the user can log into other instances of jira (current version 7.7.1) all of which are setup with AD and LDAP in the same configuration. (e.g.: the user can log into our test and dev instance running the same version and configured identically as production). Cache on all browsers have been cleared.
Hi Eugene,
If I understand the problem here you have users in Jira that exist in an external directory, but that in this particular Jira instance, all the users that originate from that LDAP directory are unable to login to Jira here.
If the Jira configurations are truly identical, then my thought is that perhaps this dev instance of Jira has some different network configuration that could prevent Jira from correctly communicating with this LDAP server. If Jira cannot communicate with this LDAP, that would explain why Jira cannot authenticate these users. If this is the cause though, we should see errors in the logs of Jira when users try to login. Try navigating to the $JIRAHOME/logs/ folder. There is both a security log and an atlassian-jira.log that could potentially show us more information in regards to why this might not be working.
I would be interested to learn more about any specific errors that are generated in these logs at the time an LDAP user attempts to login to Jira here. These might tell us more about what the next steps are to troubleshoot this.
If we are still not getting a clear reason as to why this login is failing, I would recommend trying to follow the further troubleshooting steps listed in the KB: Unable to login to JIRA applications.
Please set com.atlassian.jira.login & com.atlassian.jira.login.security to DEBUG in Administration > System > Troubleshooting and Support > Logging and Profiling. Have the user (attempt to) login. Set those log levels back to the WARN so they don't spam the logs.
com.atlassian.jira.login
com.atlassian.jira.login.security
With DEBUG logging set for those two packages in Jira, the logs will provide much more information about why those logins are failing. I suspect you won't need to do the DEBUG logging steps to track down why this is happening, but I offer this as a set of next steps in case the first ones are not clearly indicating the problem here.
Andy
It is not the case that all users using the user directory service for ldap cannot login. It is that "one" user cannot login.
We identified in previous comment that there is an AD group called Contracts that has a similarly named group in a different domain called contracts (note the lower case first letter and that it is in a different domain).
The theory is that user changed her password and it attempted to sync the AD information for her and ran into this conflict as she is a member of one of these groups. It also was the case that on 4/3 there was a database space issue (see the support zip logs and you will see that). The idea is that these are somehow related.
We got permission to rename one of the groups from contracts to Contracts Portugal and we did a re-indexing. I am not sure if Eugene has heard back from the user yet on whether that helped.
Regardless, it is good information on how to increase the logging if we still have the issue.
I just saw we had confirmation for the user she still cannot login. We will look at the logging setting to increase logging and see if it shakes anything to the surface.
I enabled the logging, but the user logging in did not show up in the log. What she got was a User unknown or password incorrect textbox during logging into Jira.
I had expected the resolution of the group conflict to resolve this. On a hunch, and an idea Eugene and I had talked about earlier, I removed the user from the remaining group called "Contracts" and had her try again, and it worked.
She was able to login.
Idea 2: The group could not resolve that it was no longer in conflict with that user still in it. Removing her from it removed that conflict and synced contracts and then the user separately, allowing her to login.
It looks like you're new here. Sign in or register to get started.