Hi,
Running Confluence 6.2 on Centos6, connecting via LDAP to a Active Directory domain.
We have an issue with Confluence (JIRA also seems affected by this as well) where we are unable to mention (i.e. '@<username>' in comments section) a certain newly created domain user. Normally when typing '@' and then other characters it suggests users from the domain. New users do not seem to appear as any of the suggestions, although older users do. When you go to Users>Find a User (user mgmt) the new user does not appear. If the new user logs in to Confluence (using AD account) the account then appears in 'find users' but when the LDAP directory is synchronised, it is removed from the cache and searches once again are unable to find it.
What I've noticed is if I restrict the LDAP directory to a specific OU in 'Additional User DN' field (the one that actually contains the new user account) and resync LDAP, it clears ~19500 users from cache (and adds others), after which the new user's account appears in the list of users. Also, after this, mentioning using '@' works as expected.
It seems the LDAP directory is hitting a some sort of limit and not returning all users in the entire directory. Is there a limit to the number of users LDAP will return? I've found no obvious way of configuring this. The options appear to be:
- Enable the Confluence LDAP user directory to find all users in Active Directory by changing limit
- create some sort of filter so it restricts the returned users to a paricular group or OUs (unfortunately users could be in multiple OUs)
I'm looking at https://confluence.atlassian.com/kb/how-to-write-ldap-search-filters-792496933.html but I'm not entirely sure where to define these filters.
Cheers,
Tim