The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Crowd Connector to AD

lilachFeit
August 10, 2016

Hi

i'm trying to connect my Crowd server to the company AD, i'm always getting 'authorization fail'.

Does the user I've entered in the connector must be an Admin on the AD container (OU)? (or READ permissions are enough?)

Also, the AD guys told me that the connection to the AD must be with Kerberos Ntlm protocol, Does Crowd supports that? (or there is no way i'm connecting it to our organization AD)

 

Thanks.

3 answers

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

1 vote
Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 10, 2016

The user that you set while configuring the connector does not have to be an admin. Any standard user with read rights is enough.

The AD connector in Crowd uses standard username/password authentication for LDAP (or LDAPS). Though it is not supported by Crowd, LDAP requests to Active Directory can also be authenticated with Kerberos but I would be very surprised that your organisation forbids standard username/password LDAP (or LDAPS) authentication.  

lilachFeit
August 11, 2016

Hi

Thanks for the quick answer, can you please explain what i need to do to authenticated with Kerberos while defining my connector?

(do i need to change my url from "ldap://...." to something else?)

 

Thanks!

Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 11, 2016

Hi @lilach feit,

You can't do that as it is not supported by Crowd. As of today the LDAP connector in Crowd only allows you "bind" to AD with a username/password, not with a Kerberos ticket.

0 votes
lilachFeit
August 10, 2016

Hi Steve, 

It needs to be KERBEROS protocol 
NTLN is blocked in our network. 

Does Crowd supports KERBEROS protocol ? 
If so, please let me know what is the configuration required ?


Thanks. 

0 votes
Steve Behnke [DiscoverEquip.com]
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 10, 2016

Can you explain the requirement again? The connection between crowd needs to be Kerberos/NTLM?

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

TAGS
AUG Leaders

Atlassian Community Events