Hi
We've configured a Jira user directory as an Active Directory in Read/Write mode. The username attribute of the Jira directory is set to "userPrincipalName" - because this will be the e-mail address of the user.
When a user signs up for our Jira Service Desk, the account is written to the Active Directory. The sAMAccountName is set to the same value as userPrincipalName. In general this is good, because sAMAccountName is mandatory. But the issue starts if the user has an e-mail address longer than 20 characters. The account will not be created, because this is a hard limit in Active Directory.
https://docs.microsoft.com/en-us/windows/win32/adschema/a-samaccountname
The following error message is in the Jira log:
Could not create user: verylongusername@example.com
com.atlassian.crowd.exception.InvalidUserException: Uncategorized exception occured during LDAP processing; nested exception is javax.naming.NamingException: [LDAP: error code 80 - 00000523: SysErr: DSID-031A124A, problem 22 (Invalid argument), data 0
Questions:
- Why does Jira the sAMAccountName not truncate to 20 characters? Is there an option to enable this?
- Is there a possibility to set the sAMAccountName to something different never exceeding 20 characters, like an internal Jira user id?