"Active Directory LDAP" with internal and external users

Jason K April 13, 2015

I'd like to be able to offer our Confluence instance to outside users. Currently all of our users are internal and authenticate via LDAP.

In the User directory setup, I have "Delegated LDAP Authentication" as the first priority (top). The problem here, however, is that when the invitation is sent to the outside user, they are not able to log in. the account is created, but they don't authenticate.  Shouldn't the system next try the internal directory if it cannot authenticate using LDAP?

 

3 answers

1 vote
rrudnicki
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 14, 2015

Hi Jason, 

 

I think would be good if we have this feature on Confluence, so I've created this feature request. Please, vote on that to increase the visibility and start watching that to keep updated.

 

Regards, 

Renato Rudnicki

1 vote
Mallmann
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 13, 2015

Hello Jason,

Confluence will only try to authenticate the user against the next directory of the list in case this user does not exist on the current directory. For example:

Directory List:

DirectoryA

DirectoryB

DirectoryC

Let's say you've got a user called "UserC" from DirectoryC. If this user exists on DirectoryA, Confluence will not try to authenticate this user against other directories other than the DirectoryA; however, if the user exists only on DirectoryC, Confluence will not find the user on DirectoryA neither on DirectoryB and then will find the user on DirectoryC and authenticate it.

 

Let me know if you have any questions. I hope it helps!

Eduardo

0 votes
Jason K April 13, 2015

Thanks Eduardo,

That makes sense. So maybe I need to ask a different question - is there a way to specify which directory a user is created in? In your example, I'd like the invited user to be created in DirectoryB, but they are being created in DirectoryA.

 

Thanks again.

Mallmann
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 13, 2015

Hey Jason, Confluence will try to create the user against the first directory of the directory list. So in this case you'd need to change the directory order :) Eduardo

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events