• 3
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Atlassian Status as of 30 October 2013

      Hi everyone,

      Thank you for your votes and comments on this feature request. Whilst this is something we would like to implement some day, it is not at the forefront of our upcoming backlog.

      We will be focussing on improving the integration of Crowd within our Atlassian suite of products, as well as simplifying and improving the overall user management and administrative experience.

      If our backlog changes and this feature request becomes a priority, this ticket will be updated. If you'd like to better understand how we make roadmap decisions, have a read of : https://confluence.atlassian.com/display/DEV/Implementation+of+New+Features+Policy

      Cheers, Helen Hung
      Atlassian Product Management

      It would be useful to have support for Kerberos-based authentication

            [CWD-461] Add Kerberos Support

            Not mean to beat up a dead horse but any though on having Crowd authenticates with Kerberos w/o having to buy additional plugin?

            Steve Nguyen added a comment - Not mean to beat up a dead horse but any though on having Crowd authenticates with Kerberos w/o having to buy additional plugin?

            Correct.

            That's actually one of the steps detailed in IWAAC's online documentation https://www.cleito.com/products/iwaac/documentation/

            Bruno Vincent added a comment - Correct. That's actually one of the steps detailed in IWAAC's online documentation https://www.cleito.com/products/iwaac/documentation/

            Just a heads-up – you'll need to configure firefox to allow gssapi.
            In the address bar: about:config
            I'll be careful...
            search for "negotiate"
            network.negotiate-auth.trusted-uris: domain.com

            -Paul

            Paul Rawson added a comment - Just a heads-up – you'll need to configure firefox to allow gssapi. In the address bar: about:config I'll be careful... search for "negotiate" network.negotiate-auth.trusted-uris: domain.com -Paul

            Hi Ian,

            IWAAC should already work with RHEL clients in your environment. Technically speaking, any Linux client should work as long as it belongs to the Active Directory domain. Many of our clients have successfully deployed it mixed environments (Windows, Mac OS X, Linux). The reason we do not officially support Linux clients is that would mean too many Linux distributions to test.

            In the case of RHEL clients, if you used realmd for Active Directory integration (please check https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Windows_Integration_Guide/index.html for a full list of available options for AD integration), the Kerberos configuration on the desktop should already be just fine and you should be able to automatically log onto your IWAAC enabled applications with Firefox.

            Since you can download and test IWAAC for free, I suggest that you install it on a test environment. If it does not work out of the box with your RHEL clients, please drop us a line at support@cleito.com, we will be happy to do our best effort to make it work in your environment.

            Best regards,

            Bruno

            Bruno Vincent added a comment - Hi Ian, IWAAC should already work with RHEL clients in your environment. Technically speaking, any Linux client should work as long as it belongs to the Active Directory domain. Many of our clients have successfully deployed it mixed environments (Windows, Mac OS X, Linux). The reason we do not officially support Linux clients is that would mean too many Linux distributions to test. In the case of RHEL clients, if you used realmd for Active Directory integration (please check https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Windows_Integration_Guide/index.html for a full list of available options for AD integration), the Kerberos configuration on the desktop should already be just fine and you should be able to automatically log onto your IWAAC enabled applications with Firefox. Since you can download and test IWAAC for free, I suggest that you install it on a test environment. If it does not work out of the box with your RHEL clients, please drop us a line at support@cleito.com, we will be happy to do our best effort to make it work in your environment. Best regards, Bruno

            Bruno –

            This might be better asked in a different venue, but do you have any plans to support Linux clients? Specifically RHEL 7 and / or RHEL 6 are what I'd be interested in.

            Thanks,

            Ian

            Ian Lee [LLNL] added a comment - Bruno – This might be better asked in a different venue, but do you have any plans to support Linux clients? Specifically RHEL 7 and / or RHEL 6 are what I'd be interested in. Thanks, Ian

            Hi,

            We are proud to announce the release of our new add-on, Integrated Windows Authentication for Apps using Crowd (IWAAC) at https://marketplace.atlassian.com/plugins/com.cleito.iwaac

            IWAAC uses SPNEGO/Kerberos to allow your Windows domain users to log into Jira, Confluence, or any other web app using Crowd as its user management system without entering a password.

            Please check out https://www.cleito.com/products/iwaac/ for more details.

            Best regards,

            Bruno

            Bruno Vincent added a comment - Hi, We are proud to announce the release of our new add-on, Integrated Windows Authentication for Apps using Crowd (IWAAC) at https://marketplace.atlassian.com/plugins/com.cleito.iwaac IWAAC uses SPNEGO/Kerberos to allow your Windows domain users to log into Jira, Confluence, or any other web app using Crowd as its user management system without entering a password. Please check out https://www.cleito.com/products/iwaac/ for more details. Best regards, Bruno

            Justin added a comment -

            AppFusions' Kerberos SSO Authenticator for AD & Atlassian Servers solution supports Confluence, JIRA, Crowd, FishEye, Crucible, Bamboo, SVN as of this writing. It was first released in June 2011 and continually supported since, through dozens of Atlassian version releases (esp. JIRA and Confluence; the others came later).

            Deployed, the Kerberos SSO over HTTP authentication flow is as follows:

            1. User gets a Kerberos ticket from Active Directory during Windows login to a domain joined PC.
            2. With a Kerberos-enabled browser (MSIE, Chrome, and Firefox), the user accesses an Atlassian web application protected by the AppFusions Kerberos SSO Authenticator.
            3. The AppFusions Kerberos SSO Authenticator denies access to the browser with a 401 response and negotiates with the browser to use Kerberos for authentication or fall back to basic authentication if Kerberos is not possible.
            4. If Kerberos is negotiated, the web browser gets a service ticket from a domain controller for authentication.
            5. The web browser sends the service ticket to the AppFusions Kerberos SSO Authenticator for validation with a domain controller.
            6. Upon service ticket validation, the AppFusions Kerberos SSO Authenticator uses Atlassian Seraph to log the user into the Atlassian web application.

            Flow diagram is here.Contact Info@appfusions.com for more information. Many many references, successes, renewals, upgrades.

            Justin added a comment - AppFusions' Kerberos SSO Authenticator for AD & Atlassian Servers solution supports Confluence, JIRA, Crowd, FishEye, Crucible, Bamboo, SVN as of this writing. It was first released in June 2011 and continually supported since, through dozens of Atlassian version releases (esp. JIRA and Confluence; the others came later). Deployed, the Kerberos SSO over HTTP authentication flow is as follows: User gets a Kerberos ticket from Active Directory during Windows login to a domain joined PC. With a Kerberos-enabled browser (MSIE, Chrome, and Firefox), the user accesses an Atlassian web application protected by the AppFusions Kerberos SSO Authenticator. The AppFusions Kerberos SSO Authenticator denies access to the browser with a 401 response and negotiates with the browser to use Kerberos for authentication or fall back to basic authentication if Kerberos is not possible. If Kerberos is negotiated, the web browser gets a service ticket from a domain controller for authentication. The web browser sends the service ticket to the AppFusions Kerberos SSO Authenticator for validation with a domain controller. Upon service ticket validation, the AppFusions Kerberos SSO Authenticator uses Atlassian Seraph to log the user into the Atlassian web application. Flow diagram is here .Contact Info@appfusions.com for more information. Many many references, successes, renewals, upgrades.

            we have Confluence (and soon Jira) deployed with a custom authenticator for Kerberos Logon. Adopting Crowd would be a step back for us because we have a password free infrastructure already

            Stefan Ernst added a comment - we have Confluence (and soon Jira) deployed with a custom authenticator for Kerberos Logon. Adopting Crowd would be a step back for us because we have a password free infrastructure already

            Reopening this issue since it is no longer resolved given that previously suggested plugins are no longer compatible with support versions of Crowd or exist.

            Helen Hung (Inactive) added a comment - Reopening this issue since it is no longer resolved given that previously suggested plugins are no longer compatible with support versions of Crowd or exist.

            The plugins referenced here are either deprecated or gone...

            Damon Buckwalter added a comment - The plugins referenced here are either deprecated or gone...

              Unassigned Unassigned
              david.soul@atlassian.com David Soul [Atlassian]
              Votes:
              137 Vote for this issue
              Watchers:
              111 Start watching this issue

                Created:
                Updated: