Hi,
I face the following challenge in our JIRA implementation:
We have a corporate MS Active Directory, that we have integrated with JIRA using the User Directory feature. This sync is configured as ReadOnly with Local Groups and is mainly meant to get all employees into the jira-users group.
So far so good. We have now the additional requirement, to have certain AD groups being also synced. As the users are already synced by the first user dictionary this would be mainly about the group membership. By creating now a second user dictionary of type "read-only" and setting respective filters on groups and users, expected this to happen. But actually I face the following:
* a group with the correct name is created
* the users are NOT assigned to this group.
Checking the application server logs I can see, that users and the respective memberships are selected, but no assignments are done. (Ie. I see no members in the groups assigned)
=> Would you say the approach taken (with 2 user dictionaries) should work or do you have any alternative proposals?
Here an extract from the logs:
2017-12-07 13:47:16,065 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [crowd.directory.ldap.SpringLdapTemplateWrapper] Timed call for lookup with mapper on cn=xxxx,ou=dl,ou=msx,ou=resources,dc=global,dc=corp took 60ms
2017-12-07 13:47:16,065 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [directory.ldap.cache.AbstractCacheRefresher] found [ 12 ] remote user-group memberships, [ 0 ] remote group-group memberships in [ 131ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DbCachingRemoteChangeOperations] synchronising [ 12 ] user members for group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DbCachingRemoteChangeOperations] internal directory has [ 12 ] members
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DbCachingRemoteChangeOperations] scanned and compared [ 12 ] user members from [ DL Dummy ] in [ 0ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] removing [ 0 ] users from group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] adding [ 0 ] users to group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] synchronised [ 12 ] user members for group [ DL Dummy ] in [ 0ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DbCachingRemoteChangeOperations] synchronising [ 0 ] group members for group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DbCachingRemoteChangeOperations] scanned and compared [ 0 ] group members from [ DL Dummy ] in [ 0ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] removing [ 0 ] group members to group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] adding [ 0 ] group members from group [ DL Dummy ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [atlassian.crowd.directory.DirectoryCacheImplUsingChangeOperations] synchronised [ 0 ] group members for group [ DL Dummy ] in [ 0ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 TRACE ServiceRunner [directory.ldap.cache.AbstractCacheRefresher] migrated memberships for group - (1/1 - 100.0%) 132ms elapsed
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 DEBUG ServiceRunner [directory.ldap.cache.AbstractCacheRefresher] Applied remote memberships in [ 132ms ]
2017-12-07 13:47:16,066 atlassian-scheduler-quartz1.clustered_Worker-3 INFO ServiceRunner [atlassian.crowd.directory.DbCachingRemoteDirectory] FULL synchronisation complete for directory [ 10201 ] in [ 376ms ]