Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

add LDAP directory for authentification only in JIRA

SherryX
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 14, 2012

we currently use jira user management and all users are added/updated in jira (jira internal directory).

Now I try to add LDAP directory but like to use it only for authentification.

If I add a new directory with delegated LDAP authentification (to be the second directory), then all the existing users will still use the existing password in jira (not password from LDAP).

But if I change the order of the directories, existing users can use LDAP password but will lose existing groups and memberships in JIRA.

Can I copy all the users in "jira internal directory" to "delegated LDAP authentification" directory, so I can remove internal directory and use only "delegated LDAP authentification" directory instead?

1 answer

1 accepted

0 votes
Answer accepted
Gregory Sudderth
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 17, 2012

I had this very same problem, but in a limited sense...I had myself in the internal directory, and I was also out on LDAP too. Well of course when I changed my password on the LDAP side I couldn't get in. I had to delete myself and add myself...but that's a big problem when you have issues etc.

So, I had to park the issues on a bogus user, delete myself, add myself (with delegated) and move the issues back.

Clumsy but totally functional. The only twist was the closed issues had to be dealt with seperately (bulk move vs. edit).

G.

SherryX
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 19, 2012

Thanks, Gregory. If only one or two users, it should be allright, but I need to move all users (more than 1000), I guess there should be a better way. This is a testing upgrade (4.2.2 to 4.4.4) in the test instance, so I think maybe I need to get OSUSER.xml (with LDAP config), copy to WEB-INF/classes and then re-start jira.

I'll try and let you know if that works. Thanks for your information.

SherryX
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
March 3, 2012

Gregory, I could not make LDAP work yet. Your solution did work, just not easy for bulk move(many users).

Thanks

Suggest an answer

Log in or Sign up to answer