This is my first go with Atlassian products. I have setup Jira, Confluence and Bitbucket to point to our local domain AD. All of that works fine.
I know Crowd supports SSO. But right now I only have it working for accounts that are in the local AD domain. We have a number of AD domains in a trusted forest that I want to use. Is there a way, and if so, how, that I can authenticate across all of the domains in our AD forest? For example, we have domains like us.co, ca.co, eu.co, that all are in a trusted AD domain forest. I want to set it so that user1@eu.co can authenticate and user our software in the us.co domain.
Do I have to setup different ldap directories for them in addition to my us.co connector? If so, what user account do I use to authenticate to that domain? The point of having a trusted forest is that in AD we can see other domain users and we can login to each other's domains using our own local domain accounts (e.g. I can logon to a ca.co workstation using my user1@us.co credentials). Of course, we don't have administrator credentials on each other's domains, that defeats the purpose of the trusted domain scheme. So how can I incorporate all of our trusted domains into our Crowd authentication so that everyone in all of the domains in the forest can use our software?
Thanks in advance!