Hello, I'm considering upgrading to 4.3+ and enabling proper LDAP integration. Currently we use an SSO solution, but osuser.xml is also set up to authenticate against the directory.
A fairly common support request is people trying to add a user to a role, but they can't find the user. The solution is to get the user to hit jira once which will create their account automatically, but if we enable proper LDAP integration this won't be necessary. Similar issue with user custom fields.
I have got it to work with local groups, with a reduced page size, the problem is that even the incremental synchronisation takes 20 minutes, and I am vaguely worried about performance problems of both jira and the ldap server (more the former). It's possible though that I could reduce the sync interval to once every 24 hours.
There are 47,000 users imported, and I'm not able to reduce this by using a narrower LDAP query.
So my question is does anyone else do this successfully, or has anyone else tried and had to stop? Are there better alternatives, such as copying the user on first login?
cheers, jamie