Install the Okta Privileged Access gateway on Ubuntu or Debian
Before you begin, verify that the gateway machine runs a supported operating system version. See Supported operating systems. Ubuntu and Debian are supported on AWS, Google Cloud, Azure, and on-premises deployments.
-
Confirm the operating system version and architecture of the gateway machine.
cat /etc/os-release uname -mThe first command returns the distribution name, version, and version codename. The second command returns the architecture. Packages are published for the
amd64andarm64architectures, whichunamereports asx86_64andaarch64. Verify that both values are supported before you continue. -
Add the Okta Privileged Access repository key.
curl -fsSL https://dist.scaleft.com/GPG-KEY-OktaPAM-2023 | gpg --dearmor | sudo tee /usr/share/keyrings/oktapam-2023-archive-keyring.gpg > /dev/null -
Create a package resource list entry. Use the stable repository for production installations. Use the preview repository only when you're testing preview features.
Replace DISTRIBUTION with the distribution name for your operating system version. This is the same value that
cat /etc/os-releasereturns asVERSION_CODENAME.Operating system
Version
Distribution name
Ubuntu
16.04
xenialUbuntu
18.04
bionicUbuntu
20.04
focalUbuntu
22.04
jammyUbuntu
24.04
nobleUbuntu
26.04
resoluteDebian
11
bullseyeDebian
12
bookwormDebian
13
trixieStable
echo "deb [signed-by=/usr/share/keyrings/oktapam-2023-archive-keyring.gpg] https://dist.scaleft.com/repos/deb DISTRIBUTION okta" | sudo tee /etc/apt/sources.list.d/oktapam-stable.listPreview
echo "deb [signed-by=/usr/share/keyrings/oktapam-2023-archive-keyring.gpg] https://dist.scaleft.com/repos/deb DISTRIBUTION okta-preview" | sudo tee /etc/apt/sources.list.d/oktapam-preview.list -
Update the list of available packages.
sudo apt-get update -
Verify that the gateway package is available from the repository you added.
apt-cache policy scaleft-gatewayThe output lists a candidate version and the
dist.scaleft.comrepository. If the candidate is(none), the distribution name in step 3 is incorrect, or the update in step 4 failed. -
Install the gateway package.
sudo apt-get install scaleft-gatewayNote:scaleft-gatewayis the only package required for a gateway. Thescaleft-client-toolsandscaleft-server-toolspackages are separate components, for client machines and managed servers. Install them on the gateway machine only if that machine also acts as a client or as a managed server. - For database integrations, additional configuration is required after installation. See Configure the gateway to support database integrations.
Verify or update the gateway version
-
Check the version of the gateway that's installed on the machine.
sft-gatewayd --versionTo list the versions available in the repository, run
apt-cache madison scaleft-gateway. -
Update the gateway to the latest available version.
sudo dnf install scaleft-gateway -
Update the gateway to a specific version. Replace VERSION with the version that you want, for example 1.111.1. Note that the RPM package name joins the version with a hyphen rather than an equals sign.
sudo dnf install scaleft-gateway-VERSION