I am using Confluence 5.8.10 and Crowd 2.8.3 running on Ubuntu 14.04.3.
In the Confluence Internal Directory, I have just a single user defined named 'atlassian'. 'atlassian' is also an admin user.
In Crowd, I have a another user named 'ericg' in both the confluence-users and confluence-administrators groups. I have an application named 'atlassian_confluence' and in the groups tab I see both confluence-users and confluence-administrators. In the authentication test for atlassian_confluence, ericg passes the authentication test.
If I return to Confluence and go to the User Directories, the order of the directories is (0) Confluence Internal Directory and (1) Crowd Server. If I test the 'ericg' user with the (1) Crowd Server directory, the authentication test is passed. The (1) Crowd Server is fully synchronized.
I can log into Confluence using the 'atlassian' and 'ericg' user without any problems.
My /opt/atlassian/confluence/confluence/WEB-INF/classes/seraph-config.xml file contains:
<!-- Default Confluence authenticator, which uses the configured user management for authentication. -->
<authenticator class="com.atlassian.confluence.user.ConfluenceAuthenticator"/>
<!-- Custom authenticators appear below. To enable one of them, comment out the default authenticator above and uncomment the one below. -->
<!-- Authenticator with support for Crowd single-sign on (SSO). -->
<!-- <authenticator class="com.atlassian.confluence.user.ConfluenceCrowdSSOAuthenticator"/> -->
So far, so good.
So, now, I would like to enable Single Sign On for Confluence, but am having problems. I follow the instructions at Integrating Crowd with Atlassian Confluence.
I change seraph-config.xml to:
<!-- Default Confluence authenticator, which uses the configured user management for authentication. -->
<!-- <authenticator class="com.atlassian.confluence.user.ConfluenceAuthenticator"/> -->
<!-- Custom authenticators appear below. To enable one of them, comment out the default authenticator above and uncomment the one below. -->
<!-- Authenticator with support for Crowd single-sign on (SSO). -->
<authenticator class="com.atlassian.confluence.user.ConfluenceCrowdSSOAuthenticator"/>
My /opt/atlassian/confluence/confluence/WEB-INF/classes/crowd.properties file looks like:
application.name atlassian_confluence
application.password <<password>>
application.login.url http://localhost:8095/crowd/console/
crowd.server.url http://localhost:8095/crowd/services/
crowd.base.url http://localhost:8095/crowd/
session.isauthenticated session.isauthenticated
session.tokenkey session.tokenkey
session.validationinterval 5
session.lastvalidation session.lastvalidation
I am certain my application.name and application.password are both set correctly.
However, now I can no longer log into Confluence with either the 'atlassian' or 'ericg' user. What especially surprises me is that the 'atlassian' user no longer works. Why would that be?
I do stop and start the Confluence service while editing the seraph-config and crowd.properties.
What am I doing wrong?
I do also have JIRA and Stash installed and SSO w/Crowd works perfectly with both of them.
If further details are needed, please let me know.