Use OpenID provider to login to JIRA / Crowd

Brian Kennedy February 12, 2013

I am interested in using Crowd for single sign on, but my company already has an OpenID provider that we use. We do not need to use CrowdID as an open ID provider. What I am interested in is hooking Crowd (or JIRA/Confluence directly) into my OpenID provider server so that my existing users can login to my atlassian products. Is this possible, and if so, how?

6 answers

2 votes
Caspar Krieger
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 27, 2013

Re using an external OpenID provider to authenticate to JIRA, Confluence, or Crowd:

  • JIRA - acting as a Relying Party is not officially supported out of the box (vote on this feature request to get it added), but there's a third-party plugin (OpenID Authentication for JIRA) for sale.
  • Confluence - acting as a Relying Party is not officially supported out of the box (vote on this feature request to get it added), but there's a third party plugin (Confluence OpenID Authenticator) for sale; unfortunately, the plugin is not listed as working with the latest versions of Confluence, but it might be worth contacting the vendor to ask for support to be added.
  • Crowd - can act as a provider (more specifically, CrowdID is a provider which can be backed by Crowd), but cannot act as a Relying Party (i.e. use an external OpenID provider; vote on this feature request to get it added).
    • Somewhat related, Crowd does support acting as an authentication provider to Google Apps via SAML (i.e. users in Crowd can log in to Google Apps), but still not as a consumer. Probably not helpful to anyone specifically looking for an OpenID based solution, but possibly relevant to people investigating SSO in general.

(I'm a developer on the Crowd team.)

Jeremy Heckathorn January 2, 2018

Has there been any update regarding the support an external OpenId provider to authenticate to Jira?

Like Jo Wilkes likes this
2 votes
Janusch Skubatz May 30, 2013

Same question here! We would love to see the ability for single sign on with google apps just like in OnDemand, using Google Authenticator.

Zack Loveless June 10, 2019

Same question here in 2019. Interested in OIDC support for Atlassian's cloud/on-demand products.

Like # people like this
Gaurav
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 15, 2019

OpenID Connect in Crowd is on our current roadmap, can't share any timeline with you right now, but there will be an update soon.

1 vote
Dennis Biringer August 7, 2013

We have the same situation. We are mandated to use a specific openID server and need to integrate JIRA, Confluence, and Stash into the picture. We are currently using JIRA for user account management but would consider using Crowd with the added benefit of SSO. However, we must use the provided openID server and, so far, I don't see how that can be done.

0 votes
Catheline Dass July 15, 2020

Hi Brian - Were you able to solve this?

0 votes
Lokesh Naktode_miniOrange
Marketplace Partner
Marketplace Partners provide apps and integrations available on the Atlassian Marketplace that extend the power of Atlassian products.
August 21, 2019

Hi @Brian Kennedy2 ,

 

Yes, it is possible to connected JIRA, Confluence and other Atlassian application to any of the OAuth/OpenID provider for Single Sign-on with the help third party OAuth/OIDC client plugins from the Atlassian Marketplace.  

Please take a look into the OAuth/OIDC client plugin from Atlassian Marketplace.

https://marketplace.atlassian.com/search?query=OAUTH%20%20miniOrange

 

Also, with the help of above plugins, you will also be able to manage users and group from your OpenID provider but if you are interested in managing user and group in Crowd, simply connect Crowd as user directory to all the Atlassian applications and configure the plugin for Single Sign-on only.

 

I work for the miniOrange. In case if you have any questions or need further assistance, feel free to reach out via our customer portal.

 

Thanks,

Lokesh 

0 votes
Krzysztof Rogala October 25, 2013

We have a similar requirement. We want to use CrowdID and its login page for our Confluence, Jira and a couplle of custom web apps. I don't see how this can be done. I have configured Confluence and JIRA to use SSO, which is great, but it requires each app to use its own login page (which we are trying to avoid).

Caspar Krieger
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 27, 2013

Suggest an answer

Log in or Sign up to answer