only for 3 days. Sync interval is set to 10 minutes and it worked for years.
It happened also on some of dev instances with the same LDAP server connected, but at different times. When I start the sync on any dev instance that is not stuck, the sync finishes in the usual time.
Logs do not show any fail or warn, just start of the sync, few groups update and that's all. I enabled DEBUG level for Crowd and it shows that Jira connects to LDAP regularly, no fails observed during sync being stuck.
Existing users can log in and use Jira without problems, new users cannot because Jira does not update group membership obviously.
No changes were done in User Directory configuration in Jira itself, nor any changes in LDAP configuration.
I have no idea where I can look next, so I would be glad for any advice.
Also, do any of you know how to reset the sync without Jira reboot?
Thanks in advance,
Pamela
Hi @Pamela Strucker,
As per your description, I would bet on you having the Follow Referrals enabled on your user directory configuration and it would be making Jira point to different domain controllers or domains.
With that said, I would recommend disabling it if it is enabled and see if the issue persists.
Regarding the sync without reboot, I believe you can work around this by creating a fake user directory and deleting it. This will force the sync service to be restarted.
Hope it helps, please let us know your thoughts.
Hi @Artur Moura , thank you for the reply. Actually, I have this disabled, but in a meantime I contacted Support and they advised two things that helped:
* set up sync interval to default 60 minutes (we had 10 minutes, sync is done under 2 minutes),
* enable ldap timeout... I had it disabled.
I just confirmed everything working for the last couple of days.
I suspect that it was rather a timeout problem (it worked for years so I didn't question that - in hindsight, it should be changed as the first troubleshooting step). I won't return to 10 minutes sync intervals however, as it does not hurt us.
As for restarting sync, Support told me that only reboot works - I will definitely try the trick with the new user directory, just in case. Thanks for the suggestion!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Pamela Strucker,
Glad to know the support was able to help!
I agree with you, indeed the timeout was playing a role.
I believe the threads were not being closed after the sync and got stuck, causing the sync to fail.
Thanks for sharing your feedback here!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.