How to configure base DN when having many OUs

I have 5 Organizational Units from which I need to dwnload users and groups

OU1,OU2,OU3,OU4,OU5

To download users from these 5 OUs, i created 5 connections as below:

OU=OU1,DC=intern,DC=company,DC=com

OU=OU2,DC=intern,DC=company,DC=com

OU=OU3,DC=intern,DC=company,DC=com

OU=OU4,DC=intern,DC=company,DC=com

OU=OU5,DC=intern,DC=company,DC=com

Users were downloaded successfully

Now I need to download related groups (group1, group2 and group3).

The issue here is that groups cannot have many OUs so they will have OU=OU1 or OU=OU2 or OU=OU3 or OU=OU4 or OU=OU5 to have users from the 5 OUs assigned to the 3 groups.

in this case, only users belonging to the configured OU within the group will be assigned to the downloaded group (group1, group2, or group3)

If they have only one OU as the RDN is unique in LDAP, they will not be able to download users from the 5 OUs

Is there a solution to get all users assigned to the 3 groups downloded and assigned to the users logged from the 5 OUs?


thanks,



2 answers

0 votes

Hi Ghazi,

Let's supose these are your LDAP locations to the users:
OU=OU1,DC=intern,DC=company,DC=com
OU=OU2,DC=intern,DC=company,DC=com

And these are the LDAP locations to your groups:
DC=groups,DC=company,DC=com

Your LDAP Base DN should be the common part ot all locations, complemented to the specific location for users and groups:

Base DN: DC=company,DC=com
Additional User DN: DC=intern
Additional Group DN: DC=groups

If you want to filter specific users dependin on their groups you can create a filter(User Object Filter) for that.
More information about filters can be found at: https://confluence.atlassian.com/display/DEV/How+to+write+LDAP+search+filters

Another useful link: https://confluence.atlassian.com/doc/connecting-to-an-internal-directory-with-ldap-authentication-229838462.html

Hi Daniel,

 

Thanks for your quick reply.

I tried with Base DN equals to only DC values but it didn't worked (not able to login with ldap)

so the base DN should necessarily contain OU values as if if I put a filter without OU, I can never login.

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted 9 hours ago in Jira Service Desk

Looking for anyone who has switched from Zendesk to Jira Service Desk

Hi Community! The Jira Service Desk marketing team is looking for customers who have successfully switched from Zendesk to Jira Service Desk!   We’d love to hear your thoughts on the pros and ...

15 views 0 1
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you