OK, so according to the crowd docco, you can import users and groups:
* From an LDAP directory to a Delegated Authentication directory.
* From one internal Crowd directory to another internal Crowd directory.
This is quite inflexible. One of the reasons we're moving with crowd is to move off our legacy, crufty ldap store to something saner. However, without the ability to sanely import from LDAP (delegated or no) into crowd this is not really possible, and thus negates much of the promise of Crowd.
For example, we use a delegted LDAP directory for auth, with many local groups in Jira. If I import from Jira, I get no users, and all the groups. If I use delegated LDAP auth in crowd, I get the users, but none of the groups. There seems to be no way to merge these for rationalisation and management.
Someone please tell me if I'm missing something here.