Skip to main content

Licence activation, online and offline

One licence binds one host. Online activation when the host has internet; an offline .lic file for air-gapped sites, with no network traffic at all.

A licence is always bound to one host. The product derives a hardware fingerprint on the machine and the licence is valid only there — copying the licence file to another machine fails verification.

The fingerprint is derived from two files in the install directory, state/machine-id and state/server_guid. Never regenerate them and never copy them between machines; back up the whole state/ directory together.

Use this when the host can reach license.reallysec.com:443.

Copy your licence token from the console (a string starting with LIC-).

Open the product's Licence page, paste the token, click Activate.

The status becomes valid. From then on the gateway heartbeats to the licence server every 5 minutes; renewals, tier changes and revocations take effect through the heartbeat.

A short outage of the licence server does not interrupt work: an activated licence has a grace period, and the paid features lock only once it runs out.

Offline activation (air-gapped)

When the host has no internet, the vendor signs a .lic file bound to your host fingerprint.

On the product's Licence page copy the host fingerprint (64 hex characters) and send it to Reallysec.

You receive a .lic file. Back on the Licence page choose Offline activation and upload the whole file (pasting its contents works too).

The product verifies signature and fingerprint locally and unlocks. No heartbeat is needed afterwards and nothing is sent out.

An offline licence's feature set is fixed in the file: renewals, tier changes and new paid capabilities need a re-issued .lic.

Deactivating and moving

To move a licence to another host, click Deactivate on the old host's Licence page first (an online licence returns its seat to the server), then activate on the new host as above. Offline licences must be re-issued for the new host.

Troubleshooting

SymptomCause
activation limit reachedEvery host seat on this licence is in use — deactivate on the old host first
Offline license is bound to a different hostThe fingerprint in the .lic does not match this machine — the fingerprint files were regenerated, or the file was issued for another host
no hardware identifier availableThe container cannot read /etc/machine-id; usually state/machine-id is not mounted or not readable
Cannot log in after the licence expiredSince Elastic AI Copilot 1.1.21 login, logout, password change and deactivation ignore licence state; upgrade older versions

On this page