Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Migrating Users between User Directories

Normann P_ Nielsen _Netic_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 15, 2015

It this still valid : https://confluence.atlassian.com/jira/migrating-users-between-user-directories-426116517.html

 

For JIRA /Confluence?

 

If  not - what other options for Migrating local (Internal) users to LDAP/AD

 

 

2 answers

2 accepted

1 vote
Answer accepted
Nicolas Bourdages
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 15, 2015

I tried the migration feature on my test environment, and it worked as advertised, but what I actually needed was not another internal directory with LDAP authentication, but a fully synced LDAP

So, I didn't actually migrate them. I just made sure the users had the same exact username as the LDAP standard we had, and just added the LDAP directory on top. The users synced like a charm, and inherited their JIRA group memberships from LDAP. With good user and group filters, only the users with a certain LDAP groups were synced, and only groups with "jira" were added to JIRA. It's super important that if you do that, you leave your LDAP directory in higher priority than your internal directory.

So, my answer is, that documentation is true and works correctly if you want to go from internal to internal with LDAP auth. I recall that all users were disabled after the migration though, so I had to re-enable them all.

If you want to switch to a synced LDAP, you might want to just match the existing usernames to your new LDAP format and add your LDAP directory in higher priority. Some people may disagree with the method I'm sure, but it worked fine for us.

0 votes
Answer accepted
Rodrigo Girardi Adami
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 16, 2015

Hi team,

From Confluence 5.3.x onwards, if you have the same username between users in the LDAP and internal directory, they won't lose the ownership of created contents and permissions. These new versions of Confluence contains a table called user_mapping in the database, which as the name says, maps the username to a hash code. Using the same user name between different user directories should maintain the permissions and ownership.

Nicolas answer is correct smile

Cheers,

Rodrigo

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events