Install the Okta Privileged Access gateway on Red Hat (RHEL), Alma Linux, Amazon Linux, CentOS Stream, or Oracle Linux
Before you begin, verify that the gateway machine runs a supported operating system version. See Supported operating systems. Amazon Linux is available only on AWS. The other distributions are supported on AWS, Google Cloud, Azure, and on-premises deployments.
There are some known issues when managing Active Directory accounts with Okta Privileged Access that apply to Amazon Linux gateway installations. See Okta Privileged Access - Amazon Linux Gateway Known Issues.
-
Confirm the operating system version and architecture of the gateway machine.
cat /etc/os-release uname -mThe first command returns the distribution name and version. The second command returns the architecture, either
x86_64for Intel or AMD processors, oraarch64for ARM processors. Verify that both values are supported before you continue. -
Add the RPM key.
sudo rpm --import https://dist.scaleft.com/GPG-KEY-OktaPAM-2023 -
Create the repository definition file. Use the stable repository for production installations. Use the preview repository only when you're testing preview features.
Replace PLATFORM-KEY with the platform name for your distribution.
Operating system
Platform name
Alma Linux
almaAmazon Linux
amazonlinuxCentOS Stream
centosOracle Linux
oraclelinuxRed Hat Enterprise Linux
rhelReplace RELEASE-VERSION with the major version of the operating system. Don't include the minor version. For example, for Red Hat Enterprise Linux 8.6, use 8. For Amazon Linux, use 2, 2022, or 2023.
Leave
$basearchas it is. The package manager replaces it with the architecture of the machine. The single quotation marks aroundEOFprevent the shell from expanding$basearchbefore the file is written.Stable
sudo tee /etc/yum.repos.d/oktapam-stable.repo << 'EOF' [oktapam-stable] name=Okta PAM Stable - PLATFORM-KEY RELEASE-VERSION baseurl=https://dist.scaleft.com/repos/rpm/stable/PLATFORM-KEY/RELEASE-VERSION/$basearch gpgcheck=1 repo_gpgcheck=1 enabled=1 gpgkey=https://dist.scaleft.com/GPG-KEY-OktaPAM-2023 EOFPreview
sudo tee /etc/yum.repos.d/oktapam-preview.repo << 'EOF' [oktapam-preview] name=Okta PAM Preview - PLATFORM-KEY RELEASE-VERSION baseurl=https://dist.scaleft.com/repos/rpm/preview/PLATFORM-KEY/RELEASE-VERSION/$basearch gpgcheck=1 repo_gpgcheck=1 enabled=1 gpgkey=https://dist.scaleft.com/GPG-KEY-OktaPAM-2023 EOF -
Update the package metadata and accept the new GPG key. On Amazon Linux 2, use
sudo yum updateinstead.sudo dnf updateVerify that the key fingerprint matches the following before you accept it.
Importing GPG key 0xB8966AE8: Userid : "Okta PAM/ASA Packager (PAM/ASA Package Signing Key) <security+pam-packages-2023@okta.com>" Fingerprint: A3A9 03C2 9B5C AF75 34B9 F393 1983 7E37 B896 6AE8 From : https://dist.scaleft.com/GPG-KEY-OktaPAM-2023Note:If you get 404 errors, verify that PLATFORM-KEY matches the platform name in the preceding table, and that RELEASE-VERSION is a supported major version with no minor version.
-
Install the gateway package. On Amazon Linux 2, which doesn't include dnf, use
sudo yum install scaleft-gatewayinstead.sudo dnf install scaleft-gatewayNote:scaleft-gatewayis the only package required for a gateway. Thescaleft-client-toolsandscaleft-server-toolspackages are separate components, for client machines and managed servers. Install them on the gateway machine only if that machine also acts as a client or as a managed server. - For database integrations, additional configuration is required after installation. See Configure the gateway to support database integrations.
Verify or update the gateway version
Check the version of the gateway that's installed on the machine.
sft-gatewayd --versionTo list the versions available in the repository, run
sdnf --showduplicates list scaleft-gateway.- Update the gateway to the latest available version.
sudo dnf install scaleft-gatewayOn Amazon Linux 2, which doesn't include dnf, use
sudo yum install scaleft-gateway. -
Update the gateway to a specific version. Replace VERSION with the version that you want, for example 1.111.1. Note that the RPM package name joins the version with a hyphen rather than an equals sign.
sudo dnf install scaleft-gateway-VERSION