We have configured Crowd so that we can login with the default authenticator.
Our next step was to prepare SSO. So I followed the instructions and switched the authenticator lines in seraph-config.xml and copied and edited the crowd.properties file as required.
After the confluence restart I cannot login any more. In the confluence log I see:
2018-04-20 12:46:01,066 WARN [http-nio-8090-exec-1] [atlassian.seraph.auth.DefaultAuthenticator] login login : 'mchjbaus' tried to login but they do not have USE permission or weren't found. Deleting remember me cookie.
-- referer: http://dolly2.abg.fsc.net:8090/login.action?os_destination=/admin/users/dosearchusers.action&permissionViolation=true | url: /dologin.action | traceId: 3af9dd70be01ca8a
In the Crowd log I see a LOT of lines like:
2018-04-20 12:45:45,863 http-nio-8095-exec-15 INFO [plugin.rest.filter.BasicApplicationAuthenticationFilter] Application 'confluence' failed authentication
I have already reset the application's password so I am sure that the password in Crowd and the crowd.properties file is identical.
When I try to log in, I can see in the Crowd log that my userID is passed over to Crowd and is processed there via LDAP, but the result is always 'invalid user or password'.
Originally we had http://server.domain:8095/crowd and http://server.domain:8090 for confluence. We changed the latter to http://server.domain:8090/confluence - but the result is still the same.