Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-36426

Specifying an Additional Group DN causes memberships to be ignored in Active Directory

    XMLWordPrintable

Details

    • Bug
    • Resolution: Obsolete
    • Medium
    • 5.6.4, 5.7
    • 5.6.5
    • None

    Description

      Environment

      Confluence 5.6.5

      Directory Structure:
      • Base DN: DC=corp,DC=local
      • Location of Groups: OU=Confluence,DC=corp,DC=local
        • Groups include confluence-users and confluence-administrators, among others
      • Users are members of groups at that location
      Steps to Reproduce
      • Configure a connection to Active Directory, with DC=corp,DC=local as your base DN
      • Set OU=Confluence as your Additional Group DN
      • Save and Synchronise Confluence
      Expected Result
      • All users will be synchronised in
      • Memberships from Active Directory will be preserved - if a user is a member of confluence-users in Active Directory, that user should be a member of confluence-users in Confluence.
      Actual Result
      • All users will be synchronised in
      • Memberships from Active Directory will not be present - users sync'd in will not be members of specific groups.
      Possible Workaround

      Performing a test as a particular user will force the memberships for that user to be synchronised in.

      Workaround:

      Remove the additional Group DN from the configuration, and synchronise Confluence against the directory - memberships will be preserved.

      Note: You can use LDAP Filters to ensure only the correct users and groups are brought into Confluence

      Attachments

        1. 5.6.4_DB.png
          5.6.4_DB.png
          44 kB
        2. 5.6.4_WorkingDCS.txt
          3 kB
        3. 5.6.5_DB.png
          5.6.5_DB.png
          42 kB
        4. 5.6.5_FaultyDCS.txt
          3 kB
        5. 5.7.0_DB.png
          5.7.0_DB.png
          45 kB
        6. 5.7.0_WorkingDCS.txt
          3 kB

        Activity

          People

            Unassigned Unassigned
            dnorton@atlassian.com Dave Norton
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: