We have an on premise Jira server instance which is configured to use native authentication. We also have several internally developed web applications that use Jira REST API for automation and data exchange with this Jira instance. There is a desire to move from Jira native authentication to Active Directory based authentication for a variety of reasons. Some stakeholders within my team have raised concerns that this approach would pose a security/privacy risk because now, the users of our internal web applications would be required to enter their Windows network credentials to authenticate with Jira and there is a possibility that these credentials would inadvertently or maliciously get logged to a debug or audit log, or somehow find their way into the wrong hands.
We also have some command line test scripts that are independent of the aforementioned web apps that also talk to Jira and would be in the same boat when it comes to LDAP authentication.
I am sure that this is not a new problem for many users on this community forum. My questions:
- If you or your company have been in this situation, how did you address it?
- Does Atlassian have a solution that would allow apps such as our internal web apps to authenticate against Jira (using LDAP) without “seeing” the credentials?
- Are there any third party tools on Atlassian marketplace or elsewhere that would take care of both the use cases above (web apps, as well as command-line scripts)?
Thanks,
Toni