Open-source project
Nyr/openvpn-install avatar
Nyr/openvpn-install

openvpn-install: A One-Script OpenVPN Server Setup for Six Linux Distributions

OpenVPN road warrior installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and Fedora

20,642 stars5,071 forksShellMIT

At a glance

What is it?
openvpn-install is a shell script by Nyr that sets up a full OpenVPN road-warrior server on Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, or Fedora in a single command, with client certificate management handled by re-running the same script.
Who is it for?
openvpn-install is the right tool for an engineer who needs an OpenVPN road-warrior server on a supported Linux distribution and wants the setup completed without reading through OpenVPN's documentation. It is the wrong tool for any server running outside its six supported distributions, for deployments that require a web-based management interface or usage monitoring, or for users who need built-in client list inspection.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Shell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Road Warrior Problem openvpn-install Addresses

A road warrior VPN configuration describes a setup where clients on untrusted networks, such as hotel Wi-Fi, shared office connections, or a home ISP, tunnel their traffic through a central VPN server you control. The README links directly to the Wikipedia definition of this term, naming it the goal. openvpn-install automates the server side of that setup: the OpenVPN daemon, the certificate infrastructure, client profile generation, and the system firewall rules, all in a single guided session.

The target user is an engineer or system administrator who wants to run their own VPN server on a Linux machine or a cloud VPS without reading through the OpenVPN documentation to understand certificate authority setup or iptables configuration. The README describes the setup time as no more than a minute, even for users who have never worked with OpenVPN before.

The script's design principle, as the README states it, is to be as unobtrusive and universal as possible. It handles the setup and gets out of the way. After the first run, the same script file handles all subsequent management tasks.

Six Supported Distributions and What Falls Outside the Scope

The script explicitly supports six Linux distributions: Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, and Fedora. These cover the two dominant Linux family trees used in server deployments: Debian-based systems and Red Hat-based systems. AlmaLinux and Rocky Linux are community-maintained successors to the older CentOS Stream model for enterprise-style deployments.

The supported list is the complete list. macOS, Windows, Alpine Linux, Arch Linux, and any distribution outside the six named do not work with this script. The README documents no compatibility mode, no partial support, and no workaround for other operating systems. If your server runs a distribution not on the list, openvpn-install is not the tool for that server.

The server-side constraint is absolute, but the client devices that connect to the resulting VPN are not restricted. A properly configured OpenVPN server accepts connections from Windows, macOS, Android, iOS, and Linux clients, as OpenVPN client applications exist for all of these platforms. The script only controls what runs on the server.

Running the Script and What the First Session Produces

The README gives one installation command. Download the script and run it:

bash
wget https://git.io/vpn -O openvpn-install.sh && bash openvpn-install.sh

The script launches an interactive assistant that walks through the setup. After the session ends, you have a working OpenVPN server and at least one client configuration file. The README describes the design goal as being as unobtrusive and universal as possible, meaning the script limits its changes to what OpenVPN requires and does not make modifications to other parts of the system.

The entire project is a single shell script: openvpn-install.sh. There is no package to install, no dependency manager to run, and no configuration files to write by hand before executing the script. The script calls the system package manager internally to install OpenVPN and its dependencies.

Re-Running the Script to Add and Remove Clients

The same openvpn-install.sh file handles all post-setup management. Running the script again on a server where OpenVPN is already installed presents a different menu: add a new user, remove an existing user, or uninstall OpenVPN completely. There is no separate administration panel, web interface, or command-line tool for client management.

This is a deliberate simplicity trade-off. The tool has no runtime dependencies beyond bash and the system package manager. It has no database to maintain, no daemon of its own to keep running, and no network service to secure. The entire state lives in the files OpenVPN creates during setup.

The simplicity comes with a real limitation: the script does not provide a way to list existing clients without running it interactively. Inspecting active connections, reviewing client certificate status, or checking the revocation list requires accessing OpenVPN's configuration directory and log files directly, outside the script.

What openvpn-install Does Not Cover

openvpn-install sets up a server and manages client certificates. It does not provide usage statistics, per-client bandwidth accounting, connection logging with a searchable interface, or a web portal for client self-service. Engineers who need those capabilities must add them as separate components after the script finishes.

The script requires root or sudo access on the server. Running it as an unprivileged user will not work because OpenVPN's daemon and the firewall rules it configures require system-level permissions.

Certificate revocation is handled through the remove-client option in the script. The README does not describe how the revocation list is constructed or how OpenVPN picks up revocation changes after a client is removed. For deployments where certificate revocation response time matters, the implementation would need to be verified by inspecting the script itself.

The script also does not address multi-server or high-availability configurations. It sets up a single server with a single OpenVPN instance.

openvpn-install versus wireguard-install: Two Protocols, One Author

The README opens with a direct reference: wireguard-install, a companion repository by the same author, is also available. Both tools solve the same road-warrior deployment problem with the same single-script approach. The difference is the underlying VPN protocol.

OpenVPN uses TLS for its control channel and is an older, more widely deployed protocol. WireGuard is a newer protocol with a smaller codebase and different network characteristics. The README notes both are available but does not describe a technical comparison or recommend one over the other.

The protocol choice has practical implications for network environments. Some corporate firewalls or network policies may block WireGuard's UDP-based traffic while permitting OpenVPN's TLS-based connections on standard ports. Older client devices may also have better client application support for OpenVPN. Engineers with no specific network constraints on either side can evaluate both scripts, as the author structures them similarly.

MIT License and Maintenance History

The repository carries an MIT license. The project has no versioned releases; changes are tracked through commits on the master branch. The last push was on 2026-09-22.

The repository consists of three files: openvpn-install.sh, README.md, and LICENSE.txt. There are no configuration files, dependency manifests, or test suites. The project's entire logic is in the single shell script, which means code review and maintenance changes are confined to one file.

Editorial conclusion

openvpn-install is the right tool for an engineer who needs an OpenVPN road-warrior server on a supported Linux distribution and wants the setup completed without reading through OpenVPN's documentation. It is the wrong tool for any server running outside its six supported distributions, for deployments that require a web-based management interface or usage monitoring, or for users who need built-in client list inspection. Before running the script, confirm that the server runs Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, or Fedora and that the account has root or sudo access.

Frequently asked questions

Which Linux distributions does openvpn-install support?

The script supports Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, and Fedora. The README names these six as the complete supported list. Distributions outside this list are not supported.

How do I add or remove a VPN client after the initial setup?

Re-run the same openvpn-install.sh script on the server. If OpenVPN is already installed, the script presents a management menu with options to add a new user, remove an existing user, or uninstall OpenVPN entirely.

Can I use openvpn-install on a VPS?

The script is suitable for a VPS running one of the six supported Linux distributions. The README mentions that a VPS is a valid host and references a VPS provider for users who do not already have a server. Root or sudo access on the VPS is required.

Official sources

  1. Issues
  2. License: MIT
  3. Nyr/openvpn-install on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/nyr-openvpn-install.svg)](https://hysenlabs.com/projects/nyr-openvpn-install)