-
Type:
Bug
-
Resolution: Low Engagement
-
Priority:
Medium
-
None
-
Affects Version/s: 2.8
-
Component/s: Directory - Internal/Delegated
-
5
-
Severity 2 - Major
-
4
User from AD delegated directory is unable to login to Crowd when "Aggregate group membership across directories" is checked and the AD delegated directory "doesn't allow all to authenticate".
Steps to replicate
- User tester is created in Crowd Internal Directory and belongs to "crowd-administrators" group. His password is stored as admin
- Create a new "AD Delegated Directory" that consists of user tester and password 123456
- Ensure that user tester is synchronised in Crowd database by logging in or creating the user manually
- Go to Applications >> crowd >> Directories tab
- Add "AD Delegated Directory", set it as the first Directory order, set Allow all to authenticate to False
- Check "Aggregate group memberships across directories"
- Click Update
- Try to login with username tester and password 123456
Observed Result
- Unable to login with username tester and password 123456
- Unable to login with username tester and password admin
Expected Result
User should be able to login with tester and password 123456 with the configuration above. According to the Aggregating membership rule (documentation), user tester and password 123456 should be belong to "crowd-administrators" group, then supposedly have the ability to authenticate to Crowd console
- mentioned in
-
Page Loading...