Dear all,
in Confluence 6.11 we are evaluating the restrictions in using one user account from one Active Directory (AD-1) which is member of a group in another Active Directory (AD-2).
Our test scenario in details
- in AD-1 (domain1): user XY is an account name
- in AD-2 (domain2): user XY from AD-1 is referenced as a member in a universal group TEST_GROUP
-- ! ATTENTION PLEASE: !
--- MEMBERSHIP is a REFERENCE to user XY in AD-1 (via distinguishedName CN=XY,OU=dep,OU=org,DC=domain1,...)
--- in AD-2 NO USER with NAME XY exists !
The directory list order is: first AD-1, second AD-2.
A query for user XY in >Confluence administration >Users results in
- User XY is found as account in AD-1 (domain1)
- BUT: the group membership of XY(@AD-1; domain2) in TEST_GROUP of AD-2 is not found
Also: when looking up the members of TEST_GROUP (AD-2 / domain2) in >Confluence administration >Groups the referenced external AD account XY (@AD-1) is not found.
If a user account with NAME XY (not only reference) is present in AD-2 then his group memberships are found (even if this user is disabled). But this redundancy of account names (same name in two directories) is not what we want!
My conclusion: Confluence will only find group memberships if the user account name exists in the Active Directory that hosts the group(s). A LDAP Reference to an external account is unsufficient!?
All hints for a solution or workaround are gratefully appreciated! ;-)
Best
Winfried