I may be wrong, but the current Crowd based SSO uses replication to move user information around from the Crowd server to the client servers (JIRA, Confluence, Stash, etc.).
What would be ideal is for every authentication check in JIRA, Confluence, Stash, etc., instead of checking the local replicated copy of Crowd, the application makes a network call to the Crowd server to see if the username/password/group is valid. This way the applications don't work with stale data until the next replication update. This would be like how other applicaitons use LDAP/AD/NIS/etc. for authentication.
Do I have my SSO mis-configured? Is this possible? If not, can the powers that be make it so? Thanks.
-Ernie