CaskDS
LDAP directory service with Kerberos support for authoritative identity and policy.
Signed. Sealed. Verifiable.
Cask Trust is an open source trust stack for organizations that need strong identity, secure certificate issuance, resilient naming, and modern access control without vendor lock-in.
The Suite
LDAP directory service with Kerberos support for authoritative identity and policy.
Feature-rich, highly secure certificate authority with auditable issuance workflows.
Full-featured DNS authoritative nameserver plus recursive resolver for reliable name services.
Single sign-on platform supporting SAML, OAuth/OIDC, RADIUS, and TACACS+.
Mobile device management for secure enrollment, policy enforcement, and lifecycle control.
Unified web management for operating, monitoring, and scaling all Cask services.
Why Cask Trust
In the 19th century, bourbon could be altered at any stage before it reached the customer. The 1897 Bottled-in-Bond Act changed that by enforcing provenance, custody, and verification. A sealed and stamped bottle became a trustworthy artifact.
Cask Trust applies the same principle to identity systems. Every service in the stack contributes to an auditable chain of trust: directory, certificates, DNS, Kerberos realm, and access control, operated as one coherent platform.
Built In The Open