# How to update LDAP plugin

**URL:** <https://community.jenkins.io/t/how-to-update-ldap-plugin/19611>\
**Category:** Using Jenkins\
**Created:** [September 16, 2024, 9:19am UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611 "2024-09-16T09:19:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![harridu](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/harridu/32/729_2.png) [@harridu](https://community.jenkins.io/u/harridu)\
**Post date:** [September 16, 2024, 9:19am UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/1 "2024-09-16T09:19:19Z")

</div>

Hi folks,  
after the upgrade Jenkins 2.474 to 2.476 (via Debian package) I got a Devil Jenkins shown at login time. Even the admin account was blocked. I learned the LDAP plugin has to be updated to version 733, but how is this supposed to work? Before the upgrade version 733 was not shown to upgrade to, and after the upgrade LDAP was broken and I was not allowed to login.

I reset the security settings in config.xml to false, accessed Jenkins without login and updated LDAP. After that I found that all LDAP settings were gone and I had to configure users from scratch:-(. Fortunately it was just a test system.

How can I upgrade without losing the LDAP settings and all users?

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [September 16, 2024, 9:36am UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/2 "2024-09-16T09:36:03Z")

</div>

Before starting Jenkins after updating it via the package manager, download the ldap hpi from [https://updates.jenkins.io/download/plugins/ldap/733.vd3700c27b\_043/ldap.hpi](https://updates.jenkins.io/download/plugins/ldap/733.vd3700c27b_043/ldap.hpi) and put it into `JENKINS_HOME/plugins` (overwriting an existing ldap.hpi)  
Then start your Jenkins

---

<div class="post-metadata">

**Author:** ![harridu](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/harridu/32/729_2.png) [@harridu](https://community.jenkins.io/u/harridu)\
**Post date:** [September 16, 2024, 1:14pm UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/3 "2024-09-16T13:14:46Z")

</div>

There is just a file “ldap.jpi” and an “ldap” directory. No hpi file to overwrite. AFAIU the new ldpap.hpi file has to be renamed.

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [September 16, 2024, 3:05pm UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/4 "2024-09-16T15:05:20Z")

</div>

ah yes, delete the `ldap.jpi` rename the `.hpi` to `.jpi`

---

<div class="post-metadata">

**Author:** ![mannih](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mannih/32/10214_2.png) [@mannih](https://community.jenkins.io/u/mannih)\
**Post date:** [September 17, 2024, 10:23am UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/5 "2024-09-17T10:23:55Z")

</div>

Thank you harridu and Markus. Always nice to see that someone else already asked your question and got a good answer.  
But: Is it on purpose that the new version of the LDAP-plugin could not be updated via the regular plugin-update mechanism? Was downloading ldap.hpi and renaming it to ldap.jpi the plan for this upgrade?

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [September 17, 2024, 10:39am UTC](https://community.jenkins.io/t/how-to-update-ldap-plugin/19611/6 "2024-09-17T10:39:53Z")

</div>

This is an exceptional case I think. The ldap plugin is responsible for the login process so if the plugin doesn’t work then you can’t use Jenkins at all. Even though Jenkins maintainers try their best to stay compatible it is not always possible.  
For almost any other plugin it would be possible to run the update after upgrading Jenkins.
