LDAP & directory

LDAP, RADIUS and directory sync, built in

Let VPNs, Wi-Fi and legacy software authenticate against the same users as your modern apps. Casdoor serves LDAP and RADIUS itself, and keeps users in sync with Active Directory and other directories.

Built-in LDAP server

Bind and search with simple authentication on port 389, with users as posixAccount entries for Linux PAM and NSS.

Built-in RADIUS server

Authenticate VPNs and Wi-Fi against Casdoor users, and use RADIUS as an MFA method.

Kerberos and SPNEGO

Sign in to web apps with the Windows domain session people already have.

Directory sync

Import users and groups from Active Directory, Entra ID, Google Workspace, Okta, Keycloak, AWS IAM, SCIM and databases.

What's included

  • LDAP bind and search
  • Users and groups (memberOf) over LDAP
  • RADIUS server and RADIUS MFA
  • Kerberos/SPNEGO
  • Syncers for AD, Entra ID, Google Workspace and Okta
  • WeCom, DingTalk and Lark syncers

Included in the free open-source edition and in every Casdoor Cloud plan.

terminal
# Your legacy apps can read Casdoor users over LDAP
ldapsearch -x -H ldap://door.acme.com:389 \
  -D "cn=admin,ou=acme" -W \
  -b "ou=acme" "(uid=alice)"

# VPNs and Wi-Fi can use the built-in RADIUS server
radtest alice <password> door.acme.com 0 <secret>

FAQ

Frequently asked questions

Can Casdoor replace our LDAP server?
For apps that look up users and check passwords over LDAP, usually yes: Casdoor's LDAP server handles bind and search. It is not a general-purpose directory that apps write entries to; users and groups are managed in Casdoor or synced in from your directory.
Can Casdoor import users from Active Directory?
Yes. Casdoor's Active Directory syncer imports users and groups and keeps them up to date. There are also syncers for LDAP, Entra ID, Google Workspace, Okta, Keycloak, AWS IAM, SCIM directories and databases.