Install the Okta Privileged Access gateway on Red Hat (RHEL), Alma Linux, Amazon Linux, CentOS Stream, or Oracle Linux

Before you begin, verify that the gateway machine runs a supported operating system version. See Supported operating systems. Amazon Linux is available only on AWS. The other distributions are supported on AWS, Google Cloud, Azure, and on-premises deployments.

  1. Confirm the operating system version and architecture of the gateway machine.

    cat /etc/os-release
    uname -m

    The first command returns the distribution name and version. The second command returns the architecture, either x86_64 for Intel or AMD processors, or aarch64 for ARM processors. Verify that both values are supported before you continue.

  2. Add the RPM key.

    sudo rpm --import https://dist.scaleft.com/GPG-KEY-OktaPAM-2023
  3. Create the repository definition file. Use the stable repository for production installations. Use the preview repository only when you're testing preview features.

    Replace PLATFORM-KEY with the platform name for your distribution.

    Operating system

    Platform name

    Alma Linux

    alma

    Amazon Linux

    amazonlinux

    CentOS Stream

    centos

    Oracle Linux

    oraclelinux

    Red Hat Enterprise Linux

    rhel

    Replace RELEASE-VERSION with the major version of the operating system. Don't include the minor version. For example, for Red Hat Enterprise Linux 8.6, use 8. For Amazon Linux, use 2, 2022, or 2023.

    Leave $basearch as it is. The package manager replaces it with the architecture of the machine. The single quotation marks around EOF prevent the shell from expanding $basearch before the file is written.

    Stable

    sudo tee /etc/yum.repos.d/oktapam-stable.repo << 'EOF'
    [oktapam-stable]
    name=Okta PAM Stable - PLATFORM-KEY RELEASE-VERSION
    baseurl=https://dist.scaleft.com/repos/rpm/stable/PLATFORM-KEY/RELEASE-VERSION/$basearch
    gpgcheck=1
    repo_gpgcheck=1
    enabled=1
    gpgkey=https://dist.scaleft.com/GPG-KEY-OktaPAM-2023
    EOF

    Preview

    sudo tee /etc/yum.repos.d/oktapam-preview.repo << 'EOF'
    [oktapam-preview]
    name=Okta PAM Preview - PLATFORM-KEY RELEASE-VERSION
    baseurl=https://dist.scaleft.com/repos/rpm/preview/PLATFORM-KEY/RELEASE-VERSION/$basearch
    gpgcheck=1
    repo_gpgcheck=1
    enabled=1
    gpgkey=https://dist.scaleft.com/GPG-KEY-OktaPAM-2023
    EOF
  4. Update the package metadata and accept the new GPG key. On Amazon Linux 2, use sudo yum update instead.

    sudo dnf update

    Verify that the key fingerprint matches the following before you accept it.

    Importing GPG key 0xB8966AE8:
     Userid     : "Okta PAM/ASA Packager (PAM/ASA Package Signing Key) <security+pam-packages-2023@okta.com>"
     Fingerprint: A3A9 03C2 9B5C AF75 34B9 F393 1983 7E37 B896 6AE8
     From       : https://dist.scaleft.com/GPG-KEY-OktaPAM-2023
    
  5. Install the gateway package. On Amazon Linux 2, which doesn't include dnf, use sudo yum install scaleft-gateway instead.

    sudo dnf install scaleft-gateway
  6. For database integrations, additional configuration is required after installation. See Configure the gateway to support database integrations.

Verify or update the gateway version

  1. Check the version of the gateway that's installed on the machine.

    sft-gatewayd --version

    To list the versions available in the repository, run sdnf --showduplicates list scaleft-gateway.

  2. Update the gateway to the latest available version.
    sudo dnf install scaleft-gateway

    On Amazon Linux 2, which doesn't include dnf, use sudo yum install scaleft-gateway.

  3. Update the gateway to a specific version. Replace VERSION with the version that you want, for example 1.111.1. Note that the RPM package name joins the version with a hyphen rather than an equals sign.

    sudo dnf install scaleft-gateway-VERSION