Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-468

Add default config to optimize LDAP group lookup

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 0.5.0
    • 0.6.0
    • Server
    • None

    Description

      The config below needs to be added to the Shiro provider in order to prevent LDAP group lookup every request.

      cacheManager = org.apache.shiro.cache.MemoryConstrainedCacheManager
      securityManager.cacheManager = $cacheManager
      
      <topology>
          <gateway>
              <provider>
                  <role>authentication</role>
                  <name>ShiroProvider</name>
                  ...
                  <param>
                      <name>main.cacheManager</name>
                      <value>org.apache.shiro.cache.MemoryConstrainedCacheManager</value>
      	    </param>
                  <param>
                      <name>main.securityManager.cacheManager</name>
                      <value>$cacheManager</value>
                  </param>
                  ....
              </provider>
              ....
          </gateway>
          ...
      </topology>
      
      

      Attachments

        Activity

          People

            sumit.gupta Sumit Gupta
            kminder Kevin Minder
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: