Install DataStax Enterprise (DSE) 6.9 on Debian-based systems with APT

Use these instructions to install DataStax Enterprise (DSE) 6.9 on Debian-based systems using APT. This process also installs the DataStax Agent for use with DSE OpsCenter 6.8. It doesn’t install DSE OpsCenter, DataStax Studio, or DataStax Bulk Loader (DSBulk).

When installed from a package, DSE runs as a service. The service initialization script is located in /etc/init.d/dse. Run levels aren’t set by the package.

For other installation options, see Choose an installation method.

When you install DSE, it creates a cassandra superuser role in the database, and DSE runs as this user. Don’t use the default cassandra role in production because it is a security risk. Instead, create a new superuser role for running DSE.

Prepare the environment

  • Prepare an environment where you want to install DSE, including sufficient hardware, a supported platform, and root or sudo access.

  • Install APT package manager.

  • Install a supported Java 11 runtime: OpenJDK 11 (recommended) or Oracle Java SE 11.0.x (JDK).

    If you install multiple Java versions, set your $JAVA_HOME environment variable to Java 11.

  • Install a supported Python version for CQL shell: Python 3.8 to 3.11.

  • For production installations and simulated production test environments, review the recommended settings.

    Some settings can be applied before installing DSE. For settings that require a running DSE instance, plan to apply them after the installation.

  • If you plan to use DSE OpsCenter:

    • DSE 6.9 requires DSE OpsCenter 6.8. DSE 6.9 doesn’t support earlier versions.

    • To use DSE OpsCenter Lifecycle Manager (LCM) to automatically manage the Java runtime for DSE clusters, see Manage Java installs and Choose a Java vendor in LCM.

  • Install the libaio package:

    Debian
    sudo apt-get install libaio1
    Ubuntu 24.04 or later
    sudo apt-get install libaio1t64

    On Ubuntu 24.04 and later, the libaio library was renamed to libaio1t64. DSE requires a symlink from the old library name to the new one to detect it properly. Without this link, DSE issues a warning about the missing library and performance is significantly degraded.

    sudo ln -s /lib/x86_64-linux-gnu/libaio.so.1t64 /lib/x86_64-linux-gnu/libaio.so.1
  • Install GnuPG (GPG), which is used to verify the integrity and authenticity of the downloaded DSE package.

    To check if GPG is installed, run gpg --version.

Download the DSE package from IBM Fix Central

  1. Get access to download DSE from IBM Fix Central:

    An IBMid account with MFA enabled is required. If you don’t have one, create an IBMid account. If your organization uses Enterprise Federation (EF) for authentication with corporate credentials, see the IBMid EF documentation.

  2. Find DSE 6.9 on IBM Fix Central:

    1. Go to Fix Central.

    2. In the Product selector field, begin typing IBM DataStax Enterprise, and then select that option from the menu.

    3. In the Release field, select the version that you want to install.

    4. Click Continue.

    5. On the Identify fixes page, click Continue to use the default Browse for fixes option.

    6. On the Select fixes page, select the fix pack (DSE version) you want to install, and then click Continue.

      Depending on the product and version, more fix packs might be available if you set the Platform filter to All, and then click Submit.

    7. If prompted, sign in with your IBMid.

      An IBMid account with MFA enabled is required. If you don’t have one, create an IBMid account. If your organization uses Enterprise Federation (EF) for authentication with corporate credentials, see the IBMid EF documentation.

    8. On the Download options page, select Download using your browser (HTTPS), and then click Continue.

    9. Review the terms and conditions, and then click I agree to activate the download links.

  3. To download the DSE DEB package, click the dse-VERSION-deb.zip link for the relevant DSE patch release, such as dse-6.9.24-deb.zip.

    For new deployments, DataStax recommends the latest patch release. If you are scaling an existing deployment, install the same patch release as the existing nodes. For a summary of features and changes in each release, see the DSE 6.9 release notes.

  4. Extract the downloaded zip file:

    sudo unzip dse-VERSION-deb.zip

Verify DSE DEB packages

Optionally, you can validate the package signatures. This action requires debsigs and debsig-verify, which are available only in Ubuntu 22.04 and later.

  1. Get the package signing public key for your DSE version:

    • DSE 6.9.24 or later: Download the dse-package-keys.zip file from the IBM Fix Central fix pack list, and then unzip it.

    • DSE 6.9.23 or earlier: Contact IBM Support for assistance with locating the package signing public key.

  2. Add the package signing public key for your DSE version:

    • DSE 6.9.24 or later:

      sudo apt-key add dse-package-signing.pub.asc
    • DSE 6.9.23 or earlier:

      sudo apt-key add dse-deb-signing.pub.key
  3. Install the packages required to validate the signatures:

    sudo apt-get update ; sudo apt install -y rpm apt-utils debsigs debsig-verify
  4. Create a debsig policy file (.pol) with the key number for the DSE GPG public key (dse-package-signing.pub.asc):

    sudo mkdir -p /etc/debsig/policies/425D217E4288511D
    cat << EOF | sudo tee /etc/debsig/policies/425D217E4288511D/dse-package-signature-policy.pol
    <?xml version="1.0"?>
    <!DOCTYPE Policy SYSTEM "https://www.debian.org/debsig/1.0/policy.dtd">
    <Policy xmlns="https://www.debian.org/debsig/1.0/">
      <Origin Name="DataStax Enterprise Database" id="425D217E4288511D" Description="Trusted Package Signer"/>
      <Selection>
        <Required Type="origin" File="signer-key.gpg" id="425D217E4288511D"/>
      </Selection>
      <Verification MinOptional="0">
        <Required Type="origin" File="signer-key.gpg" id="425D217E4288511D"/>
      </Verification>
    </Policy>
    EOF
    sudo mkdir -p /usr/share/debsig/keyrings/425D217E4288511D
    gpg --dearmor < dse-package-signing.pub.asc > signer-key.gpg
    sudo cp signer-key.gpg /usr/share/debsig/keyrings/425D217E4288511D/
  5. Validate the packages:

    debsig-verify -d dse_*VERSION*-1_all.deb

    You can monitor the validation process in the terminal while it runs:

    debsig: Starting verification for: dse_*VERSION*-1_all.deb
    debsig:         getSigKeyID: got 425D217E4288511D for origin key
    debsig: getDbPathname: using /etc/debsig/policies/425D217E4288511D keyring
    debsig: Using policy directory: /etc/debsig/policies/425D217E4288511D
    debsig:   Parsing policy file: /etc/debsig/policies/425D217E4288511D/dse-package-signature-policy.pol
    debsig:     parsePolicyFile: parsing '/etc/debsig/policies/425D217E4288511D/dse-package-signature-policy.pol'
    debsig:     parsePolicyFile: completed
    debsig:     Checking Selection group(s).
    debsig:       Processing 'origin' key...
    debsig: getDbPathname: using /usr/share/debsig/keyrings/425D217E4288511D/signer-key.gpg keyring
    debsig:         getKeyID: mapped 425D217E4288511D -> 425D217E4288511D
    debsig:         getSigKeyID: got 425D217E4288511D for origin key
    debsig:     Selection group(s) passed, policy is usable.
    debsig: Using policy file: /etc/debsig/policies/425D217E4288511D/dse-package-signature-policy.pol
    debsig:     Checking Verification group(s).
    debsig:       Processing 'origin' key...
    debsig: getDbPathname: using /usr/share/debsig/keyrings/425D217E4288511D/signer-key.gpg keyring
    debsig:         getKeyID: mapped 425D217E4288511D -> 425D217E4288511D
    debsig:         getSigKeyID: got 425D217E4288511D for origin key
    gpg: Signature made Tue MM DD 08:18:57 2026 UTC
    gpg:                using RSA key 425D217E4288511D
    gpg: Good signature from "DataStax Enterprise Database <psirt@us.ibm.com>" [unknown]
    gpg: WARNING: This key is not certified with a trusted signature!
    gpg:          There is no indication that the signature belongs to the owner.
    Primary key fingerprint: ...
    debsig:     Verification group(s) passed, deb is validated.
    debsig: Verified package from 'Trusted Package Signer' (DataStax Enterprise Database)

    A warning message like This key is not certified with a trusted signature means GPG validated an untrusted key.

Install DSE with APT

  1. Set up a local APT repository to host the downloaded DSE Debian package.

  2. In /etc/apt/sources.list.d create a file named datastax.sources.list, and then add your local DSE repository to the file:

    echo "deb [trusted=yes] file:REPOSITORY_DIRECTORY_PATH ./" | sudo tee -a /etc/apt/sources.list.d/datastax.sources.list

    Replace REPOSITORY_DIRECTORY_PATH with the path to your local repository directory.

    The [trusted=yes] option allows APT to use the repository without GPG key verification.

  3. Update packages:

    sudo apt-get update
  4. Install the DSE packages:

    • Install the latest patch release of DSE 6.9:

      sudo apt-get install dse-full
    • Install an earlier patch release of DSE 6.9 by specifying the patch number and all packages:

      sudo apt-get install dse=6.9.PATCH-1 \
          dse-full=6.9.PATCH-1 \
          dse-libcassandra=6.9.PATCH-1 \
          dse-libgraph=6.9.PATCH-1 \
          dse-libhadoop2-client-native=6.9.PATCH-1 \
          dse-libhadoop2-client=6.9.PATCH-1 \
          dse-liblog4j=6.9.PATCH-1 \
          dse-libsolr=6.9.PATCH-1 \
          dse-libspark=6.9.PATCH-1 \
          dse-libtomcat=6.9.PATCH-1
  5. Optional: Install the demos.

    Installing the DSE demos is not recommended for production. Only install the demos in development environments to run tutorials.

    sudo apt-get install dse-demos=6.9.PATCH-1

Start DSE

Don’t start DSE if you are upgrading. Return to the upgrade guide to continue reconfiguring your upgraded node before starting DSE:

  1. Start DSE:

    sudo service dse start

    For other startup options, see Start and stop DataStax Enterprise.

  2. Run nodetool status to verify that DSE is running:

    nodetool status

    Make sure the node reports UN (Up/Normal) status:

    Datacenter: Cassandra
    =====================
    Status=Up/Down
    |/ State=Normal/Leaving/Joining/Moving
    --  Address    Load       Tokens  Owns    Host ID                               Rack
    UN  127.0.0.1  82.43 KB   128     ?       40725dc8-7843-43ae-9c98-7c532b1f517e  rack1

    If the node fails to start, make sure the /tmp/dse directory didn’t exist before startup. If /tmp/dse is present before the first startup, the node can fail. Don’t use /tmp/dse to store any startup options or configuration files.

    For additional assistance, contact IBM Support.

  3. If you are deploying multiple nodes or datacenters, repeat the installation process on all nodes.

Next steps

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM