Blame

469c6b novaflash 2025-09-25 08:09:53 1
# Use signature files to verify authenticity of files
3ac5e4 novaflash 2025-09-25 08:07:32 2
469c6b novaflash 2025-09-25 08:09:53 3
All current OpenVPN (OSS) source packages and Windows installers have been signed with the [Security mailing list GPG key](https://keys.openpgp.org/vks/v1/by-fingerprint/F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7):
3ac5e4 novaflash 2025-09-25 08:07:32 4
82488a novaflash 2025-09-25 08:11:27 5
Fingerprint F554 A368 7412 CFFE BDEF E0A3 12F5 F7B4 2F2B 01E7
6
If you have intentionally downloaded an old version of OpenVPN and the signature does not match with this key, please look at the notes at the bottom of this article.
3ac5e4 novaflash 2025-09-25 08:07:32 7
2fd0d4 novaflash 2025-09-25 08:08:31 8
# Verifying file signatures
9
3ac5e4 novaflash 2025-09-25 08:07:32 10
Signature verification can be performed by PGP or GnuPG once you have the correct key in your trusted keyring. To do this, you can obtain the correct key file, like our security mailing list GPG key mentioned above, and importing it:
11
7b8db1 novaflash 2025-09-25 08:12:38 12
`wget -O security-openvpn-net.asc https://keys.openpgp.org/vks/v1/by-fingerprint/F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7`
c76949 novaflash 2025-09-25 08:12:45 13
7b8db1 novaflash 2025-09-25 08:12:38 14
`gpg --import security-openvpn-net.asc`
2fd0d4 novaflash 2025-09-25 08:08:31 15
3ac5e4 novaflash 2025-09-25 08:07:32 16
Now you can download the open source installer file or tarball you wish to check, along with its signature file, and have them in the same location. Then you can run a verification with the signature file belonging to the downloaded file you want to check:
17
18
gpg (.asc file)
2fd0d4 novaflash 2025-09-25 08:08:31 19
3ac5e4 novaflash 2025-09-25 08:07:32 20
Make sure you have the corresponding OpenVPN package in the same directory. The GnuPG signature files for the OpenVPN file releases are available on the download page right next to the download button. If the verification succeeds you should see some message like this somewhere in the output:
21
d88e52 novaflash 2025-09-25 08:11:40 22
`gpg: Good signature from "OpenVPN - Security Mailing List <security@openvpn.net>"`
2fdce5 novaflash 2025-09-25 08:11:56 23
000344 novaflash 2025-09-25 08:12:23 24
#
25
26
#
82488a novaflash 2025-09-25 08:11:27 27
28
# Old signatures for old releases
29
30
James Yonan's PGP key (for 1.5.0 -> 2.3_alpha1, key ID 1FBF51F3, fingerprint C699 B264 0C6D 404E 6454 A9AD 1D0B 4996 1FBF 51F3)
31
Samuli Seppänen's old PGP key (2.3_alpha2 and later, key ID 198D22A3, fingerprint 0330 0E11 FED1 6F59 715F 9996 C29D 97ED 198D 22A3)
32
Samuli Seppänen's new PGP key (2,3.15 Windows installers, 2.4.1, 2.4.2: key ID 40864578 , fingerprint 6D04 F8F1 B017 3111 F499 795E 2958 4D9F 4086 4578)
33
Security mailing list GPG key (2.3.15 tarballs, 2.3.16+, 2.4.3+, key ID 2F2B01E7, fingerprint F554 A368 7412 CFFE BDEF E0A3 12F5 F7B4 2F2B 01E7)