Most Corporate LDAP directory directories do have the following rule: when an employee leaves they disable the user account for a specific number of days (usually 30 or 60) and after this his account is arhived, which means it will not be visible to any normal LDAP queries.
If I am not wrong now CROWD connector has two major problems:
* If the user is disabled in LDAP, the user will appear as active in the directory, so jira users will continue to assign issue to him or expect him to act. Surprise he is already in permantent vacation!
* When the user is finally removed from LDAP, crowd will remove the user from the directory so Jira and Confluence will start to behave very strange (even breaking in some cases), because as you may expect this used can still own filter, tickets, pages, roles, asigneee, comments. And worse, people will not be able to find who it was because the email and full name are lost, only the login will remain in the system.
Am I true? How should we fix this?
I am not wrong, the only thing crowd should do is to disable users that are disabled in LDAP or not found. I a user reappers, it will just pe enabled. This means that group membership is not lost and also the other systems (jira, confluence,...) will continue to work correctly.