I am struggling to integrate LDAP with confluence.
I am using the following main configuration:
- OpenLDAP
- LDAP Permissions: Read/Write
- Groups: posixAccount + posixGroup
The problem I'm facing is that the users and groups are transfered without a problem, but the memberships are not set.
I managed to get it to work with groupOfNames as the group scheme. The only case it works is if a group membership is defined inside the user (memberOf attribute) and the setting "Use the User Membership Attribute" is set. If either of these is not set there is no user-group assignment.
As posix is more widely supported (especially by LDAP user managers like LAM or Webmin) I would like to use it as my LDAP scheme and would prefer not to add attributes manually (would not be supported by user managers). Also this scheme is just using the username as an identifier (memberUid: username instead of members: uid=username,ou=People,dc=domain,dc=domain)
So my questions are:
Is there a possiblity to syncronize group memberships with the posixGroup scheme?
Is it sufficent if the members of a group are just set in the group entry (memberUid)?
Is it sufficent if a user is just defined by their uid and not by there complete DN?