Hi - so we have Jira (7.1) ,Confluence(5.9.6), Bit-bucket(4.6.2) and Crucible all running well in production for over 2 years with ~ 25 active users.
All authentication is handled by Jira Internal Directory. I want to keep everything the same (logins, names,issues, projects etc) except AD does the initial login authentication. Groups and permissions need to stay with Jira.
Internal Directory usernames are firstname.lastname
I have setup our AD as a 2nd User Directory and can successfully test a user (all greens) using firstname.lastname
LDAP permissions are Read Only
I feel im close to moving AD above Jira in the directory order but just want a couple of thing clarifying.
My questions:
Thanks for any help.
No, you're in the right place, but there's a lot of noise here and I am really sorry, but we've let you down. We are a community of end-users of Atlassian stuff, and most of us don't get paid to be here (if you see "Atlassian" in a person's display name, they probably do. Otherwise...)
So...
1. Yes, retaining the login name is absolutely the best approach
2. Possibly not. In later versions of the software, the login id is not the key - the systems will be aware that "Simee in LDAP" is not "Simee in the internal directory", so when you swap the directory order, it will see them as different humans.
Unusually for me, I'd take a look in the database. Does cwd_user see two sets of users in different directories?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.