I have just set up a new test server with Confluence 6.0.7 and imported data from my existing server. This all went smoothly.
I have a Crowd directory that I use for authentication, and that also works fine... until I update the seraph configuration to enable SSO.
To be clear, I am NOT trying to log into a local account with SSO enabled; I know that doesn't work.
In the Confluence logs, I see this:
2017-04-25 19:14:25,654 WARN [http-nio-8090-exec-10] [atlassian.seraph.auth.DefaultAuthenticator] login login : 'ed.jackson' tried to login but they do not have USE permission or weren't found. Deleting remember me cookie.
However, I have debug information turned on in the Crowd logs, where I can see that it is successfully authenticating the user for the application.
Both my Confluence and Crowd servers sit in a private subnet, each behind its own proxy/load balancer. However, Confluence is configured to connect directly to Crowd on the private subnet.
I suspect the problem is one of the URLs in my crowd.properties file. What I have configured now is this:
application.name=confluence
application.password=xxxxxxxx
session.validationinterval=0
crowd.base.url=http\://crowd.internal:8095/
crowd.server.url=http\://crowd.internal:8095/services/
application.login.url=https\://wiki.mycompany.com/
To reiterate, the directory sync works fine using the same Crowd URL. Likewise, the Crowd login works fine if I don't have SSO enabled.