Support Questions
Find answers, ask questions, and share your expertise
Check out our newest addition to the community, the Cloudera Innovation Accelerator group hub.

How to set Cache expiry for Knox ​LDAP Authentication Caching ?

Expert Contributor


I was going through the HDP documentation which talks about enabling caching for Knox LDAP authentication :

What is the default cache expiry time? And How can I reduce/increase the cache expiry time?




Expert Contributor

Tagging SME @Kevin Minder


You can find details here:

There is a default ehcache.xml file included with Knox which sets the TTL for entities to 120 seconds. This is included in the JAR file /usr/hdp/current/knox-server/dep/shiro-ehcache-1.2.3.jar. You can override this by extracting the file ('unzip /usr/hdp/current/knox-server/dep/shiro-ehcache-1.2.3.jar org/apache/shiro/cache/ehcache/ehcache.xml') and copying the extracted file to /etc/knox/conf, then editing it.

See the documentation here for details: You'll then need to add the following to your Knox topology with the other cache settings provided in the link you already have:

Add to your Knox topology:

<param name="main.cacheManager.cacheManagerConfigFile" value="classpath:ehcache.xml" />

Expert Contributor

Thanks Carl. @cdraper.

I will try this. An additional question :

When the end user comes and issues a connect command from jdbc client like beeline

For example :

1) beeline

2) now enter !connect string with Knox:port

3) Enter AD UserName/Password

4) AD authenticates OK

5) user submits queries.

6) more queries.

In default case, without enabling EHCache, does further A/D authentication happens for step 5..6.. and onwards ? Or since its part of the same session it doesn't need to re-authenticate?

I am wondering how much % A/D round trips can be avoided on a busy production cluster with cachetime out of 2 mins.



Session is different than cache as far as I understand (which is somewhat limited!):

Sessions is the amount of time you can be logged in to say hive. During this session it wont try to re-authenticate you.

If you quit the hive session and upload a file via knox WebHDFS before the cache timeout you will need to submit your username and password again to authenticate the request but it won't make an AD call and use the cached credentials. Thus limiting AD transactions.

Pretty sure this would need some testing to confirm. If I find a moment I will try myself this is an intresting topic.

Expert Contributor

Thanks Carl @cdraper . I enabled EhCache and enabled logging for EHCache.

In our use case : We use Knox only for Hive. And as we discussed, during the session Hive Queries do not go through re-authentication, hence, I do not think we will get any benefit by enabling cache. What's your views on this?



@Smart Solutions

AFAIK, Knox uses EHCache, which can be configured further by placing a ehcache.xml file in an appropriate location in classpath as written here:


The content of the config file is described here, with a concrete example here.

You should check "timeToIdleSeconds" (defaults to 120 seconds).

Hope this helps!

Expert Contributor

Thanks @pdarvasi