Good Afternoon everyone,
As the title says I have been working on a way to migrate users from one LDAP directory to another in the new 5.1.
Reason:
The reason I am doing this is because when I upgraded JIRA to the new 5.1 the OSuser.XML file did not update correctly. I read that if this happens and you have multiple LDAP directories written remove all but one. I follow these instructions and it worked. I kept the main LDAP directory used by 90% of our staff (icf-hq). After the install I edited the OSuser.xml file back to the way it was thinking happy thoughts and high fives to myself
.
A few weeks later Users using the icfi domain (the other domain we use) could not login. Turns out after working with JIRA support that the OSuser.xml file is no longer reconized.?.?!?!? FINE OK, so I created a ICFI Directory in the JIRA GUI thinking that would resolve the issue..Nope. Since the XML file didn't upload correctly JIRA placed those users in either the ICF-HQ domain or Internal JIRA. *Face-Palm*
I then began searching for a way to manually move users from 1 Directory to another using the GUI and yep you guessed it, not possible. (JIRA support, if you read this, this is a HUGE HUGE issue and needs to be resolved ASAP. Not being able to move users individually from one directory to another is a BIG problem. If a user is assigned to a directory and their account gets migrated they can no longer login because JIRA can not find their account.) The only way that Suport and I found to fix this issue was to set the ICFI Directory to copy user and add them to jira-users group. (What this does is if a user is in the wrong directory and when he/she tries to login it makes a copy of the account and moves it to the correct Directory making sure it has jira-users group permissions)
This is fine for 1 or 2 people but my problem is much worse. At some point we are planning to migrate all 600 people from the ICF-HQ AD to the ICFI AD. This is a Company migration that is out of my controle. That means all users that were using the ICF-HQ domain would no longer be able to login to JIRA. The bigger issue is that it's not going to be everyone at once but 100 - 300 users at a time. So I can't just use the migration tool built into JIRA. (JIRA Support, if you edited that tool to let you choose people individually that would be the perfect fix in my opinion).
SQL Solution:
OK, so i did some more research here is a link I used to fix the problem. https://jira.atlassian.com/browse/JRA-24213
Here are the directions I made:
Moving Users from 1 directory to another using SQL.
!!!!!!MAKE A BACKUP OF YOUR DATABASE BEFORE DOING THESE STEPS!!!!!!
1. User has already been created and we are moving him/her from the old directory to the new directory.
2. Login to JIRA database.
3. Open dbo.cwd_user (note that the user directory_id is going to be the old ID number in my case 4, that number needs to change to the new directory_id 10000).
4. Open dbo.cwd_membership (note that the user directory_id's will have the old directory_id # 4. Those numbers will need to change to the new directory_id # 10000).
5. First script that needs to be run is the..
update dbo.cwd_user set directory_id=<Your ID Number> where USER_NAME='<USER NAME OR ID>';
This script will move the user from the old directory_id to the new directory_id. (meaning it will move the user from the old LDAP directory icf-hq to the new LDAP directory icfi). If you go back to the dbo.cwd_user table and hit the execute button you will notice that the directory_id number has changed to 10000.
6. Now you will need to move all the internal groups that were assosiated with that user to the new LDAP directory.
update dbo.cwd_membership set directory_id=<Your ID Number> where child_name='<USER NAME OR ID>';
This script will move all the groups for that user to the new LDAP directory. If you go back to the dbo.cwd_membership table hit execute you will see the directory_id's have changed to the new directory number 10000.
7. Now that you have moved the groups over you need to change the parent ID of each group to the new directory parent ID. you will need to run this script for each group changing the parent_id number and the parent_name alias. If you don't you will not be able to remove these groups from the users account.
update dbo.cwd_membership set parent_id=<Your ID Number> where parent_name='<Your Group Name>' AND child_name='<USER NAME OR ID>';
update dbo.cwd_membership set parent_id= <Your ID Number> where parent_name= '<Your Group Name> ' AND child_name='<USER NAME OR ID>';
update dbo.cwd_membership set parent_id=<Your ID Number> where parent_name='<Your Group Name>' AND child_name='<USER NAME OR ID>';
8. Now you will need to reset the JIRA service on the server.
Note: NEVER EVER EVER EVER change the User membership parent ID for JIRA-User!!!!!!!!!!!!!!!!! If this is changed the user will NOT be able to login. I thought this would need to get moved over also but just doesn't work. It wont allow the user to login.
9. Load the dashboard and try to login.
I was able to get that user moved from the old directory to the new directory, along with his groups, and was able to login with no problems. I have only tested this is stage for one user so I need to do some more testing before production but this should help those in my situation.
Let me know if you have any questions reguarding this subject. I'll do my best to answer.
Greg