angristan/openvpn-install: A Shell Script That Turns a Fresh Linux Server Into an OpenVPN Endpoint
Set up your own OpenVPN server on Debian, Ubuntu, Fedora, CentOS, Arch Linux and more
At a glance
- What is it?
- The script targets Debian, Ubuntu, Fedora, CentOS, Arch and other systemd distributions, sets up certificates, firewall rules and forwarding, and emits .ovpn client files. It is a server-side installer, not a client, and its CLI interface is explicitly unstable between versions.
- Who is it for?
- Adopt it if you run a systemd-based Linux VPS or home server on amd64 and want a working OpenVPN endpoint without writing certificate and firewall plumbing yourself. Skip it if you need a client-side installer for Windows, macOS or Android, if you are on a non-systemd or non-amd64 host, or if you want WireGuard, which the README itself points to as simpler and faster for most cases.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 10 days ago.
- What is it written in?
- Mainly Shell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem: an OpenVPN server is a certificate authority plus a router
Standing up OpenVPN by hand means generating a CA, issuing a server certificate, issuing one certificate per device, writing a server.conf, enabling IP forwarding, and adding NAT rules in whichever firewall the distribution ships. Each of those steps has its own failure mode, and the failure usually shows up as a client that connects and then cannot reach anything.
angristan/openvpn-install collapses that sequence into one shell script aimed at people who own a server but do not want to maintain a PKI by hand. The README is explicit about the target: a VPS, a dedicated server, or a computer at home. It is a server-side tool. The clients it produces are .ovpn files, and the README tells you to copy them off the server with scp and open them in your usual OpenVPN client.
The framing matters because the name invites the wrong expectation. This is not an OpenVPN client installer for Windows, macOS or Android. It is the piece you run on the machine that will terminate the tunnel.
How the script wires routing, clients and firewall rules
The README's own diagram sets out three destination paths, and the defaults are asymmetric. Internet routing is enabled by default: clients send all traffic through the server. Access to server-side networks is disabled by default and requires explicit CIDRs. Client-to-client access is also disabled by default. That last pair is the part people get wrong, because a tunnel that connects and routes to the internet still will not let two laptops see each other until you opt in.
Addressing is configurable. The IPv4 VPN subnet defaults to 10.8.0.0/24 and the IPv6 subnet to fd42:42:42:42::/112, with the tunnel MTU at 1500. The script supports IPv4 or IPv6 server endpoints and IPv4-only, IPv6-only or dual-stack clients, and it claims automatic leak prevention that blocks the undesired protocol in single-stack modes.
Firewall handling is where the distribution differences get absorbed. The README says rules and forwarding are managed with native firewalld and nftables support and an iptables fallback. That is a design decision worth noticing: instead of asking you to translate one set of rules across distros, the script detects what is present. It also offers an unprivileged mode running as nobody/nogroup, and a choice between TCP and UDP. TCP is the reason to pick this over WireGuard in a hotel or corporate network where UDP is blocked.
Installing it and adding a first client on Ubuntu or Debian
The README's first step downloads the script to the server and marks it executable. Run it as root, and make sure the TUN module is enabled on the host.
curl -O https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh
chmod +x openvpn-install.shThe interactive menu is the documented starting point. The README calls it the easiest way to get started, and it walks through installation and later client management.
./openvpn-install.sh interactiveAfter the run, the README states that .ovpn files land in your home directory. Those are the client configurations. Copy the one you need to your device with scp and connect with an OpenVPN client.
For automation there is a non-interactive path with JSON output. The README gives these commands directly.
./openvpn-install.sh install
./openvpn-install.sh client add alice
./openvpn-install.sh client list
./openvpn-install.sh client revoke aliceRevocation is not just a file edit. The README states that revoking a client disconnects it immediately if it is currently connected, done through the OpenVPN management interface. The command list also includes uninstall, server management, and global options such as --verbose, --log <path>, --no-log, --no-color and -h/--help.
Where the script is the wrong tool
Two constraints are stated plainly in the README and both are hard boundaries. The script requires systemd. And the compatibility table notes that it is only tested on amd64, with automated testing limited to the distributions marked with a robot icon. A supported-looking row in that table is not the same as a tested row.
The larger limitation is architectural, and the project says so itself. The README's own comparison concedes that WireGuard came later and is simpler and faster for most use cases, and links to wireguard-install. If your goal is a fast tunnel between your own devices on modern kernels, this script is the long way around.
The remaining reasons to choose OpenVPN are specific: TCP support for restrictive networks, password-protected private keys (WireGuard configs store the private key in plain text, per the README), and legacy client availability. If none of those three applies to you, the honest answer is that you are paying certificate-management overhead for nothing.
There is also an operational trap in the CLI. The README carries a warning that API compatibility is not guaranteed and that breaking changes may occur between versions, advising anyone using the script programmatically to pin to a specific commit rather than master. Treat the CLI as a moving target, not a stable interface.
The alternative worth comparing: wireguard-install
The obvious alternative is the same author's wireguard-install, and the difference is not cosmetic. WireGuard uses a fixed set of public keys per peer rather than a certificate authority with signed certificates, so there is no CA to create, no per-client certificate to issue and revoke, and no CRL. Peer configuration is a key pair and an allowed-IP list.
That removes the entire lifecycle this script exists to automate. It also removes the revocation mechanism: with this project, revoking a client invalidates a certificate and the management interface drops an active session; with WireGuard you remove the peer's public key from the server configuration. The README's own trade-off list is the fairest summary: password-protected private keys and TCP transport are the two features WireGuard does not give you in the same form.
A second reference point is the repository's own docker-compose.yml, which builds a server container from test/Dockerfile.server and a client container from test/Dockerfile.client, wires them onto a 172.28.0.0/24 bridge, passes /dev/net/tun into both and sets net.ipv4.ip_forward=1. That file exists to run the test suite, not to deploy a production VPN, but it is a readable description of the minimum a working server needs: TUN, forwarding, and a privileged container.
Maintenance, testing and upgrade cost
The last push to the repository was on 2026-09-19, two days before this writing, and the repository is not archived. The project ships a Makefile-driven test suite that builds containers per distribution. Targets such as test-ubuntu-18.04, test-ubuntu-20.04, test-ubuntu-22.04, test-ubuntu-24.04, test-debian-11, test-debian-12 and test-debian-sid override BASE_IMAGE, and the driver polls the client container's logs for an "ALL TESTS PASSED" line, failing on a "FAIL:" line and timing out after 180 iterations. That is a real integration test across distros rather than a lint pass.
The upgrade cost follows from the pinning warning. If you use the interactive menu, upgrading is mostly re-running a newer script. If you script against the CLI, you inherit whatever changed between commits, and the README does not document a rollback path for an in-place upgrade. The uninstall command removes OpenVPN along with configuration and firewall rules, which is the documented way back to a clean host.
The licence is MIT, which permits commercial and private use, modification and redistribution provided the copyright notice and permission notice are retained. That is a permissive licence, not a copyleft one; nothing here imposes obligations on your own code. This is a description of the licence text, not legal advice, and OpenVPN itself is a separate project with its own licensing that this repository does not govern.
Editorial conclusion
Adopt it if you run a systemd-based Linux VPS or home server on amd64 and want a working OpenVPN endpoint without writing certificate and firewall plumbing yourself. Skip it if you need a client-side installer for Windows, macOS or Android, if you are on a non-systemd or non-amd64 host, or if you want WireGuard, which the README itself points to as simpler and faster for most cases. Before committing, verify that your distribution appears in the compatibility table, that TUN is available, and pin the script to a specific commit rather than master if you call it from automation.
Frequently asked questions
Can I install angristan/openvpn-install on Windows?
No. The script supports Linux distributions only, and the README's compatibility table lists AlmaLinux, Amazon Linux, Arch Linux, CentOS Stream, Debian, Fedora, openSUSE, Oracle Linux, Rocky Linux and Ubuntu. Windows appears only as a client platform whose DNS leaks the script can block.
Does angristan/openvpn-install work on a server without systemd?
The README states the script requires systemd, so a non-systemd host is outside the supported set regardless of distribution.
What does angristan/openvpn-install produce after installation?
The README states that .ovpn client configuration files appear in your home directory on the server. You copy them to your devices, for example with scp, and connect using an OpenVPN client.
Can two VPN clients reach each other with angristan/openvpn-install?
Not by default. The README's routing diagram marks client-to-client access as disabled by default, along with access to server-side networks, while internet routing is enabled by default.
Is the angristan/openvpn-install CLI safe to use in automation?
The README warns that API compatibility is not guaranteed and that breaking changes may occur between versions, and advises pinning to a specific commit instead of the master branch when using the script programmatically.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/angristan-openvpn-install)