• Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Directory - LDAP
    • None
    • 10
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      FreeIPA 3.x is a very powerful replacement for MS AD. As it turns out, it also contains a full RBAC system that has host-based differentiation capabilities.

      Imagine: Individual permissions allow very granular mapping to actual functions in the Atlassian stack. Traditional Atlassian roles such as jira-administrator allow a smooth migration path for existing users. Privileges are created to map these permissions to roles. Add hosts to the mix, and roles can be differentiated by server such that the jira-administrator role can be the same everywhere, but with only certain users available to exercise a role per host.

      FreeIPA does all this out of the box.

      Crowd is great, but FreeIPA has slowly improved to where Crowd was originally going to go. FreeIPA is incredibly detailed, maybe too detailed for the beginner user. As it's turned out, they compliment each other quite remarkably! Supporting both Crowd and FreeIPA will make the Atlassian stack incredibly valuable.

            [CWD-4134] Support FreeIPA Roles/Permissions/Privileges

            SET Analytics Bot made changes -
            Support reference count New: 10
            Conny Postma made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 122724 ]
            Katherine Yabut made changes -
            Workflow Original: JAC Suggestion Workflow [ 3388255 ] New: JAC Suggestion Workflow 3 [ 3630131 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 [ 1392380 ] New: JAC Suggestion Workflow [ 3388255 ]
            Issue Type Original: Improvement [ 4 ] New: Suggestion [ 10000 ]
            Status Original: Needs Verification [ 10004 ] New: Gathering Interest [ 11772 ]
            Monique Khairuliana (Inactive) made changes -
            Epic Link Original: CWD-4705 [ 600142 ]

            I've also had issues with this but eventually configured it trough trial and error in the Crowd UI. I have posted my settings here.

            Franz Geffke added a comment - I've also had issues with this but eventually configured it trough trial and error in the Crowd UI. I have posted my settings here .

            I am trying to migrate from OpenLDAP to FreeIPA.  I am not able to have JIRA communicate w/ FreeIPA. I get connection error 49.

            // code placeholder
            

            Connection test failed. Response from the server: [LDAP: error code 49 - Invalid Credentials]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - Invalid Credentials] For more information regarding LDAP error codes see Troubleshooting LDAP Error Codes.

            Andrew Meyer added a comment - I am trying to migrate from OpenLDAP to FreeIPA.  I am not able to have JIRA communicate w/ FreeIPA. I get connection error 49. // code placeholder Connection test failed. Response from the server: [LDAP: error code 49 - Invalid Credentials] ; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - Invalid Credentials] For more information regarding LDAP error codes see Troubleshooting LDAP Error Codes.
            Marcin Kempa made changes -
            Status Original: Open [ 1 ] New: Needs Verification [ 10004 ]
            Marcin Kempa made changes -
            Epic Link New: CWD-4705 [ 600142 ]
            Owen made changes -
            Workflow Original: Crowd Development Workflow v2 [ 761386 ] New: Simplified Crowd Development Workflow v2 [ 1392380 ]

              Unassigned Unassigned
              341e6a1d74a2 Brian Topping
              Votes:
              34 Vote for this issue
              Watchers:
              22 Start watching this issue

                Created:
                Updated:

                  Estimated:
                  Original Estimate - 2h
                  2h
                  Remaining:
                  Remaining Estimate - 2h
                  2h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified