Hi all,
I'm running into an issue with a configuration that I want to put in place using Confluence's LDAP function. I'm relatively certain I must be missing something through sheer fundamental lack of understanding so hopefully someone can push me in the right direction.
Existing Configuration
At present I have a fully working LDAP configuration within user directories on Confluence 5.5.2. It is wide open and pulls all users and groups from our AD infrastructure using Confluence's "Read Only, with Local Groups" mode. All users can authenticate without issue, and all users are automatically added to the "confluence-users" group.
Intended Configuration
I have need of having a second group auto-populated, one I have created called "confluence-technicalstaff". This local group has permissions assigned to it. My wish is to have all users within AD that have a specific group membership added to this group as well as "confluence-users" and all staff NOT in that same specific AD group added JUST to "confluence-users" as normal.
What I have tried
To the above end, I created a second user directory profile with almost identical settings but under User Schema Settings I altered the user object filter. I used the following
(&(objectCategory=Person)(sAMAccountName=*)(memberOf:1.2.840.113556.1.4.1941:=CN=ADGroupName,DC=domain,DC=local))
The filter has been verified as working and returning the users I want via LDP.exe and is a fairly basic filter, so I didn't expect any issues. I set the default group memberships for this directory profile to add users fitting the criteria to "confluence-technicalstaff,confluence-users" to encompass both groups.
My understanding was that all I would need to do is save the above config and then shift the priority of this new directory profile higher than the existing one. Users fitting this would then authenticate against the top profile and would get those two new group memberships the first time they logged in. As I appreciate this only happens the first time they log in, I manually added the members I wanted to the new "confluence-technicalstaff" group to ensure the initial population was done.
What happened
Everything on the second directory profile saved fine, but when I shifted it above the existing working directory profile in priority everybody logged in with an AD account lost all permissions; everyone. Lowering it below the original directory profile instantly ensured that everyone got their permissions back.
I did some hunting and found this Atlassian Answers post which detailed a similar answer and the user had kindly posted a response to their own question, highlighting that duplicate group names were responsible. As the symptoms were identical I decided to work with this and see about filtering the groups too.
I first tried just putting a random base DN string into "Additional Group DN" in LDAP Schema to eliminate the ability for the second profile to pull ANY groups. This failed the checks on save so I reverted it.
Instead I tried using a filter within "Group Schema Settings" to allow my new profile to pull only one group. I used the following:
(&(objectCategory=Group)(CN=ADGroupName))
In the original directory profile I then used the following:
(&(objectCategory=Group)(!(CN=ADGroupName)))
I thought that this would ensure that my new profile could pull ONLY that one new AD group of note, and the existing profile would then be able to pull everything EXCEPT that one new AD group of note. The second example works fine on the existing directory profile to eliminate the new group, but the first code does not work, failing the extended checks upon saving.
Out of ideas!
I'm now just about at my wit's end. I can't think of why the above wouldn't work and must assume there's a fundamental limitation within Confluence somewhere that I don't know about. Has anyone had cause to carry out work like this before, or need to set up something similar with two different directory profiles pointing to the same directory service but with different filters for a similar purpose?
Help me Obi-Wan Atlassian Answers, you're my only hope!