Linux · Raspberry Pi

AdHole on Linux and Raspberry Pi

A DNS filter for your home network and an HTTPS filter for your desktop’s browsers, in one program. For PCs (amd64) and Raspberry Pi 4 and 5 (arm64). Free, no account. It needs a distribution with systemd.

  • Free
  • No account
  • systemd
  • amd64
  • arm64

Install

Install in three commands.

You need a distribution with systemd, sudo, and a terminal opened in your desktop session: that session holds the proxy setting and Chrome’s and Firefox’s certificates.

tar xzf adhole-1.5.8-linux-amd64.tar.gzcd adhole-1.5.8-linux-amd64sudo ./adhole setup
For a PC. On a Raspberry Pi 4 or 5, or another 64-bit ARM board, take the arm64 archive and replace amd64 with arm64.
  • setup shows the installation notice and where the terms of use are. Read them, then type yes to accept and install.
  • If setup says certutil is missing, install libnss3-tools (Debian, Ubuntu, Mint), nss-tools (Fedora) or mozilla-nss-tools (openSUSE), then run sudo adhole setup again.
  • Open the dashboard: “AdHole” in your applications menu, or adhole ui. It opens in a Chrome, Edge, Brave or Chromium window if one is installed, otherwise in your browser.
  • The interface takes your session’s language when you install, English or French, and you can change it in the settings. Technical logs stay in French.

What setup changes

Everything setup changes, and teardown puts back.

A systemd service
AdHole starts with the machine and restarts on its own 5 seconds after a crash.
Port 53, freed
On Ubuntu, Fedora and others, systemd-resolved’s local listener (127.0.0.53) holds port 53. setup turns it off with a small configuration file and points /etc/resolv.conf at your router’s servers, so the machine keeps resolving names. If systemd-resolved knows no server from your router, setup stops rather than cut your connection.
This computer’s DNS
Pointed at AdHole first, with your router behind it as a fallback: through systemd-resolved, or through NetworkManager where it manages DNS. If neither does, setup tells you to set it by hand: 127.0.0.1, then your router’s address.
The certificate
Created on this machine, in the system store, and in Chrome’s and Firefox’s stores when certutil is present. Its private key never leaves the machine and only administrators can read it.
The desktop proxy
Under GNOME and KDE, the automatic proxy configuration script. Browsers go through AdHole, and go direct if it doesn’t answer.
The firewall
If ufw or firewalld is active: port 53 opened to your local network only, and port 67 for the address server AdHole can provide (off by default). Rules you keep directly in nftables or iptables are left alone.
Menu and command
“AdHole” in the applications menu, and the adhole command.

Chrome and Firefox

Chrome and Firefox keep their own certificates.

On Linux, Chrome, Chromium and Firefox don’t read the system’s certificate store, except Fedora’s packages: each keeps its own database in your home folder. setup registers the certificate in them with certutil, under your account, so the files stay yours.

A Firefox profile created later isn’t covered: run sudo adhole setup again, or import /var/lib/adhole/ca/adhole-ca.crt in Firefox’s certificate settings.

DNS filter only

Don’t want AdHole to decrypt your pages? sudo ./adhole setup -no-proxy installs the DNS filter only, with no certificate and no proxy. Pages and YouTube are then not filtered. That choice isn’t remembered: an update then installs the certificate and sets the proxy, and sudo adhole demarrer sets the proxy.

Desktop proxy

GNOME and KDE are set for you. Other desktops, by hand.

On another desktop, set the automatic proxy configuration URL yourself, in its network or proxy settings:

http://127.0.0.1:8053/proxy.pac

On a Raspberry Pi without a screen, installed over SSH, there’s no desktop session: no proxy is set, and AdHole works as the DNS filter for your home.

Raspberry Pi

A Raspberry Pi makes a good always-on home filter.

  • Devices whose DNS points to AdHole lose internet access when the machine running it is off or asleep. A Raspberry Pi that stays on suits this role well.
  • Take the arm64 archive: it runs on Raspberry Pi 4 and 5, and other 64-bit ARM boards.
  • Then set the DNS of your TV, console or phones to the Pi’s address, once, in their network settings. AdHole doesn’t do it for you.
  • AdHole only answers devices on your local network: it never becomes an open resolver on the internet.

How whole-home blocking works · Step-by-step for each device

Without systemd

Without systemd, it runs in the foreground.

On a distribution without systemd (Alpine, Devuan…), there is no service: sudo ./adhole run runs AdHole in the foreground, until you stop it with Ctrl+C.

Commands

Stop, start, undo.

adhole status
State of the service, the certificate and the proxy, a DNS test, and this machine’s local address.
sudo adhole arreter
Really stops AdHole, handing DNS back to the router first. sudo adhole demarrer starts it again. French for “stop” and “start”.
sudo adhole dns off
Hands this machine’s DNS back to the router. If no site opens at all, this brings your connection back at once. sudo adhole dns on points it at the filter again.
sudo adhole teardown
Removes everything setup put in place. Then sudo rm -rf /var/lib/adhole deletes the data.

What teardown does, in this order

  1. Hands this machine’s DNS back to the router, so nothing depends on the filter when it goes.
  2. Turns the desktop proxy off, if it still points at this machine: a proxy you set yourself since is left alone.
  3. Removes the service.
  4. Gives port 53 back to the system: systemd-resolved’s listener and your original /etc/resolv.conf return.
  5. Removes the firewall rules and the certificate.
  6. Leaves the data in /var/lib/adhole (settings, lists, certificate) until you delete it.

Devices you had pointed at this machine: set their DNS back to automatic.

Limits

What it doesn’t do on Linux.

  • Run as a service without systemd.
  • Set the proxy on desktops other than GNOME and KDE.
  • Filter pages in Chrome and Firefox without certutil.
  • Show an icon near the clock: on Linux, update alerts appear in the dashboard.
  • Remove YouTube ads in the app of a TV, a console or a phone, or the ads of Twitch, Netflix and Prime Video.
  • Look inside the sites left encrypted. The built-in list is built around French services: add your own bank before your next sensitive login.
  • Block every ad. No blocker does: some get through, and a site may occasionally look broken.

Everything it blocks, and what it doesn’t

Download

One program. Nothing else to install.

Windows, Linux or Android — a PC, a Raspberry Pi, a phone. No Java, .NET or Python to install. On a computer, installing requires administrator rights.

Windows

64-bit · x64

Download the installer

adhole-setup-1.5.8.exe · 9.8 MB

Version
1.5.8
Date
2026-09-25
Size
9.8 MB
SHA-256
38f4673ff670f236579b3bc06560ea07f147124ff2f2c9279c8d89eee153c6c5

Good to know

The installer isn’t signed. Windows shows “Windows protected your PC”: click “More info”, then “Run anyway”. Check the SHA-256 first, in PowerShell:

Get-FileHash .\adhole-setup-1.5.8.exe

The installer shows the terms of use, in English or French, before it changes anything. Please read them.

Firefox needs one extra setting: in about:config, set security.enterprise_roots.enabled to true.

Linux

systemd · amd64 · arm64

PC (amd64)

adhole-1.5.8-linux-amd64.tar.gz · 5.3 MB

Raspberry Pi 4 and 5 (arm64)

adhole-1.5.8-linux-arm64.tar.gz · 4.8 MB

Version
1.5.8
Date
2026-09-25
SHA-256 · amd64
92e29b66539b2c5162ea4a637130557baa8b465a3e9e0f532edd1c674009c5d8
SHA-256 · arm64
5c918b09dba256208edae567e60aeaa84580630fd71473b8e64ea3cef07edfd7

In a terminal opened in your desktop session:

tar xzf adhole-1.5.8-linux-amd64.tar.gzcd adhole-1.5.8-linux-amd64sudo ./adhole setup
  • On a Raspberry Pi, take the arm64 archive and replace amd64 with arm64.
  • setup shows where the terms of use are. Read them, then type yes to accept and install.
  • You need a distribution with systemd: Ubuntu, Debian, Fedora, Arch, Mint, Raspberry Pi OS… Without systemd, sudo ./adhole run runs AdHole in the foreground.
  • The proxy is set automatically under GNOME and KDE. On other desktops, set the proxy auto-configuration URL to http://127.0.0.1:8053/proxy.pac yourself.
  • If setup says certutil is missing, install libnss3-tools (Debian, Ubuntu, Mint) or nss-tools (Fedora), then run sudo adhole setup again.

Android

Android 8.0 or newer · APK

Download the APK

adhole-1.5.8.apk · 54.1 MB

Version
1.5.8
Date
2026-09-25
Size
54.1 MB
SHA-256
1f9649765b9d6bfb30b524c8264bb56a38254df93dd4ff59efd11094536d3ccd

Good to know

Not on Google Play: you install the file yourself. Android asks you once to allow your browser to install apps, then you open the file.

The app shows its terms of use the first time it opens, and starts filtering only once you accept them.

Domain names for every app; and, once you install its certificate, the pages in your browsers. Never inside other apps: the ads in the YouTube app stay, and a blocked rewarded ad pays no reward.

The same file installs on an Android TV box that accepts manual installs.

Installing on Android, step by step

Every file has a SHA-256 checksum, published in the SHA256SUMS file. On Linux: sha256sum -c SHA256SUMS --ignore-missing.

Questions

Before you install it on Linux.

Which Linux distributions work?

Those that use systemd (Ubuntu, Debian, Fedora, Arch, Mint, Raspberry Pi OS…), on a PC or a 64-bit ARM board. The proxy is set automatically under GNOME and KDE; elsewhere, you set it by hand. There’s no icon near the clock: alerts appear in the dashboard.

Firefox shows a security error on every site.

On Windows, Firefox 120 and later trust by default the root certificates added to Windows, AdHole’s included. If you see the error, that setting is probably off: under Settings → Privacy and security → Certificates, tick “Allow Firefox to automatically trust third-party root certificates you install” (or, in about:config, set security.enterprise_roots.enabled to true). On Linux, install certutil and run sudo adhole setup again.

Why does AdHole install a certificate? Is that risky?

To filter the inside of HTTPS pages, AdHole has to read them, and the certificate lets it, on the device where it runs. It’s created there, and its private key never leaves it. There is a risk: anyone who copied that key could read your traffic, so never copy the “ca” folder in AdHole’s data. On a computer, uninstalling removes the certificate; on Android you install it yourself, and you take it out yourself — uninstalling the app leaves it in place. On Linux you can also install the DNS filter alone, with no certificate.

Does it protect my TV, console and phones?

Yes, once you set their DNS to the computer’s address in their network settings. They then lose the ads and trackers served from ad servers, but not YouTube’s. The computer must stay on, and on Windows its network must be set to Private. An Android phone has a second way: install the app on it, and it is filtered wherever it goes.

No website opens at all. What do I do?

On Windows, right-click the icon near the clock and choose “Stop AdHole…”. Or, in a Command Prompt run as administrator, type adhole dns off. On Linux: sudo adhole dns off. Your connection comes back at once. After adhole dns off, the computer’s DNS stays with the router, even once AdHole is running again: apps, games and Windows no longer go through its filter. To put it back, type adhole dns on the same way.

Does AdHole update itself?

Yes, by default, at night between 3 and 5 a.m.; if the computer is off at those hours, an update that has been waiting for more than seven days installs at the first opportunity. Filtering pauses while it installs; the terms of use allow for about thirty seconds. An update is installed only if its SHA-256 checksum matches the published one, and an update that changes the terms of use waits for your agreement in the dashboard. You can turn automatic installation off; AdHole will then just let you know.

Is AdHole really free? Do I need an account?

Yes, it’s free, and no, there’s no account. There’s nothing to pay, no ads in the app, and no data asked in return.

Is AdHole open source?

No. It’s free, but proprietary: its source code isn’t published and it may not be redistributed. The open-source libraries it uses are listed, with their licences, in the third-party licences.