Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Linux Desktop App

RTS
Lite
CTS
ETS

System Requirements for Linux

Computer
  • At least 4 GB of RAM
  • CPU with actual clock speed from 2.6 GHz (including Turbo Boost), 4 logical cores (threads)
  • At least 1 GB of free disk space
Operating System
  • Linux x64: Ubuntu 18.04, Fedora 32, Debian 10, Astra Linux 1.7 and newer, Alt Linux, and other modern Linux distributions (to check the Linux version, enter lsb_release -a in the terminal).
Additional Conditions
  • Install the gnome-keyring keyring if it is not present on the system.
    Debian, Ubuntu, Astra Linux: sudo apt install gnome-keyring
    Red Hat-like (RED OS, Fedora): sudo dnf install gnome-keyring
    ALT Linux: sudo apt-get install gnome-keyring
    In a KDE environment, installing gnome-keyring is not required: it uses its own keyring — KWallet (learn more).
  • To run AppImage, FUSE version 2 library is required.
    Ubuntu 24.04 and later: sudo apt install libfuse2t64
    Earlier Debian-based systems: sudo apt install libfuse2
    Red Hat-based (RED OS, Fedora): sudo dnf install fuse-libs
    On Astra Linux 1.8 and RED OS 8, the required libraries are preinstalled.
  • Install libappindicator3-1 for Astra Linux 1.7 or below, or the installation will fail with the error “Dpkg operation interrupted”.
    Command: sudo dpkg --configure -a, then sudo apt-get install libappindicator3-1
  • The GLIBC library for Astra Linux 2.12 and earlier is outdated; version 2.28 is required. We recommend updating Astra Linux.
  • After installing the libraries, log out and back in or restart the computer.

  • Time synchronization with an NTP server (see OS documentation).
Required Permissions
  • Access to the microphone, camera, and notifications (see OS documentation).

DEB Package Signing for Astra Linux With Closed Software Environment Enabled

ETS

If Astra Linux has the closed software environment (CSE, integrity control) mode enabled, the system blocks installation of packages that are not signed with a trusted digital signature. The standard eXpress DEB package does not have such a signature, so installation will fail.

For branded ETS apps, package signing for CSE operation is performed upon request — contact eXpress support. The obtained developer key must be added to trusted keys according to Astra Linux documentation.

App Formats for Linux

SHA512 checksums and version information for the eXpress desktop app can be checked in YML files: eXpress | eXpress Corporate.
Package Format Description
DEB

For Debian-based systems (Ubuntu, Astra Linux).
Download: eXpress | eXpress Corporate

RPM

For Red Hat-based systems (ALT, Red OS, Fedora, RHEL-like).
Download: eXpress | eXpress Corporate

AppImage

For any Linux OS.
Download: eXpress | eXpress Corporate

Installation on Linux

Standard Installation

Package Format Description
DEB
  • Double-click to run > installation will proceed in the package manager.
  • Via terminal: sudo apt install ./eXpress.deb
    Dependencies will be installed automatically. Note the ./ before the file name — without it, apt will look for the package in the repositories.
RPM
  • Double-click to run > installation will proceed in the package manager.
  • Via terminal: sudo dnf install ./eXpress.rpm
    For installation on ALT Linux, see below.
    ⚠️ Installing multiple desktop apps via RPM (eXpress + eXpress Corporate + ETS app) is not supported due to file conflicts in the packages. This does not apply to updating the same application: the new version is installed over the old one using the standard installation command.
AppImage
  • Enable the “executable” or “allow execution” property for the file > double-click to run.
  • Via terminal: chmod +x eXpress.AppImage ./eXpress.AppImage

Are There Repositories for Automatic Installation on Linux?

Public eXpress repositories for Linux are not available. Many organizations set up their own local repository: the latest package is automatically downloaded via permanent links (see Linux Application Formats), placed into the organization's repository, and then workstations are updated using standard package manager tools. The version and hash sums of the current package can be obtained automatically from the YML files listed in the same section.

Installing on ALT Linux

Starting with version 3.68, the RPM package requires the dependencies (libXtst or libXtst6) and (libuuid or libuuid1). The apt-get package manager in ALT Linux does not support such conditional (boolean) dependencies. The apt-get install command fails with unmet dependencies, even though the libraries themselves are present on the system.

Installing on a Single Computer

Install the package with the rpm command:

sudo rpm -i eXpress.rpm

⚠️ After such an installation, apt-get stops installing other packages and updating the system: it sees unmet dependencies for eXpress. The apt-get --fix-broken install command removes eXpress. If you need apt-get on the computer, repackage the package (see the row below) or use AppImage.

Installing and Updating via Your Own Repository

Before adding the package to a local repository, repackage it without the conditional dependencies. Either of the two utilities from the standard ALT repository will work.


epm (the eepm package):

epm repack eXpress.rpm

⚠️ When repackaging with epm, the installation scripts of the original package are not carried over: the /usr/bin/express symbolic link will not be created. Launching from the application menu works as usual. If needed, create it manually: ln -sf /opt/eXpress/express /usr/bin/express.

rpmrebuild preserves the installation scripts. Rebuilding requires more than 2 GB in the temporary folder. In ALT, the /tmp folder is placed in RAM, so set the temporary folder on disk:

sudo apt-get install rpmrebuild echo '%__find_scriptlet_requires /bin/true' >> ~/.rpmmacros mkdir -p ~/rpmrebuild-tmp ~/rpmrebuild-out export RPMREBUILD_TMPDIR=~/rpmrebuild-tmp rpmrebuild -p -n -d ~/rpmrebuild-out --change-spec-requires='sed -e "s/(libXtst or libXtst6)/libXtst/" -e "s/(libuuid or libuuid1)/libuuid/"' eXpress.rpm

The line in ~/.rpmmacros disables automatic dependency detection for installation scripts. Without it, the ALT builder will add a dependency on /usr/bin/ischroot, and apt-get will refuse to install the package. The line applies to all builds by this user.


Place the resulting package in the local repository and update its indexes. After that, installation and updating are performed as usual: apt-get update && apt-get dist-upgrade. The repackaging step can be automated with a script on the repository server.


On computers where the package is already installed via rpm -i, apt-get will be fixed when the next version is installed from the repository. To fix it immediately, remove the package with the rpm -e command and install it from the repository via apt-get install.

The package is modified after repackaging. When contacting support, state that you are using a repackaged build.

Without a Repository and Without Modifying the Package

Use AppImage. It does not register in the package database and does not affect apt-get. The app in AppImage format finds and installs updates itself.

Certificate Installation on Linux

CTS
ETS

Installing corporate server certificates so that the connection works (not required by default).

On Astra Linux and RED OS, the Ministry of Digital Development National Certification Authority certificates are already included in the system — if the server has switched to them, no installation is needed.

For Administrators: Installing a Certificate on Linux

Step 1. Install the Certificate in the System-Wide Store

The procedure depends on the distribution family.

Linux family Steps
Debian, Ubuntu, Linux Mint, Astra Linux, Kali Linux
and their derivatives
  1. Check whether the /usr/local/share/ca-certificates directory exists:
    ls -l /usr/local/share/ca-certificates
    If it doesn't exist yet, create it:
    sudo mkdir /usr/local/share/ca-certificates
    The certificate must be in PEM format (usually it is) and have the .crt extension — if your certificate has the .pem extension, simply change it to .crt.

  2. Copy your certificate with the command:
    sudo cp ./CERTIFICATE.crt /usr/local/share/ca-certificates/
  3. Run the command to update the system-wide list:
    sudo update-ca-certificates
  4. Check that your certificate is among the trusted ones:
    awk -v cmd='openssl x509 -noout -subject' ' /BEGIN/{close(cmd)};{print | cmd}' < /etc/ssl/certs/ca-certificates.crt | grep -i CERTIFICATE
RED OS, ALT Linux, RHEL, CentOS, Fedora
and their derivatives
  1. Copy the certificate to the trusted directory:
    sudo cp ./CERTIFICATE.crt /etc/pki/ca-trust/source/anchors/
  2. Update the system-wide list of trusted certificates:
    sudo update-ca-trust extract
  3. Check the result:
    grep -c "CERTIFICATE" /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
Arch Linux, BlackArch
and their derivatives
  1. Run the command:
    sudo cp ./CERTIFICATE.crt /etc/ca-certificates/trust-source/anchors/
  2. Update the system-wide list of trusted certificates:
    sudo update-ca-trust

Step 2. Check Whether This Is Enough for the Desktop App

On some distributions, the desktop app uses not the system-wide store but its own user certificate database. In this case, a typical picture emerges: curl and browsers connect to the server normally, while the app shows a certificate error.

Distribution Is the system-wide store enough?
Astra Linux, RED OS Yes, step 1 is enough.
Debian, Ubuntu, Linux Mint
and their derivatives
No. Additionally perform step 3.

If your distribution is not in the table, check with the command:

readlink -f /usr/lib/x86_64-linux-gnu/libnssckbi.so /usr/lib64/libnssckbi.so 2>/dev/null

If the output contains p11-kit-trust.so — the system-wide store is enough. If the file links to itself or the command outputs nothing — perform step 3.

Step 3. Install the Certificate in the User's Certificate Database (NSS)

Run as the user under which the app runs, without sudo.

  1. Install the certutil utility — on most distributions it is not included in the base installation:
    sudo apt install libnss3-tools
    for RPM distributions:
    sudo dnf install nss-tools
  2. Add the root certificate:
    certutil -d sql:$HOME/.pki/nssdb -A -t "C,," -n "Certificate name" -i ./CERTIFICATE.crt
  3. If the certificate has an intermediate, add it too — with different trust flags:
    certutil -d sql:$HOME/.pki/nssdb -A -t ",," -n "Intermediate name" -i ./INTERMEDIATE.crt
  4. Check that the entries appeared:
    certutil -d sql:$HOME/.pki/nssdb -L

If certutil reports SEC_ERROR_BAD_DER, the certificate file is in binary DER format. Convert it and try again:

openssl x509 -inform DER -in CERTIFICATE.cer -out CERTIFICATE.crt

Step 4. Restart the App

Fully quit the app — closing the window is not enough; it keeps running in the notification area. You can check and quit it like this:

ps aux | grep -i express

After that, start the app again.

If your organization's server has switched to Ministry of Digital Development National Certification Authority certificates, see the instructions.

Credential Storage on Linux

Authentication data is stored in the system keyring, which provides the Secret Service. Which keyring is used depends on the desktop environment:

  • gnome-keyring — in GNOME and most other environments. To view keys, open Passwords and Keys (Seahorse) in Ubuntu, Astra Linux, and others;
  • KWallet — in the KDE environment (in Plasma 6, the service is provided by the ksecretd component). To view keys, open KDE Wallet.
If both keyrings are installed on the system, the app uses the one that first claimed the Secret Service when the session started. Therefore, on the same machine, the prompt may look different: the Unlock Keyring window (gnome-keyring) or the KDE Wallet Service wizard (KWallet).

Creating a Keyring

If no application has yet created a keyring on the system, eXpress will prompt you to create one when it starts:
Environment Description
GNOME and others A window opens prompting you to create a password for the keyring. ⚠️ On subsequent app launches, the system may ask for this password again.
KDE

When the app first accesses the keyring in KDE, the KDE Wallet Service wizard opens and prompts you to choose an encryption type:

  • Classic blowfish encryption — the wallet is protected with a password. If the password is left blank, the system will not prompt for it every time the app starts;
  • Use GPG encryption for better protection — the wallet is encrypted with an existing GPG key.
⚠️ The GPG option requires the user to already have a GPG key suitable for encryption. If no keys exist, the wizard shows the error “It seems there are no keys suitable for encryption in your system. Install at least one encryption key and try again,” and does not offer to create a key.

What to do if this error occurs: click OK > < Back and select Classic blowfish encryption. Alternatively, create a GPG key in advance with the command:
gpg --quick-generate-key "First Last <user@example.com>" default default never
then try again — the wizard will offer to select the created key.

Removing App Keys from the Keyring

If you remove the app's authentication keys from the keyring, the authentication screen will open after the app restarts. With a standard app uninstall, the keys are preserved.

For Administrators: Application-Specific Keystore
ETS
Since version 3.42,
ETS
custom apps support configuration of an independent keystore located in /home/user_name/.config/app_name directory. Contact eXpress support to get more details.

Updating on Linux

The app in AppImage format finds updates on its own and offers to install them. The app from a DEB or RPM package finds updates, but you have to download and install them manually (details). Check for updates manually: Settings (avatar button) > Check for updates.

For Administrators: Additional Update Options

Disabling Update Checks

  • Create an AppConfig.json in the /home/user_name/.config/app_name folder and add:
    { "AutoUpdate": false, "Update": false }
    Pre-made file: AppConfig.json. Version 3.54 or above is required.
  • Or, block access to the updates.express.ms resource (
    ETS
    app uses its own updates server, if configured).

Standard Update

Manual updates are performed as a standard installation (see above).

⚠️ After installing the new package, restart the app. Installing the package does not send an update signal to the running app, so the running instance continues working with the old files that no longer exist on disk. This looks like a “broken window”: the app doesn't close normally and has to be force-quit.
For Administrators: Centralized Updates via Puppet, Ansible, or a Package Manager If the package is installed centrally — via Puppet, Ansible, or a package manager on a schedule — add an app restart as a separate step after the package installation. Otherwise, the update will be applied on disk but not in the running app.

Uninstalling on Linux

Before uninstalling, close the application via the system tray icon — otherwise it will continue running from the already deleted files until restarted.
Package Format Description
DEB
  • Via the package manager: find the app in the list of installed programs and select “Remove”.
  • Via the terminal (for example, Ubuntu): first find the exact package name (for ETS builds, it differs from express):
    dpkg -l | grep -i express
    then uninstall:
    sudo apt remove package_name
RPM
  • Via the package manager: find the application in the list of installed programs and select “Remove”.
  • Via the terminal: first find the exact package name:
    rpm -qa | grep -i express
    then uninstall:
    sudo dnf remove package_name
    On systems without dnf (for example, ALT Linux):
    sudo rpm -e package_name
AppImage
  • Delete the eXpress.AppImage file.
  • If AppImageLauncher was used for menu integration or the shortcut was pinned manually, additionally remove the integration file (usually in ~/.local/share/applications) and the pinned shortcut.
For an ETS app, the package name, keys, and folders will use the ETS app's name instead of eXpress.
For Administrators: Uninstalling the App With Full Cleanup of Traces
  1. Uninstall the app using the standard method (see the table above).
  2. Open the keyring manager (Passwords and Keys in Ubuntu, KDE Wallet in KDE, Seahorse in Astra Linux, and others) and delete the keys that start with eXpress.
  3. Delete the app profile folder in the file manager:
    /home/username/.config/eXpress
    or via the terminal:
    rm -rf ~/.config/eXpress
  4. Delete the remaining local user data:
    rm -rf ~/.cache/eXpress ~/.local/share/eXpress ~/.local/state/eXpress
  5. If the app was added to autostart, delete its shortcut:
    rm -f ~/.config/autostart/eXpress.desktop
  6. Check for installation leftovers — the package manager usually removes them, but after uninstalling an RPM package, the /opt/eXpress directory remains empty:
    sudo rm -rf /opt/eXpress /usr/bin/express /usr/share/applications/express.desktop
  7. For AppImage, additionally delete the eXpress.AppImage file, and if AppImageLauncher was used — the integration file in ~/.local/share/applications and the pinned shortcut.