We've got JIRA 6.1 running with authentication delegated to LDAP, read only. We'd now like to add the latest Confluence version to the mix and it seems there are a couple options:
- Delegate Confluence user management to LDAP read only, with the same config we're using in JIRA
- This was the only option on older versions of Confluence/JIRA as discussed in the docs
- Since LDAP integration is read only, it may be simper to do it this way and avoid un extra service call everytime a user is authenticated (Confluence -> LDAP rather than Confluence -> JIRA -> LDAP)
- Delegate Confluence user management to JIRA, which is delegating user management to LDAP
- This seems to be possible on newer versions, as this diagram shows
- This would eliminate the need to configure LDAP twice
Is there a best practice for this? Are their additional strengths/weaknesses of each option?