Unable to Aggregate group memberships to Login in Crowd Application With AD Delegated Authentication

XMLWordPrintable

    • 5
    • Severity 2 - Major
    • 4

      User from AD delegated directory is unable to login to Crowd when "Aggregate group membership across directories" is checked and the AD delegated directory "doesn't allow all to authenticate".

      Steps to replicate

      1. User tester is created in Crowd Internal Directory and belongs to "crowd-administrators" group. His password is stored as admin
      2. Create a new "AD Delegated Directory" that consists of user tester and password 123456
      3. Ensure that user tester is synchronised in Crowd database by logging in or creating the user manually
      4. Go to Applications >> crowd >> Directories tab
      5. Add "AD Delegated Directory", set it as the first Directory order, set Allow all to authenticate to False
      6. Check "Aggregate group memberships across directories"
      7. Click Update
      8. Try to login with username tester and password 123456

      Observed Result

      • Unable to login with username tester and password 123456
      • Unable to login with username tester and password admin

      Expected Result

      User should be able to login with tester and password 123456 with the configuration above. According to the Aggregating membership rule (documentation), user tester and password 123456 should be belong to "crowd-administrators" group, then supposedly have the ability to authenticate to Crowd console

            Assignee:
            Unassigned
            Reporter:
            Patrice Rompas (Inactive)
            Votes:
            7 Vote for this issue
            Watchers:
            12 Start watching this issue

              Created:
              Updated:
              Resolved: