Hi,
we are still running on Jira Server 7.6.
Our instance uses a read-only LDAP connection for all employees of our company. All external contractors are working with accounts created inside Jira Directory.
Since we have "external user management" turned on it is not possible to reset the passwords of the internal Jira users since the option does not appear. The only option we would have is to set a new password. This of course is not permissible since it is not GDPR compliant.
The only option for someone, who forgot his password, is to drop by the Admin's office to change his/her password in person. (=not very user friendly)
Is there an option to allow resetting a user password (Internal Jira Users only) while at the same time using an external LDAP directory?
If not. Was/is/will be this issue addressed in some later release?
Best regards
Marco
Hi Marco,
I understand that you are using both Jira's internal user directory AND an external LDAP for managing users that exist in your Jira application. Inside of Jira's Cog icon -> System -> General Configuration there is an option to edit various settings here. In your case, you have set the "External user management" setting here to On. The default value here is Off.
In your case, I believe this setting should actually be set to Off. If you review the Configuring Jira Application options documentation, it better explains this feature:
When turned ON, JIRA will not display options for users to change their password and edit their profile. This will also disable the Forgot your password link on the login page. Generally you would only turn this ON if you are managing all your users from outside JIRA (e.g. using Crowd, Microsoft Active Directory, or another LDAP directory) Default: OFF
With this setting to OFF, you LDAP users CAN still login and authenticate to Jira. The only downside here is that these users could potentially see things like the forgot password link in Jira. They won't actually be able to reset their LDAP login credentials via Jira, but it will be there.
It will also be there for the internal users that Jira can change the credentials for.
I think this setting name is somewhat confusing because administrators believe they need to turn this on in order to manager users in LDAP for Jira. In your case, since you have a mix of internal and external users, this setting should be left off.
Regards,
Andy
Thank you Andy for this concise answer.
This finally explained the setting. Our previous admin set it and I hesitated changing it.
Now everything works as expected.
best regards
Marco
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.