Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-2851

LDAP connector using Incremental Sync still syncs all memberships

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.4.4, 2.5
    • 2.3.2
    • Directory - LDAP
    • None

      When syncing an LDAP directory with Active Directory using incremental sync, user and group checks on periodic sync will properly respect the uSNChanged attribute and only make needed changes. However, even if AbstractCacheRefresher.synchroniseMemberships() returns an empty list, the connector will still query LDAP for all of the groups and check memberships as per a full sync, which can be very expensive in large ADs that depend on incremental syncs for performance.

              jwalton joe
              alaskowski Adam Laskowski (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: