Blame
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 1 | # Introduction |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 2 | |
| 2657a3 | flichtenheld | 2025-05-28 21:15:32 | 3 | This page contains instructions for using OpenVPN project's own software repositories. |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 4 | For OpenVPN 3 Linux, see the dedicated [OpenVPN 3 Linux](/Pages/OpenVPN3Linux) page. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 5 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 6 | The OpenVPN project provides the latest OpenVPN releases (and development snapshots) as packages for major Linux distributions. This allow you to use more up-to-date version of OpenVPN than what is typically available in your distribution's repositories. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 7 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 8 | Note that this is mostly interesting for users of distribution releases with long release cycles (e.g. Debian, Ubuntu LTS, RHEL). Distributions with rolling releases (e.g. Arch, openSUSE Tumbleweed) or half-year release cycles (e.g. Fedora, Ubuntu) should usually provide reasonably recent versions of OpenVPN. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 9 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 10 | There are various repositories available depending on your distribution and the desired version of OpenVPN: |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 11 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 12 | * OpenVPN Community APT Repositories -- Provides Stable and Testing releases for Debian/Ubuntu |
| 13 | * OpenVPN Community Fedora Copr Repositories -- Provides Stable, Testing, and Snapshot releases for Fedora/RHEL |
|||
| 98fd5f | flichtenheld | 2025-05-28 21:33:25 | 14 | * OpenVPN Community openSUSE Buildservice Repositories -- Provides Testing and Snapshot releases for openSUSE/SLES and Debian/Ubuntu |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 15 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 16 | # Repository HOWTOs |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 17 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 18 | ## Fedora / RHEL: Using Fedora Copr |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 19 | |
| 20 | CentOS/RHEL users: Ensure you have the `yum-plugin-copr` package installed (can be installed via `yum`). |
|||
| 21 | ||||
| 22 | Then run these commands: |
|||
| c3f8c6 | flichtenheld | 2025-05-21 14:14:08 | 23 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 24 | ``` |
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 25 | # yum copr enable @OpenVPN/openvpn-release-2.7 # for OpenVPN 2.7 releases |
| c3f8c6 | flichtenheld | 2025-05-21 14:14:08 | 26 | # yum copr enable @OpenVPN/openvpn-release-2.6 # for OpenVPN 2.6 releases |
| 98fd5f | flichtenheld | 2025-05-28 21:33:25 | 27 | # yum copr enable @OpenVPN/openvpn-beta # for OpenVPN Alpha and Beta releases |
| c3f8c6 | flichtenheld | 2025-05-21 14:14:08 | 28 | # yum copr enable @OpenVPN/openvpn-git # for OpenVPN Snapshot releases |
| 29 | ... |
|||
| 30 | # yum install openvpn |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 31 | ``` |
| 32 | ||||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 33 | The [@OpenVPN/openvpn-release-2.7 Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-release-2.7/) currently contains the *latest stable OpenVPN* release. Note that this repository only contains builds for RHEL (via the EPEL repositories). Fedora releases already contain the latest OpenVPN release. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 34 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 35 | To test *OpenVPN beta releases*, the [@OpenVPN/openvpn-beta Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-beta/) contains builds. This contains builds for all supported Fedora and RHEL releases so you can test on top of whatever release you're using. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 36 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 37 | There are also *nightly builds of the master branch* available in [@OpenVPN/openvpn-git Copr repository](https://copr.fedorainfracloud.org/coprs/g/OpenVPN/openvpn-git/). Testing welcome but **not intended for production use**! |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 38 | |
| 39 | If you have OpenVPN already installed, it will be upgraded to the latest available version. |
|||
| 40 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 41 | ### OpenVPN kernel module (DCO) |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 42 | |
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 43 | OpenVPN releases since 2.6 have support for delegating the actual VPN connection to the Kernel for a significant speed-up (this feature is also called "Data Channel Offload" or DCO). Since Linux 6.16 this support is contained in the upstream kernel. The version shipped together with the Linux kernel is supported starting from OpenVPN 2.7. |
| 44 | ||||
| 45 | We offer out-of-tree packages if you are on an older kernel version than 6.16, or you want to use the latest version of the module together with older kernel versions, or you want to use DCO together with OpenVPN 2.6. |
|||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 46 | Note that the module and the related package changed their names between OpenVPN 2.6 and OpenVPN 2.7 since the kernel module underwent massive changes. You can install both modules side-by-side. |
| 47 | ||||
| 48 | ``` |
|||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 49 | # yum install kmod-ovpn # Install OpenVPN kernel module for OpenVPN 2.7+ releases (not generally needed when using Linux kernel >= 6.16) |
| c3f8c6 | flichtenheld | 2025-05-21 14:14:08 | 50 | # yum install kmod-ovpn-dco # Install OpenVPN kernel module for OpenVPN 2.6 releases |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 51 | ``` |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 52 | |
| 53 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 54 | ## Debian / Ubuntu: Using OpenVPN apt repositories |
| 55 | ||||
| 56 | We maintain several OpenVPN software repositories. To setup the repositories you need to change to the root user. Typically this is done using *sudo*: |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 57 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 58 | ``` |
| 59 | $ sudo -s |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 60 | ``` |
| 61 | ||||
| 62 | Then import the public GPG key that is used to sign the packages: |
|||
| 63 | ||||
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 64 | ``` |
| 65 | # mkdir -p /etc/apt/keyrings # directory does not exist on older releases |
|||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 66 | # curl -fsSL https://swupdate.openvpn.net/repos/repo-public.gpg | tee /etc/apt/keyrings/openvpn-repo-public.asc |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 67 | ``` |
| 68 | ||||
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 69 | Next you need to create a sources.list fragment (as root) so that apt can find the new OpenVPN packages. One way to do it is this: |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 70 | |
| 71 | ``` |
|||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 72 | # echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] https://build.openvpn.net/debian/openvpn/<version> <osrelease> main" > /etc/apt/sources.list.d/openvpn-aptrepo.list |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 73 | ``` |
| 74 | ||||
| 75 | Where **\<arch\>** can be one of |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 76 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 77 | 1. **amd64** |
| 78 | 1. **arm64** |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 79 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 80 | Where **\<version\>** can be one of |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 81 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 82 | 1. **stable**: stable releases only - no alphas, betas or RCs |
| 83 | 1. **testing**: latest releases, including alphas/betas/RCs |
|||
| 84 | 1. **release/2.6**: OpenVPN 2.6 releases, including alphas/betas/RCs |
|||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 85 | 1. **release/2.7**: OpenVPN 2.7 releases, including alphas/betas/RCs |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 86 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 87 | and **\<osrelease\>** depends your distribution: |
| 88 | ||||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 89 | * **bullseye** (Debian 11.x) |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 90 | * **bookworm** (Debian 12.x) |
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 91 | * **trixie** (Debian 13.x) |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 92 | * **focal** (Ubuntu 20.04 LTS) |
| 93 | * **jammy** (Ubuntu 22.04 LTS) |
|||
| 94 | * **noble** (Ubuntu 24.04 LTS) |
|||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 95 | * **questing** (Ubuntu 25.10) |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 96 | |
| 97 | This list may be incomplete. Please check the [http://build.openvpn.net/debian/openvpn/release/ repository web page] for the complete list of releases. |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 98 | |
| 99 | Examples: |
|||
| 100 | ||||
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 101 | ``` |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 102 | # Always get the latest package, even Beta versions |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 103 | # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] http://build.openvpn.net/debian/openvpn/testing jammy main" > /etc/apt/sources.list.d/openvpn-aptrepo.list |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 104 | # Only get a specific version, do not upgrade to newer major version automatically |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 105 | # echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.asc] http://build.openvpn.net/debian/openvpn/release/2.6 bullseye main" > /etc/apt/sources.list.d/openvpn-aptrepo.list |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 106 | ``` |
| 107 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 108 | Now you're set for installing OpenVPN. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 109 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 110 | ``` |
| 111 | $ apt-get update && apt-get install openvpn |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 112 | ``` |
| 113 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 114 | ### OpenVPN kernel module (DCO) |
| 115 | ||||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 116 | OpenVPN releases since 2.6 have support for delegating the actual VPN connection to the Kernel for a significant speed-up (this feature is also called "Data Channel Offload" or DCO). Since Linux 6.16 this support is contained in the upstream kernel. The version shipped together with the Linux kernel is supported starting from OpenVPN 2.7. |
| 117 | ||||
| 118 | We offer out-of-tree packages if you are on an older kernel version than 6.16, or you want to use the latest version of the module together with older kernel versions, or you want to use DCO together with OpenVPN 2.6. |
|||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 119 | Note that the module and the related package changed their names between OpenVPN 2.6 and OpenVPN 2.7 since the kernel module underwent massive changes. You can install both modules side-by-side. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 120 | |
| 121 | ``` |
|||
| d64e2e | flichtenheld | 2026-03-12 10:58:47 | 122 | $ apt-get install ovpn-dkms # Install DCO kernel module for 2.7+ versions (not generally needed when using Linux kernel >= 6.16) |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 123 | $ apt-get install openvpn-dco-dkms # Install DCO kernel module for 2.6 versions |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 124 | ``` |
| 125 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 126 | ### Notes on expired keys |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 127 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 128 | If the apt signing key expires, apt will complain when refreshing the package cache (e.g. *apt-get update*). In that case just download the key again as described above. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 129 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 130 | ## Debian/Ubuntu: Using openSUSE Buildservice for master snapshot packages |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 131 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 132 | Snapshot packages built from the latest source code for Debian/Ubuntu are managed in different repositories since we use the openSUSE Buildservice to build them. |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 133 | |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 134 | You can find a list of supported Debian/Ubuntu Distributions on the [Download page](https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/). Use them as follows (example for Ubuntu 24.04): |
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 135 | |
| d82394 | Samuli Seppänen | 2025-02-24 12:39:35 | 136 | ``` |
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 137 | $ sudo -s |
| 138 | # mkdir -p /etc/apt/keyrings # directory does not exist on older releases |
|||
| 139 | # curl -fsSL https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/xUbuntu_24.04/Release.key | tee /etc/apt/keyrings/obs-isv-openvpn-snapshots.asc |
|||
| 140 | # echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/obs-isv-openvpn-snapshots.asc] https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/xUbuntu_24.04 ./" > /etc/apt/sources.list.d/obs-isv-openvpn-snapshots.list |
|||
| 9ad98e | Samuli Seppänen | 2025-01-29 12:45:51 | 141 | ``` |
| 142 | ||||
| ec0751 | flichtenheld | 2025-05-21 14:11:29 | 143 | For more information on package names and installation see above. |
| 008ed7 | flichtenheld | 2025-05-21 16:18:51 | 144 | |
| 145 | ## openSUSE/SLES: Using openSUSE Buildservice |
|||
| 146 | ||||
| 525aaf | flichtenheld | 2025-12-16 14:26:49 | 147 | Release and snapshot packages built from the latest source code are provided by the Community for openSUSE/SLES. The official repositories for the rolling distributions (openSUSE Tumbleweed/Slowroll/Factory) should have the latest stable OpenVPN available. |
| 008ed7 | flichtenheld | 2025-05-21 16:18:51 | 148 | |
| 525aaf | flichtenheld | 2025-12-16 14:26:49 | 149 | To install the packages go to the [Stable Download page](https://download.opensuse.org/repositories/isv:/OpenVPN:/Stable/), [Beta Download page](https://download.opensuse.org/repositories/isv:/OpenVPN:/Beta/) or [Snapshots Download page](https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/) and choose your distribution. Use them as follows (example for openSUSE Tumbleweed): |
| 008ed7 | flichtenheld | 2025-05-21 16:18:51 | 150 | |
| 151 | ``` |
|||
| 525aaf | flichtenheld | 2025-12-16 14:26:49 | 152 | # For stable releases: |
| 153 | # zypper addrepo https://download.opensuse.org/repositories/isv:/OpenVPN:/Stable/openSUSE_Tumbleweed/isv:OpenVPN:Stable.repo |
|||
| c203fe | flichtenheld | 2025-05-28 21:44:25 | 154 | # For Alpha/Beta releases: |
| 333789 | flichtenheld | 2025-05-28 21:43:57 | 155 | # zypper addrepo https://download.opensuse.org/repositories/isv:/OpenVPN:/Beta/openSUSE_Tumbleweed/isv:OpenVPN:Beta.repo |
| c203fe | flichtenheld | 2025-05-28 21:44:25 | 156 | # For snapshot packages: |
| 333789 | flichtenheld | 2025-05-28 21:43:57 | 157 | # zypper addrepo https://download.opensuse.org/repositories/isv:/OpenVPN:/Snapshots/openSUSE_Tumbleweed/isv:OpenVPN:Snapshots.repo |
| 158 | # zypper install openvpn |
|||
| 159 | # zypper install ovpn-kmp-default # pre-compiled DCO kernel module |
|||
| 008ed7 | flichtenheld | 2025-05-21 16:18:51 | 160 | ``` |
