I have set up evaluation versions of Crowd, Jira, Stash, and Confluence. Everything seems well and good between the services for my user account, which I've been using for testing. Crowd connects to LDAP correctly, and the other three services use Crowd's SSO to manage users. Where I get a bit lost is in allowing new users (who have valid LDAP credentials) to access the services.
I have Crowd set to add new users to confluence-users, stash-users, and jira-users as soon as they log in for the first time.
The first time user BOB1 visits Stash, he logs in, and Crowd verifies his credentials. When Crowd sends him back to Stash, Stash says "You do not have permission to access Stash". Apparently this is because Stash's view of the Crowd directory is out of date (by more than a few seconds) and hasn't been updated to reflect that Crowd has just added BOB1 to stash-users. Once I go into Stash and tell it to update the Crowd directory, BOB1 can then log in, but a manual update is obviously not the solution.
What is the proper way to allow each user to access the services as soon as they log in for the first time? Thanks in advance.