OpenVPN Security Advisory: Dec 14, 2018
Action needed: Important update for OpenVPN Access Server

GnuPG Public Key

All current OpenVPN (OSS) source packages and Windows installers have been signed with the Security mailing list GPG key:

If you have intentionally downloaded an old version of OpenVPN and the signature does not match with this key, please read this article really carefully.

Verifying file signatures

Signature verification can be performed by PGP or GnuPG once you have the correct key in your trusted keyring. To do this you can obtain the correct key file, like for example our security mailing list GPG key mentioned above, and importing it:

$ gpg --import keyname.asc

Now you can download the open source installer file or tarball you wish to check, along with its signature file, and have them in the same location. Then you can run a verification with the signature file belonging to the downloaded file you want to check:

$ gpg -v --verify [.asc file]

Make sure you have the corresponding OpenVPN package in the same directory. GnuPG signature files for OpenVPN file releases are available on the download page.

If it checks out GPG will let you know and show the primary key and its sub key. The primary key should have the fingerprint mentioned in the beginning of this article.

 

Share