I'm trying to understand what Atlassian crowd does over an LDAP server? It looks like most Atlassian products allow you to point to an Atlassian server for authorization/authentication. If that's the case why use Crowd?
Crowd allows you to manage your users for all of your Atlassian Server and Data Center applications. Packed with critical features such as single sign-on, audit logs, and delegated administration, Crowd allows you to manage users and their authentication permissions from multiple directories.
Data Center Pricing FAQ You can host a fully functional copy of Crowd on your own hardware, free for 30 days for free.
Crowd supports read-only connections to an LDAP directory using the Posix/NIS schema. This is useful if you have a Unix installation and want to integrate with an LDAP directory. The Posix/NIS schema allows integration between an LDAP directory and the Unix NIS (Network Information Service).
When you log in to a Crowd-connected application, Crowd will verify your password and login permissions. Using Crowd for single sign-on (SSO), each person needs only one username and password to access all web applications. You can host your own OpenID provider to include external applications.
LDAP provides you just Authentication/Authorization. Sometimes more. Atlassian Crowd offers Single Sign On. When you have multiple web apps, e.g. Confluence, Jira, Fisheye, etc you don't want to sign on to each one of them, if you're singed in on one.
Also Crowd offers OpenId, which means that you can use it with any app that supports OpenId. LDAP requires configuration of each application to the corresponding LDAP Server.
The real reason we use crowd is for multiple directory authentication. We have our internal users in active directory. We have our customers that can authenticate through crowd to access JIRA/Confluence using the same sign on they use in our application through some custom database magic, and application authentication is handled internally by crowd. It's really just makes things so much smoother, than trying to cram everything into AD.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With