Licensing
SSLNexus supports permanent local Free operation, a seven-day Trial and authority-backed commercial licences. The signed Ed25519 token remains the licence credential, while /v1/activate and /v1/check return the effective runtime entitlement that the Central Engine enforces.
Install Free. Evaluate Everything. Stay Free If That Is Enough.
A new SSLNexus installation begins on the permanent local Free tier and does not require registration. The optional Trial is separate: after verifying a customer email address, an Administrator can start it from Settings → Product licence and receive the standard Enterprise profile for exactly seven days. Separately licensed add-ons such as MSP HUB are not included unless explicitly provided.
Free remains available indefinitely for a small supported estate. The current default allows up to 5 active automated certificates, 1 managed parent domain and 1 Linux deployment target using Nginx or Apache.
The standard Enterprise profile is unlocked, including its normal platforms, applications and features. Paid connectivity grace does not extend the Trial period.
The installation returns directly to Free. Existing configuration and already deployed certificates are retained; capabilities outside the Free entitlement stop accepting new restricted operations until licensed again.
Practical use: a hobbyist or lab operator can continue using the Free tier with Let's Encrypt for supported Nginx/Apache workloads after evaluating the complete platform. The Trial expires; the installation does not.
Signed Credential Versus Effective Entitlement
The signed token deliberately retains the legacy R14 shape for cryptographic compatibility. It is not treated as the final feature set. Licence Authority 0.16 can change the effective tier, expiry, grace, limits, platforms, applications and individual feature switches without issuing a different client build.
tier: free, the running client uses Free. If Enterprise is returned with Internal PKI disabled, Internal PKI stays disabled.Granular Feature Entitlement
The effective feature map can independently control capabilities including Internal PKI, Vendor Portal, Network Operator, network appliances, Palo Alto Networks, F5 BIG-IP, VMware vCenter, Deployment Plugins and Source Control. Platform and application arrays remain separate enforcement layers.
Enterprise
Internal PKI: Disabled
F5 BIG-IP: Enabled
VMware vCenter: Disabled
Business
Network platform: Enabled
F5 BIG-IP: Enabled
When an older authority does not return a feature key, R14 uses its legacy tier/platform rules only as a compatibility fallback. An explicit false from 0.16 is never replaced just because the base tier normally contains that feature.
Default Commercial Profiles
The tier matrix is the normal commercial starting profile. The licensing authority can apply customer-specific effective overrides.
| Capability | Free | Starter | Business | Enterprise |
|---|---|---|---|---|
| Active automated certificates | 5 | 25 | 200 | Unlimited |
| Linux / SSH | Yes | Yes | Yes | Yes |
| Windows / WinRM | No | No | Yes | Yes |
| Network appliances | No | No | No | Yes |
| Deployment Plugins + Source Control | No | No | No | Yes |
| Vendor Portal | No | No | No | Yes |
| Internal PKI / ACME CA | No | No | No | Yes |
MSP HUB Add-On
MSP HUB is available as an optional Enterprise add-on for managed service providers. It keeps the MSP's own organisation as a normal certificate estate and adds separately governed client estates beneath the same control plane.
- Client-estate capacity is set by the commercial licence and can be sized to the number of customers the MSP manages.
- Staff access can be assigned per customer so operational engineers work only with the estates they support.
- Removing the add-on is non-destructive. Existing client estates are preserved; MSP customer operations become unavailable until the entitlement is restored.
Installation Seats
Installation-seat allocation is controlled by Licence Authority 0.16. The authority can permit one, several or many installations. The R14 client does not use the legacy signed-token max_activations field to make seat decisions: /v1/activate accepts or rejects a new installation and /v1/check validates a registered installation.
The customer licence portal shows current seat allocation and active installations. Releasing a retired installation frees that authority-side assignment; it does not delete certificates or configuration from another installation.
Grace And Live Refresh
Authority-backed licences use the grace value returned by 0.16. Missing grace_days means the legacy seven-day compatibility fallback, while 0 explicitly means no grace. Other non-negative values are used exactly as supplied.
The Central Engine checks the authority every 15 minutes by default, unless an administrator configured another interval. Temporary authority/network failures retain the quick reconnect path. Use Settings > Product licence > Refresh authority to perform an immediate effective /v1/check.
The Trial is different: it remains seven-day standard Enterprise-profile access and falls directly back to permanent local Free at Trial expiry. Paid connectivity grace does not extend the Trial.
Credential Rotation
If Licence Authority 0.16 reports that the licence credential was rotated, SSLNexus keeps the current certificate/configuration state and cached entitlement/grace behaviour. Settings displays a clear instruction that a new signed token must be activated. Rotation is not treated as a one-minute network outage retry.
Low-Sensitivity Support And Feature-Use Telemetry
Activation and periodic validation send the licence/installation identifiers and a limited host snapshot including hostname, operating-system/version, kernel, architecture, SSLNexus product version/revision, aggregate service-health state and boolean feature-use indicators.
Feature-use indicators report only whether capabilities such as Internal PKI, F5, vCenter, Network appliances, Vendor Portal, Source Control or Deployment Plugins are configured/used. They do not send certificate contents or names, private keys, CA/API credentials, target passwords, repository tokens, customer playbooks or CA secrets.
Downgrade And Feature Removal
A tier change or individual feature removal is non-destructive. Existing targets, plugins, PKI state and deployed certificates remain. New operations that require a capability the current effective licence does not grant are blocked server-side, and the dashboard uses the same effective state to hide, disable or explain unavailable controls.
Customer Licence Portal
Use the dedicated customer portal at https://portal.sslnexus.com/portal/ to review licence state and active installations and release a retired installation. Treat the signed licence token as a credential.

