The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Problems with Active Directory

ket.pjwstk
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
September 21, 2011

Hi,

Our goal is to retrieve one group of users with all members and our configuration looks like:

Base DN O=some dn

Additional Users DN /left empty/

Additional Group DN:cn=group_name,cn=groups

And everything is almost fine, because we get group with members, however with also get all users that are not members of any group. And thats a prboblem, because there are ~38k of such users in given AD instance.

2 answers

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

1 vote
Answer accepted
JamieA
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
September 21, 2011

You need to set the user object filter under "user schema settings". There you need to filter for only users that are members of your group... using the memberOf attribute.

Eclipse directory studio or JXplorer is useful for testing this stuff.

ket.pjwstk
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
September 22, 2011

I've done as you wrote and it helped. Ie. I got specific group with users, however I get the following error:

INFO] [talledLocalContainer] com.atlassian.crowd.exception.OperationFailedException: org.springframework.ldap.InvalidNameException: CN=Deleted Objects,null: [LDAP: error
code 34 - 0000208F: NameErr: DSID-031001F7, problem 2006 (BAD_NAME), data 8350, best match of:
INFO] [talledLocalContainer] 'CN=Deleted Objects,null'
INFO] [talledLocalContainer] ]; nested exception is javax.naming.InvalidNameException: CN=Deleted Objects,null: [LDAP: error code 34 - 0000208F: NameErr: DSID-031001F7,
problem 2006 (BAD_NAME), data 8350, best match of:
INFO] [talledLocalContainer] 'CN=Deleted Objects,null'
INFO] [talledLocalContainer] ]; remaining name 'CN=Deleted Objects,null'

JamieA
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
September 22, 2011
0 votes
Amit Girme
July 11, 2013
Temporary solution is remove incremental synchronization check box. Atlassian working on it https://jira.atlassian.com/browse/CWD-2581 Hopefully it wont take long.
TAGS
AUG Leaders

Atlassian Community Events