Skip to main content

Verifying Access Server Downloads with SHA256SUM

Abstract

Official SHA256 checksums for OpenVPN Access Server downloads, including Linux packages, virtual machine images, bundled clients, installation scripts, and post-authentication scripts.

When downloading Access Server files manually, you can verify that the files you receive are authentic and unaltered. One way to do this is to use SHA-256 checksums, which provide a unique signature for each file. You can compare this signature with the one we provide to confirm the integrity of the downloaded files. If the checksum matches, you can be confident that the file is intact and authentic.

SHA256 checksums for Access Server files

Artifacts

Platform

Architecture

Package

SHA256SUM

RHEL 8

x86_64

openvpn-as-3.2.2_413ca39f-1.el8.x86_64.rpm

f87f11a75c648a020ab3275fdba1afa92600681a7f0bdec033240b7a24540614

RHEL 9

x86_64

openvpn-as-3.2.2_413ca39f-1.el9.x86_64.rpm

ca6e1e64d5c51f0ea7c08e9374a4e14d4f2f844752e22783ac5a06a25f38ff7c

RHEL 10

x86_64

openvpn-as-3.2.2_413ca39f-1.el10.x86_64.rpm

bba0282c5b462362c583b76e520147342e34c634d7516455086e0c449a162e46

Debian 12 (Bookworm)

amd64

openvpn-as_3.2.2-413ca39f-Debian12_amd64.deb

2954f804e970ab637e6f66210bdae4aa29beae1739801976cf5b48ab29608df9

Debian 13 (Trixie)

amd64

openvpn-as_3.2.2-413ca39f-Debian13_amd64.deb

260d696d58ab7d5a07a124a7c383393342fa1d668b6e3a8b4cd3ff88eeff3ffd

Ubuntu 22 (Jammy)

amd64

openvpn-as_3.2.2-413ca39f-Ubuntu22_amd64.deb

5cd33eb5482dbf9b668c4c5d360139826cb00227f90bb798540ad903996fb0f0

Ubuntu 22 (Jammy)

arm64

openvpn-as_3.2.2-413ca39f-Ubuntu22_arm64.deb

b5a547ee22a112de7ca15756e8f64e8e535ed3d955bf69f0e823f78069121c77

Ubuntu 24 (Noble)

amd64

openvpn-as_3.2.2-413ca39f-Ubuntu24_amd64.deb

b69be91fe448d56cfcdfec163be622c38d135af8da89343f7967f517b7ffebd6

Ubuntu 24 (Noble)

arm64

openvpn-as_3.2.2-413ca39f-Ubuntu24_arm64.deb

cf7684d6337f146f8f8eab2cf6b4d209a37fa70727171b2aa686ca687d2cf40f

Ubuntu 26 (Resolute)

amd64

openvpn-as_3.2.2-413ca39f-Ubuntu26_amd64.deb

2988e0d451bf62dd335aabb5f8cf183f162050f7d701bbe02e1fdb01321229fd

Ubuntu 26 (Resolute)

arm64

openvpn-as_3.2.2-413ca39f-Ubuntu26_arm64.deb

e24aafce64c4acc2f13fb0ee23d1de957aa9a3c83fa6fc5867dd77f11868b5f1

VMware ESXi

x86_64

as-ubuntu-image-noble-3.1.0.ova

b5e2ebb967229b4838506f8a0a94330b7e3f2b89be1b38283566f48291606027

Hyper-V

x86_64

as-ubuntu-image-noble-3.1.0.vhdx.zip

fcc5b64bb9d3a3db7dd7dae9dc571939abf65d871a8cd868cf9f99cf6c38ef8b

Debian/Ubuntu (clients bundle)

all

openvpn-as-bundled-clients-latest.deb

be1e15752555470bee3527d72e49502648f5b1c26248ff00cee607a97d9b2140

RHEL (clients bundle)

all

openvpn-as-bundled-clients-latest.rpm

843790fa48fed3c784b00d08b9a62f26e499406707d812f515a64f7e32b52418

Scripts

File Name

SHA256SUM

Version

install.sh

c2a4da11e48f83ae52b7a1e18f6842036fecf460c7c2c72181dba3ed0b755071

2.1

bridge-down.sh

279a3321fd2760d6eb1acb0ba71c9b862bc33c9ced1efa775142d4697b28a848

1.0

bridge-up.sh

5538ee6e9d6cb2e2bb5882d54c69fd044ca89375c1406ad5432877d01369c091

1.0

aws-updown.sh

8ecd0465d6ba39ba376c76f129aaa6ac303c47f9783810b25fe1591e6270a77b

1.0

ipsec.conf

4da7378f563f079ecd635b2fb7201308ab33269b707a71b687c234a6dfb9167d

1.1

ipsec.secrets

46fe56cd944fb8c87c7fbf24d50c9730e361228be5b57a5de04dac0f901fff35

1.0

pascrs.py

a260aaf39d7b8d3cf6474a852c69a50c7929c4839d5a323a1671fbc69949e9b2

1.0

pasvar.py

4c1c45fa98b39d3372a7da1fcc6437241cb46a111ae98cb60a3e08c5428c0a44

1.0

post_auth_custom_auth.py

55f2fdb1d7b38d635b57443f4ab0e9aee2717d94e06ec5b14c36ca4a36397a08

1.0

post_auth_ip_address_checking.py

d76ceaa9672b608c9f4a6415decffb12c3dc55987384533ad917fe2feb6683ab

1.1

post_auth_ldap_autologin_dbsave.py

df0c7cbadfb1afa2ac11eeb8bf9fc89ba350cb8a0e23a7549f75433636bbdaef

1.3

post_auth_mac_address_checking.py

32168e06f790042d0d63c621484d3c8f6243880ca1207e34b91043e5b53b155c

2.2

post_auth_pas_only.py

b4cf2e3d497516c59a4a7ba55aa8a3cbf538940122543652ab03d0f6eabb486f

1.1

post_auth_radius_mapping.py

dd93bd12a54f3ed0b28cc492b3c4b02a0169924b8734daf53aaab628a2de477e

2.3

post_auth_saml_group_mapping.py

e8935204d951fd2e59e93a010f812eb87437c098ee23d8fe8e1aa4a485db882e

1.2

post_auth_x509_group.py

97266d0235fb47dd00687a737a43cc54a06a036e0c3b9a2cc83d8056b855a89e

1.0

post_auth_x509.py

22bd5dab4fc2bf299c76c793e72ba712038d700ac709e9034797e5a0dc731a67

1.0

SHA256SUM is a tool that generates a 256-bit hash (a unique string of characters) for a file. A calculation based on the file's contents generates this hash, and if even one byte of the file changes, the hash will be completely different. By comparing the hash of your downloaded file with the official hash provided by us, you can verify that the file hasn't been altered or corrupted.

  1. Verifying the file ensures it wasn't corrupted during the download process.

  2. Comparing the checksum helps protect against any unauthorized modifications to the file.

  3. Downloading a file from an official source may not always guarantee safety if the file is intercepted and altered. To ensure the file is legitimate, you should verify the checksum.

We recommend using the install.sh script from the Access Server Portal, as it leverages the operating system's built-in package manager to automatically authenticate packages with a trusted signing key, eliminating the need for manual verification. However, if preferred, you can manually validate the install.sh script's integrity using the SHA256 checksum provided in the table above.

For offline installations, you can manually check the integrity of any downloaded files using the provided SHA256 hashes. To verify a downloaded file, follow these steps:

  1. Connect to the console and get root privileges.

  2. Download the install script from the Access Server portal or manually download the Access Server file.Situation: I don't want to use your Linux installation script; how can I install it manually?

  3. Calculate the checksum of your downloaded file:

    sha256sum openvpn-as-x.deb1
    

    1

    Replace the filename with the file you want to check the integrity of.

  4. After running the command, the tool returns a checksum.

  5. Compare the checksum with the one listed for the file in the scripts table. If it matches, your file is authentic.

  • If you're using the installation script from the Access Server Portal, you can verify the integrity of install.sh by comparing the SHA256SUM and version from the scripts table.

  • The easiest way to ensure the authenticity of Access Server installation files is to use our install script, which leverages the operating system's built-in package manager to authenticate downloaded packages using a trusted signing key. This eliminates the need for manual file verification. However, suppose you prefer downloading the installation files manually, such as for offline installations. In that case, you can authenticate their integrity by comparing the files against the provided SHA256 hashes to ensure they haven't been tampered with or corrupted.