Install the Okta Privileged Access gateway on Ubuntu or Debian

Before you begin, verify that the gateway machine runs a supported operating system version. See Supported operating systems. Ubuntu and Debian are supported on AWS, Google Cloud, Azure, and on-premises deployments.

  1. Confirm the operating system version and architecture of the gateway machine.

    cat /etc/os-release
    uname -m

    The first command returns the distribution name, version, and version codename. The second command returns the architecture. Packages are published for the amd64 and arm64 architectures, which uname reports as x86_64 and aarch64. Verify that both values are supported before you continue.

  2. Add the Okta Privileged Access repository key.

    curl -fsSL https://dist.scaleft.com/GPG-KEY-OktaPAM-2023 | gpg --dearmor | sudo tee /usr/share/keyrings/oktapam-2023-archive-keyring.gpg > /dev/null
  3. Create a package resource list entry. Use the stable repository for production installations. Use the preview repository only when you're testing preview features.

    Replace DISTRIBUTION with the distribution name for your operating system version. This is the same value that cat /etc/os-release returns as VERSION_CODENAME.

    Operating system

    Version

    Distribution name

    Ubuntu

    16.04

    xenial

    Ubuntu

    18.04

    bionic

    Ubuntu

    20.04

    focal

    Ubuntu

    22.04

    jammy

    Ubuntu

    24.04

    noble

    Ubuntu

    26.04

    resolute

    Debian

    11

    bullseye

    Debian

    12

    bookworm

    Debian

    13

    trixie

    Stable

    echo "deb [signed-by=/usr/share/keyrings/oktapam-2023-archive-keyring.gpg] https://dist.scaleft.com/repos/deb DISTRIBUTION okta" | sudo tee /etc/apt/sources.list.d/oktapam-stable.list

    Preview

    echo "deb [signed-by=/usr/share/keyrings/oktapam-2023-archive-keyring.gpg] https://dist.scaleft.com/repos/deb DISTRIBUTION okta-preview" | sudo tee /etc/apt/sources.list.d/oktapam-preview.list
  4. Update the list of available packages.

    sudo apt-get update
  5. Verify that the gateway package is available from the repository you added.

    apt-cache policy scaleft-gateway

    The output lists a candidate version and the dist.scaleft.com repository. If the candidate is (none), the distribution name in step 3 is incorrect, or the update in step 4 failed.

  6. Install the gateway package.

    sudo apt-get install scaleft-gateway
  7. For database integrations, additional configuration is required after installation. See Configure the gateway to support database integrations.

Verify or update the gateway version

  1. Check the version of the gateway that's installed on the machine.

    sft-gatewayd --version

    To list the versions available in the repository, run apt-cache madison scaleft-gateway.

  2. Update the gateway to the latest available version.
    sudo dnf install scaleft-gateway
  3. Update the gateway to a specific version. Replace VERSION with the version that you want, for example 1.111.1. Note that the RPM package name joins the version with a hyphen rather than an equals sign.

    sudo dnf install scaleft-gateway-VERSION