Hello everyone, how did you ensure you could run your companies authentication and user management with the JIRA system? What do you all use, LDAP, active directory, something else?
All of them, I've seen JIRA hooked up to all sorts of user directories. I've even seen it use a non-directory method, where certificates were handed out. Of course, most organisations have some form of LDAP (that includes AD, same basic idea).
What you mean by handing out certificates? Using some kind of software certificates from a pki?
Both is some sort of a remote user management isn't it?
Yup. JIRA was not hooked up to a directory (like it is with LDAP and the others). Imagine it more like having a swipe-card (certificate) to your office (JIRA). Present the card and it goes "Ah, you can come in"
But when using a swipe-card or a smartcard the user management is done by the pki system rather than the JIRA system? In that case how does JIRA knows which user shall be logged in and which user role or which user group he or she belongs to?
Anyhow it seems that you need a plugin which will handle the communication and authentication with the ldap system or the pki system?
We run everything off our enterprise AD and wrote a couple big LDAP filter queries that starts with the department-wide AD group to pull in all users, then recursively goes through all their group memberships and pulls all those groups in. We then piggyback Confluence off of the JIRA user directory. This allows us to have identical users and groups so we can permit and restrict information easily across both systems using our already established AD groups instead of building local groups in JIRA. The only local groups we use are the three built-ins, jira-users, jira-developers, and jira-administrators.
@Paul Thanks for the detailed description.
It looks like you're new here. Sign in or register to get started.