I have setup a Delegated Active directory to the AD server using LDAP.
When the permission to 'Add/ Remove Group' is selected...
(i) Does adding a new group on this directory within Crowd create a local group in Crowd?
(ii) does Crowd get a read-only access to LDAP server?
(iii) Since I am not able to search and view the users or groups in LDAP, how can I create groups within Crowd and add users to it?
(What I am trying to do is create a delegated authentication directory and create/modify application-specific (jira/crucible/confluence) groups within crowd which will be the SSo for all the apps.)