Hi folks,
due to company security policies we have to ensure a safe lock out of users who left the company. On the other hand a simple deletion of the user is unwanted.
I run some tests and investigations. Removing an user from group shash-users seems not to be enough:
- only a new login attempt to web-ui is prevented. As long as the user stays logged in the user can continue using the Bitbucket server.
- ssh-based git activities seems not to be affected at all by removing user from shash-users
Conclusions:
- I see no safe approach to lock out an user from Bitbucket server immediately.
- To lock out a user safely it's needed to remove the user from group stash-users and remove all ssh keys of this user.
Questions:
- What are the best practise suggestions?
- How do you handle user management?
- Did I miss important details (or misunderstood the documentation)?
I highly appreciate every suggestion and answer.
Marko