Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.casdoor-ubuntu-24-04-584aa352-87e7-490d-93a7-4eaca1b5f307/image6_logolarge.png

Casdoor on Ubuntu 24.04 LTS

by cloudimg

Self hosted identity and access management and single sign on, from one self contained server.

Casdoor is a popular open source, self hosted, UI first identity and access management (IAM) and single sign on platform. It is a full authentication server: it issues signed OIDC and OAuth2 tokens and also supports SAML, CAS, LDAP and WebAuthn, so one deployment can be the login for all of your applications. A rich admin console manages organizations, users, applications, providers, roles, permissions, certificates, sessions and tokens, alongside a customisable login and account web interface. Casdoor is a single self contained Go binary that bundles its web console and uses an embedded database, so a complete identity provider with its console runs with no separate database to operate.

No known login

The image ships with no default or shared credential. Casdoor seeds a built in admin with a default password the first time it initialises an empty database, and the captured image ships an empty database. On the first boot of every instance, a one shot service boots Casdoor against the empty database, generates a unique admin password for that specific instance, resets the admin to that password through the Casdoor API, proves the default password no longer works, and writes the new password to a file that only the root user can read. The JWT signing certificate and the built in application client secret are also generated fresh per instance, so nothing signing related is shared between instances.

Hardened and ready on first boot

  • Casdoor runs as a single binary under systemd as an unprivileged system user, backed by an embedded SQLite database that needs no external server.
  • nginx terminates TLS on port 443 and reverse proxies to Casdoor so the OIDC issuer and its tokens are served over HTTPS, with HSTS and sensible security headers. Port 80 redirects to HTTPS.
  • A host firewall denies inbound traffic except ports 22, 80 and 443, so the application port is never exposed directly to the network.
  • A self signed certificate is regenerated per VM on first boot, with the VM public IP and hostname in its Subject Alternative Names. Replace it with your own CA signed certificate and domain for production.
  • A built in self test proves the admin login round trip end to end over TLS and that the upstream default password is rejected.

Why cloudimg

cloudimg delivers Casdoor fully patched on a hardened Ubuntu 24.04 LTS base, serving on first boot, with a unique admin password per instance and no shared credentials. Every image is built at a current stable release, passes an automated verification gate, and is backed by 24/7 support with a guaranteed 24 hour response SLA.

Licensing

Casdoor is open source software distributed under the Apache License 2.0, and is free. The cloudimg charge covers packaging, hardening, security patching, image maintenance and 24/7 support. A step by step deployment guide is provided.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.casdoor-ubuntu-24-04-584aa352-87e7-490d-93a7-4eaca1b5f307/image5_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.casdoor-ubuntu-24-04-584aa352-87e7-490d-93a7-4eaca1b5f307/image7_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.casdoor-ubuntu-24-04-584aa352-87e7-490d-93a7-4eaca1b5f307/image4_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.casdoor-ubuntu-24-04-584aa352-87e7-490d-93a7-4eaca1b5f307/image2_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies