There are two ways to setup partial Directory authentication in Jira but the differences between them are not quite well documented. Which are they?
- LDAP with local groups
- Internal with LDAP authentication
I am interested about ALL things that are different between this two types of setups.
I discovered few of them, but it is essential to know them all.
I know:
- On LDAP-with-local-groups if the user is not returned by the LDAP, Jira will remove all group memberships from the user, without providing any way to put them back, other than manually. I think that this can happen even when one of the delegated LDAP servers fail to repond (you get a partial response).
- On Internal-with-LDAP-auth nothing happens when the user is removed, still he will not be able to login obviously.
- Even if Jira nows have an "active" attribute attached to users, there is no way of changing this attribute based on what LDAP returns. Obviously, Jira LDAP settings should include an LDAP filter which extracts this information, there a