Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-75035

When using Delegated LDAP with default group, the group membership is not populated

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Medium
    • None
    • 9.4.2
    • Login
    • None

    Description

      Issue Summary

      When configuring Jira to use delegated LDAP with Default Group Memberships Jira does not populate its tables to include all related data to ensure that users can log in properly either for the first time or in subsequent logins (if marked to update attributes in each login).

      This occurs on either SSO (third-party tools such as Jira SAML SSO) or direct authentication through LDAP.

      This is reproducible on Data Center: (yes)

      Steps to Reproduce

      1. Lift a Jira instance and setup a delegated LDAP directory marking to
        1. Copy User on Login
        2. Update User attributes on Login (for proper testing in multiple logins, not only the first)
        3. Default Group Memberships with any value set
        4. Synchronise Group Memberships
      2. Create an user in LDAP with groups to be synchronized in Jira (as the example below we have a user with two groups - jira-administrators and jira-servicedesk-users)
      3. Login and observe the user is not set with the required groups

      Expected Results

      User created and set with all expected groups.

      Actual Results

      User created with only the Default Group.

      Workaround

      Either manually insert each user in the required group on Jira or create a new Delegated LDAP directory entry without any entry in "Default Group Memberships" and rank it first than the older (please proceed with cautious and only after proper backup - see the JRASERVER-75079 before proceeding with the new directory creation).

      As example below, when creating same Delegated LDAP directory the result is correctly set:

      The second workaround is using LDAP Connector instead of Delegated (if possible) - see Differences between connector and delegated LDAP directories in Jira.
       

       

      Attachments

        1. correct_ldap.png
          correct_ldap.png
          100 kB
        2. group1.png
          group1.png
          22 kB
        3. group2.png
          group2.png
          22 kB
        4. groupc1.png
          groupc1.png
          25 kB
        5. groupc2.png
          groupc2.png
          26 kB
        6. ldap_settings.png
          ldap_settings.png
          103 kB
        7. result.png
          result.png
          47 kB
        8. resultc.png
          resultc.png
          52 kB
        9. user.png
          user.png
          28 kB
        10. userc.png
          userc.png
          28 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              b99328de92bd Douglas Alves
              Votes:
              2 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated: