Can Jira's LDAP directory work together with an upstream Kerberos Authentication filter Edited

Hi,

Can we combine a custom Kerberos/Spnego-based authentication filter with the Atlassian-provided LDAP Directory?  i.e. will the LDAP directory filter 'pick up' the UserPrincipal in the request or an http header?

ldap directory: https://confluence.atlassian.com/adminjiraserver071/connecting-to-an-ldap-directory-802592350.html

Context

Our jira instance already currently uses a custom spnego-based authentication mechanism prior to 'home grown' user provisioning code (which uses ldap and Jira api's ). We would like to replace this 'home grown' user provisioning code with Atlassians' "out of the box"  LDAP directory functionality.

Question

If we enable the LDAP directory, does the "LDAP directory filter" check the HttpServletRequest.getPrincipal() (or some http header) for the user.

 

Usecase

Here's our usecase:

1) User Bob Brown (username "bbrown") logs on to the LAN

2) Bob points his browser to our internal jira instance

3) Authentication filter confirms via kerberos/spnego that "bbrown" has already authenticated on the network and puts  "Bob" in the request user principal  and/or  "bbrown" in some http header

4) Tomcat filter processor chains to the LDAP filter

5) LDAP filter recognizes that user "bbrown" has been authenticated and *SKIPS* challenge (i.e. doesn't prompt for creds)

6) LDAP filter looks up Bob's user info from LDAP

7) LDAP filter updates Jira's database with Bob Brown's user information (i.e. update in case his name change or inserts if it doesn't yet exist).

 

Summary

The key point lies in #5: can the ldap filter recognize that "bbrown" has authenticated, yet still retrieve user info from ldap? 

 

thanks in advance

 

 

 

1 answer

HI @Will Milspec 

When you add a JIRA user directory and point that to Active Directory your users are able to log in using their AD-credentials. (Username and password)

Atlassian does not offer Kerberos/SPNEGO, but there are a couple of add-ons that offer that functionality:

https://marketplace.atlassian.com/search?query=kerberos

I work for Kantega Single Sign-on.

Our add-on will use the incoming token and find the user based on whatever you have configured as the username (typically sAMAccountName, userPrincipalName or mail) and log in that user with no passwords asked. 

Let me know if you have any questions.

Suggest an answer

Log in or Sign up to answer
Atlassian Community Anniversary

Happy Anniversary, Atlassian Community!

This community is celebrating its one-year anniversary and Atlassian co-founder Mike Cannon-Brookes has all the feels.

Read more
Community showcase
Sarah Schuster
Posted Mar 28, 2018 in Jira Software

Can a company’s culture make or break agile adoption?

Can a new-to-agile team survive and thrive in a non-agile culture? If so, what advice would you give to those trying to be agile in a non-agile culture? What's the key(s) to success? Share your thoug...

12,013 views 15 13
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you