Skip to main content

Verifying Access Server Downloads with SHA256SUM

Abstract

Official SHA256 checksums for OpenVPN Access Server downloads, including Linux packages, virtual machine images, bundled clients, installation scripts, and post-authentication scripts.

When downloading Access Server files manually, you can verify that the files you receive are authentic and unaltered. One way to do this is to use SHA-256 checksums, which provide a unique signature for each file. You can compare this signature with the one we provide to confirm the integrity of the downloaded files. If the checksum matches, you can be confident that the file is intact and authentic.

SHA256 checksums for Access Server files

Artifacts

Platform

Architecture

Package

SHA256SUM

RHEL 8

x86_64

openvpn-as-3.2.3_8444f22d-1.el8.x86_64.rpm

315e5b52160f761d8cd53c5b7d9e000b21f61351063e58a333f0d2b54b9d3dc9

RHEL 9

x86_64

openvpn-as-3.2.3_8444f22d-1.el9.x86_64.rpm

374f682461d1e91d5d100f85fb542b3402e0c25f96302264bc89d5a8f4083fd2

RHEL 10

x86_64

openvpn-as-3.2.3_8444f22d-1.el10.x86_64.rpm

c7899d8555a9a0bb48f8b326db15ea882ac2f3093501aba533a8f0702c2c217a

Debian 12 (Bookworm)

amd64

openvpn-as_3.2.3-8444f22d-Debian12_amd64.deb

5d4b1f09cd437461d9a463ed521740c882ce939bc22387059c141f7168fb328b

Debian 13 (Trixie)

amd64

openvpn-as_3.2.3-8444f22d-Debian13_amd64.deb

458252e58b575b7f6ee436d3d93192b1598da0b95f04c1cfbe3e7b9f2d8f447c

Ubuntu 22 (Jammy)

amd64

openvpn-as_3.2.3-8444f22d-Ubuntu22_amd64.deb

ca87fd063f66149b2db713c52be4994d49641999adcbaaceb856f363eefd1a77

Ubuntu 22 (Jammy)

arm64

openvpn-as_3.2.3-8444f22d-Ubuntu22_arm64.deb

58a1957d36c1d2dd929e767414c0ae48a13fefc222070c853161246dfd8fe535

Ubuntu 24 (Noble)

amd64

openvpn-as_3.2.3-8444f22d-Ubuntu24_amd64.deb

448251212c66cc9c55259185b5ab27c5b8b947228684838195bc7f7827623bd4

Ubuntu 24 (Noble)

arm64

openvpn-as_3.2.3-8444f22d-Ubuntu24_arm64.deb

3ac97cdfb24e07fb420764814f68e1ac80dc28748e722d39c19e13e921bbbfb4

Ubuntu 26 (Resolute)

amd64

openvpn-as_3.2.3-8444f22d-Ubuntu26_amd64.deb

d4fcf4a6f4b959686701e35f85f5c7bfb4372d661c4f822bd0aa4c6aed8bf126

Ubuntu 26 (Resolute)

arm64

openvpn-as_3.2.3-8444f22d-Ubuntu26_arm64.deb

7faa78cabe4f6526abe4ac2cef15565ee687c18ec4bc3c088aef8d780ef7233b

VMware ESXi

x86_64

as-ubuntu-image-noble-3.2.2.ova

323b6af7dffcfad59d2ccfdeebc8e2835203407b4265c3e0ed182196b8617f40

Hyper-V

x86_64

as-ubuntu-image-noble-3.2.2.vhdx.zip

a5993e04fb486ca31f1eeb25e567b06ac09e155e64d722314e2ca8cd5c7d75d3

Debian/Ubuntu (clients bundle)

all

openvpn-as-bundled-clients-latest.deb

be1e15752555470bee3527d72e49502648f5b1c26248ff00cee607a97d9b2140

RHEL (clients bundle)

all

openvpn-as-bundled-clients-latest.rpm

843790fa48fed3c784b00d08b9a62f26e499406707d812f515a64f7e32b52418

Scripts

File Name

SHA256SUM

Version

install.sh

55e7779b53012c2b9168013bff2b2ac2d9bfe7bc574f116cbafe85b6e77173d7

2.4

bridge-down.sh

279a3321fd2760d6eb1acb0ba71c9b862bc33c9ced1efa775142d4697b28a848

1.0

bridge-up.sh

5538ee6e9d6cb2e2bb5882d54c69fd044ca89375c1406ad5432877d01369c091

1.0

aws-updown.sh

8ecd0465d6ba39ba376c76f129aaa6ac303c47f9783810b25fe1591e6270a77b

1.0

ipsec.conf

4da7378f563f079ecd635b2fb7201308ab33269b707a71b687c234a6dfb9167d

1.1

ipsec.secrets

46fe56cd944fb8c87c7fbf24d50c9730e361228be5b57a5de04dac0f901fff35

1.0

pascrs.py

a260aaf39d7b8d3cf6474a852c69a50c7929c4839d5a323a1671fbc69949e9b2

1.0

pasvar.py

4c1c45fa98b39d3372a7da1fcc6437241cb46a111ae98cb60a3e08c5428c0a44

1.0

post_auth_custom_auth.py

55f2fdb1d7b38d635b57443f4ab0e9aee2717d94e06ec5b14c36ca4a36397a08

1.0

post_auth_ip_address_checking.py

d76ceaa9672b608c9f4a6415decffb12c3dc55987384533ad917fe2feb6683ab

1.1

post_auth_ldap_autologin_dbsave.py

df0c7cbadfb1afa2ac11eeb8bf9fc89ba350cb8a0e23a7549f75433636bbdaef

1.3

post_auth_mac_address_checking.py

32168e06f790042d0d63c621484d3c8f6243880ca1207e34b91043e5b53b155c

2.2

post_auth_pas_only.py

b4cf2e3d497516c59a4a7ba55aa8a3cbf538940122543652ab03d0f6eabb486f

1.1

post_auth_radius_mapping.py

dd93bd12a54f3ed0b28cc492b3c4b02a0169924b8734daf53aaab628a2de477e

2.3

post_auth_saml_group_mapping.py

e8935204d951fd2e59e93a010f812eb87437c098ee23d8fe8e1aa4a485db882e

1.2

post_auth_x509_group.py

97266d0235fb47dd00687a737a43cc54a06a036e0c3b9a2cc83d8056b855a89e

1.0

post_auth_x509.py

22bd5dab4fc2bf299c76c793e72ba712038d700ac709e9034797e5a0dc731a67

1.0

SHA256SUM is a tool that generates a 256-bit hash (a unique string of characters) for a file. A calculation based on the file's contents generates this hash, and if even one byte of the file changes, the hash will be completely different. By comparing the hash of your downloaded file with the official hash provided by us, you can verify that the file hasn't been altered or corrupted.

  1. Verifying the file ensures it wasn't corrupted during the download process.

  2. Comparing the checksum helps protect against any unauthorized modifications to the file.

  3. Downloading a file from an official source may not always guarantee safety if the file is intercepted and altered. To ensure the file is legitimate, you should verify the checksum.

We recommend using the install.sh script from the Access Server Portal, as it leverages the operating system's built-in package manager to automatically authenticate packages with a trusted signing key, eliminating the need for manual verification. However, if preferred, you can manually validate the install.sh script's integrity using the SHA256 checksum provided in the table above.

For offline installations, you can manually check the integrity of any downloaded files using the provided SHA256 hashes. To verify a downloaded file, follow these steps:

  1. Connect to the console and get root privileges.

  2. Download the install script from the Access Server portal or manually download the Access Server file.

  3. Calculate the checksum of your downloaded file:

    sha256sum openvpn-as-x.deb1
    

    1

    Replace the filename with the file you want to check the integrity of.

  4. After running the command, the tool returns a checksum.

  5. Compare the checksum with the one listed for the file in the scripts table. If it matches, your file is authentic.

  • If you're using the installation script from the Access Server Portal, you can verify the integrity of install.sh by comparing the SHA256SUM and version from the scripts table.

  • The easiest way to ensure the authenticity of Access Server installation files is to use our install script, which leverages the operating system's built-in package manager to authenticate downloaded packages using a trusted signing key. This eliminates the need for manual file verification. However, suppose you prefer downloading the installation files manually, such as for offline installations. In that case, you can authenticate their integrity by comparing the files against the provided SHA256 hashes to ensure they haven't been tampered with or corrupted.