Setting up LDAP in Crowd for authentication only but "User Group Attribute" is required by setup screen. Our LDAP schema doesn't seem to have memberOf attribute and we wouldn't be using it anyway.
Is there anyway to work around this?
Hi Lars,
It looks like you have a Posix based LDAP schema, could you try using one of the Posix based LDAP configurations in Crowd.
Also make sure that you have the "Use the User Membership Attribute" un-ticked on the Connector tab. Here is the specific documentation related to OpenLDAP directories that have a Posix Schema.
http://confluence.atlassian.com/display/CROWD/OpenLDAP+Using+Posix+Schema
Crowd also has a more generic, Posix Schema configuration:
http://confluence.atlassian.com/display/CROWD/Posix+Schema+for+LDAP
Cheers,
Justin
Could you please try to use "dummyValue" into your "User Group Attribute" field and ensure that "Group Members Attribute" is valid.
This would force Crowd to use the membership mapped by the groups instead of LDAP users. Please try the above suggestion and let us know how it goes.
Septa Cahyadiputra
Where would I find "group members attribute"? Are you referring to something in our LDAP schema or a setting in Jira?
You could find the mentioned field under the "Group Configuration" section for Crowd, and "Group Schema Setting" for JIRA.
As mentioned earlier, if the mapping of the membership is configured under the groups, you should be able to configure it here, and using "DummyValue" as the "User Group Attribute" value would force Crowd to use only this parameter to retrieve all the necessary membership from your LDAP server.
Hope it helps.
What object classes do your Groups and Users implement? Could you give us a sanatised snippet of your LDAP schema as an LDIF for example, so we can give you the best answer possible.
Here is the schema for users:
dn: dc=people,dc=internap,dc=comobjectclass: organizationalUnitobjectclass: dcObjectobjectclass: topdc: peopleou: peopledescription: user accountsdn: uid=barack,dc=people,dc=internap,dc=comobjectclass: personobjectclass: inetOrgPersonobjectclass: organizationalPersonobjectclass: posixAccountobjectclass: topcn: Baracksn: Barackuid: barackgecos: Barackgivenname: Barackmail: barack@internap.com
...
Could you please provide us the sanitized LDIF of one of your group. What we are looking is the "member" or "uniquemember" parameter where you configured the meber of the particular group.
I hadn't initially planned to use groups since I am using Delegated Authentication Directory seutp but pulling users out of a specific group will be helpful.
dn: cn=stooges,ou=unix,dc=internap,dc=comobjectclass: posixGroupobjectclass: topcn: stoogesmemberuid: curlyhowardmemberuid: joebessermemberuid: joederitamemberuid: larryfinememberuid: moehowardmemberuid: shemphoward
It looks like you're new here. Sign in or register to get started.