Nested groups, how to exclude from search in UI

Hi!

I'm having the following pseudo LDAP-structure:

ou=groups
|_ou=internal
|         |
|         |_cn:myInternalGroup
|                    member:uid=foo
|
|
|
|_ou=wiki
          |
          |_cn:myWikiGroup
                     member:cn:myInternalGroup,ou=internal,ou=groups

The internal tree is full of groups that are irrelevant for Wiki-users, so I want to limit the groups that are shown in the UI to only "ou=wiki".

The problem is that if I add a "Group Object Filter", confluence is not able to resolve the subgroup, as it sits under ou=internal.

How can I hide groups from the user interface without breaking the nesting of groups that are necessary to resolve membership?

Best regards,
Thomas

3 answers

1 accepted

Confluence does not have such ability to filter out groups in UI only while still synchronizing those groups from LDAP server.

I had the same problem. You can find a documention and create a filter based on the structure of your directory: https://confluence.atlassian.com/display/DEV/How+to+write+LDAP+search+filters

eg. userSearchFilter

(&(objectCategory=Person)(sAMAccountName=*)(memberOf=cn=myWikiGroup,ou=wiki,ou=groups,ou=XXX,dc=XXX,dc=XXX,dc=XX))

Grettings
Jürgen

Thanks for your reply, but if I understand you correctly, this still does not solve my problem, as it would also prevent confluence to resolve the subgroups (which resides in the tree I'm trying to hide).

From the documentation: " In essence the filter limits what part of the LDAP tree Confluence syncs from"

I still need confluence to sync from the "internal"-tree, but I don't want to show the "internal" groups in the User Interface when end-users search for groups.

Do you have testing to configure the Additional Group DN like this:

cn:myWikiGroup,ou=groups

Suggest an answer

Log in or Sign up to answer
Atlassian Community Anniversary

Happy Anniversary, Atlassian Community!

This community is celebrating its one-year anniversary and Atlassian co-founder Mike Cannon-Brookes has all the feels.

Read more
Community showcase
Kesha Thillainayagam
Posted Apr 13, 2018 in Confluence

We want to hear how your non-technical teams are using Confluence!

Hi Community! Kesha (kay-sha) from the Confluence marketing team here! Can you share stories with us on how your non-technical (think Marketing, Sales, HR, legal, etc.) teams are using Confluen...

2,945 views 27 12
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you