Commit ec0751

2025-05-21 14:11:29 flichtenheld: Reorganise
Pages/OpenVPN software repos.md ..
@@ 4,52 4,53 @@
For OpenVPN 3 Linux, see the dedicated [OpenVPN 3 Linux](/Pages/OpenVPN3Linux) page.
- Latest OpenVPN releases are available in the OpenVPN project's apt repositories. This allow you to use more up-to-date version of OpenVPN than what is typically available in your distribution's repositories. Please note that all commands listed below have to be run as root, e.g. using *sudo* or *su*.
+ The OpenVPN project provides the latest OpenVPN releases (and development snapshots) as packages for major Linux distributions. This allow you to use more up-to-date version of OpenVPN than what is typically available in your distribution's repositories.
- Pre-built Linux binaries are only available for Debian and Ubuntu. This is so for two reasons:
+ Note that this is mostly interesting for users of distribution releases with long release cycles (e.g. Debian, Ubuntu LTS, RHEL). Distributions with rolling releases (e.g. Arch, openSUSE Tumbleweed) or half-year release cycles (e.g. Fedora, Ubuntu) should usually provide reasonably recent versions of OpenVPN.
- * Official Debian and Ubuntu repositories tend to have fairly old OpenVPN versions available
- * The Fedora and Fedora EPEL provides fairly up-to-date OpenVPN releases for supported Fedora and Red Hat Enterprise Linux (including clones such as CentOS, Scientific Linux) releases.
+ There are various repositories available depending on your distribution and the desired version of OpenVPN:
- All packages are available in *amd64/x86_64* flavours. Additionally, *arm64/aarch64* flavours might be available for newer distributions and *i386* flavour might be available for older distributions. Even if a package is built on a particular OS, it does not mean it won't work on older and/or newer versions of the same distro, or even on a different operating system. If you encountered any issues with the package, please file a new [bug report](/TesterDocumentation#Reportingbugs).
+ * OpenVPN Community APT Repositories -- Provides Stable and Testing releases for Debian/Ubuntu
+ * OpenVPN Community Fedora Copr Repositories -- Provides Stable, Testing, and Snapshot releases for Fedora/RHEL
+ * OpenVPN Community openSUSE Buildservice Repositories -- Provides Snapshot releases for openSUSE/SLES and Debian/Ubuntu
- # CentOS / Fedora / Red Hat Enterprise Linux
+ # Repository HOWTOs
- There are two alternatives here for OpenVPN packages. Fedora carries are reasonably up-to-date release in the main repositories. For CentOS and Red Hat Enterprise Linux (RHEL) the [Fedora EPEL](https://fedoraproject.org/wiki/EPEL) repositories which contains the last OpenVPN releases when the distribution was released. All of these packages are considered to be stable for enterprise usage and will essentially just get bug and security fixes during the lifetime of the distribution. OpenVPN major releases will only be added to the next Fedora release.
-
- To get newer releases than the main Fedora and EPEL repositories provides, consider using the OpenVPN packages from the Fedora Copr repository. The Copr repository will always have the latest OpenVPN releases available.
-
- ## Using Fedora EPEL (CentOS / RHEL)
-
- Ensure you have the Fedora EPEL repository enabled. CentOS users may do this easily by installing the `epel-release` package via `yum install`. Red Hat Enterprise Linux users need to install this package manually, as described in the [Fedora EPEL wiki page](https://fedoraproject.org/wiki/EPEL). Then just run `yum install openvpn`.
-
- ## Using Fedora Copr
+ ## Fedora / RHEL: Using Fedora Copr
CentOS/RHEL users: Ensure you have the `yum-plugin-copr` package installed (can be installed via `yum`).
Then run these commands:
```
- [root@host:~]# yum copr enable dsommers/openvpn-release-2.6 # for OpenVPN 2.6 releases
- [root@host:~]# yum copr enable dsommers/openvpn-release # for OpenVPN 2.5 releases
+ [root@host:~]# yum copr enable @OpenVPN/openvpn-release-2.6 # for OpenVPN 2.6 releases
+ [root@host:~]# yum copr enable @OpenVPN/openvpn-beta # for OpenVPN Beta releases
+ [root@host:~]# yum copr enable @OpenVPN/openvpn-git # for OpenVPN Snapshot releases
...
[root@host:~]# yum install openvpn
```
- The [dsommers/openvpn-release-2.6 Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release-2.6/) currently contains the *latest stable OpenVPN* release.
+ The [@OpenVPN/openvpn-release-2.6 Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-release-2.6/) currently contains the *latest stable OpenVPN* release. Note that this repository only contains builds for RHEL (via the EPEL repositories). Fedora releases already contain the latest OpenVPN release.
- To test *OpenVPN beta releases*, the [dsommers/openvpn-beta Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-beta/) contains builds for all recent Fedora, Red hat Enterprise Linux and CentOS/CentOS Stream releases.
+ To test *OpenVPN beta releases*, the [@OpenVPN/openvpn-beta Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-beta/) contains builds. This contains builds for all supported Fedora and RHEL releases so you can test on top of whatever release you're using.
- There are also *nightly builds of the master branch* available in [dsommers/openvpn-git Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-git/). Testing welcome but **not intended for production use**!
+ There are also *nightly builds of the master branch* available in [@OpenVPN/openvpn-git Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-git/). Testing welcome but **not intended for production use**!
If you have OpenVPN already installed, it will be upgraded to the latest available version.
- ### Data Channel Offload support (DCO)
+ ### OpenVPN kernel module (DCO)
- The Data Channel Offload support is available in OpenVPN 2.6 beta releases and newer and in [OpenVPN 3 Linux](/Pages/OpenVPN3Linux). The needed Linux kernel module is available for Fedora and Red Hat Enterprise Linux 8 and newer. To get the needed `kmod-ovpn-dco` package, the `dsommers/openvpn3` Copr repository need to be enabled as well.
+ OpenVPN releases since 2.6 have support for delegating the actual VPN connection to the Kernel for a significant speed-up (this feature is also called "Data Channel Offload" or DCO). You need to install an additional kernel module to use this feature.
+ Note that the module and the related package changed their names between OpenVPN 2.6 and OpenVPN 2.7 since the kernel module underwent massive changes. You can install both modules side-by-side.
+
+ ```
+ [root@host:~]# yum install kmod-ovpn-dco # Install OpenVPN kernel module for OpenVPN 2.6 releases
+ [root@host:~]# yum install kmod-ovpn # Install OpenVPN kernel module for OpenVPN 2.7+ releases
+ ```
- # Debian / Ubuntu: Using OpenVPN apt repositories
- We maintain several OpenVPN (OSS) software repositories. To setup the repositories you need to change to the root user. Typically this is done using *sudo*:
+ ## Debian / Ubuntu: Using OpenVPN apt repositories
+
+ We maintain several OpenVPN software repositories. To setup the repositories you need to change to the root user. Typically this is done using *sudo*:
```
$ sudo -s
@@ 59,13 60,13 @@
```
# mkdir -p /etc/apt/keyrings # directory does not exist on older releases
- # curl -fsSL https://swupdate.openvpn.net/repos/repo-public.gpg | gpg --dearmor > /etc/apt/keyrings/openvpn-repo-public.gpg
+ # curl -fsSL https://swupdate.openvpn.net/repos/repo-public.gpg | tee /etc/apt/keyrings/openvpn-repo-public.asc
```
Next you need to create a sources.list fragment (as root) so that apt can find the new OpenVPN packages. One way to do it is this:
```
- # echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] https://build.openvpn.net/debian/openvpn/<version> <osrelease> main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ # echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] https://build.openvpn.net/debian/openvpn/<version> <osrelease> main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
```
Where **\<arch\>** can be one of
@@ 98,49 99,42 @@
```
# Always get the latest package, even Beta versions
- # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] http://build.openvpn.net/debian/openvpn/testing jammy main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] http://build.openvpn.net/debian/openvpn/testing jammy main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
# Only get a specific version, do not upgrade to newer major version automatically
- # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] http://build.openvpn.net/debian/openvpn/release/2.6 bullseye main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] http://build.openvpn.net/debian/openvpn/release/2.6 bullseye main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
```
- Now you're set for installing OpenVPN. Note that packages built for older operating system releases *might* work just fine on newer release of the same operating system.
-
- ## Installing OpenVPN
-
- On Debian/Ubuntu use
+ Now you're set for installing OpenVPN.
```
$ apt-get update && apt-get install openvpn
```
- To additionally install the DCO kernel driver use
+ ### OpenVPN kernel module (DCO)
+
+ OpenVPN releases since 2.6 have support for delegating the actual VPN connection to the Kernel for a significant speed-up (this feature is also called "Data Channel Offload" or DCO). You need to install an additional kernel module to use this feature.
+ Note that the module and the related package changed their names between OpenVPN 2.6 and OpenVPN 2.7 since the kernel module underwent massive changes. You can install both modules side-by-side.
```
- $ apt-get install openvpn-dco-dkms
+ $ apt-get install openvpn-dco-dkms # Install DCO kernel module for 2.6 versions
+ $ apt-get install ovpn-dkms # Install DCO kernel module for 2.7+ versions
```
-
- ## Notes on expired keys
+ ### Notes on expired keys
If the apt signing key expires, apt will complain when refreshing the package cache (e.g. *apt-get update*). In that case just download the key again as described above.
- ## Debian Snapshot Builds
+ ## Debian/Ubuntu: Using openSUSE Buildservice for master snapshot packages
- Debian snapshot development builds are available as well. To use them:
+ Snapshot packages built from the latest source code for Debian/Ubuntu are managed in different repositories since we use the openSUSE Buildservice to build them.
- ```
- # mkdir -p /etc/apt/keyrings # directory does not exist on older Debian/Ubuntu releases
- # curl -fsSL https://build.openvpn.net/debian/snapshots/snapshots-key.asc > /etc/apt/keyrings/openvpn-repo-snapshots.asc
- # echo "deb [signed-by=/etc/apt/keyrings/openvpn-repo-snapshots.asc] https://build.openvpn.net/debian/snapshots/<osrelease> <osrelease> main" > /etc/apt/sources.list.d/openvpn-snapshots.list
- # apt-get install openvpn
- ```
-
- To test a specific build with a specific patch you might need to install a specific snapshot build. You can do this with apt by providing the exact version to install:
+ You can find a list of supported Debian/Ubuntu Distributions on the [Download page](https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/). Use them as follows (example for Ubuntu 24.04):
```
- # apt-get install openvpn=2.7-1719406367
+ $ sudo -s
+ # mkdir -p /etc/apt/keyrings # directory does not exist on older releases
+ # curl -fsSL https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/xUbuntu_24.04/Release.key | tee /etc/apt/keyrings/obs-isv-openvpn-snapshots.asc
+ # echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/obs-isv-openvpn-snapshots.asc] https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/xUbuntu_24.04 ./" > /etc/apt/sources.list.d/obs-isv-openvpn-snapshots.list
```
- See https://build.openvpn.net/debian/snapshots/ for a current list of valid *osrelease* values. Only *amd64* snapshot builds are available currently.
-
- Note that these are intended to provide an easy way to test patches or latest master, **not for production use**. If you notice any problems, let us know!
+ For more information on package names and installation see above.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9