User Tools

Site Tools


howto:licensing

This is an old revision of the document!


Off-site software licensing

Introduction

Some general background information on software licensing is provided here because it can be tricky to get access to off-site licenses right and it helps to understand some of the general principles and tools that can be used to debug the process.

Use of commercial software products is most often controlled by means of a software license. There are different types of software licensing schemes, with FlexNet the most commonly cursed used provider. Network software licenses tend to have the following features in common:

  • A license daemon runs on a license server and makes a license available at a known port number. This port number is always greater than 1024 and is unprivileged, in order to prevent attacks by way of the license port.
  • Some licensing systems use a single license daemon and port, most use two and in very malicious rare cases, three.
  • When more than one daemon is involved, one typically uses a fixed port number and some of the other daemons may use floating port numbers.
  • The client software has to be instructed where to look for the license. With some software products this can be set at install time, others use a manually-editable configuration file and most can be instructed by way of an environment variable.

Same-network licensing

If the license server is running in the same network as the clients, using the license is as simple as providing the license server and port number information to the clients, typically with an environment variable. The CHPC operates an academic license for its approved users of Ansys software, for example, and the client software can be instructed by setting the LM_LICENSE_FILE environment variable in the job script:

export LM_LICENSE_FILE=1055@login

Access to this license is controlled by listing approved users in a license option file.

It is possible to check if the license service is up and running with a telnet command, for example:

[charles@cnode0491:~]$ telnet login1 1055
Trying 172.18.0.126...
Connected to login1.
Escape character is '^]'.

There is no telnet service running on port 1055, therefore it is not possible for telnet to actually connect, but the above response is an indication that there is indeed some service running on port 1055. If you try the same command with a port where there is no service, you get this sort of response:

[charles@cnode0491:~]$ telnet login1 1047
Trying 172.18.0.126...
telnet: connect to address 172.18.0.126: Connection refused

The telnet “trick” is a quick way of checking for the existence of a service. The more sophisticated tool nmap can provide more comprehensive information:

[charles@login2:~]$ nmap -Pn -p 1055 login1

Starting Nmap 6.40 ( http://nmap.org ) at 2022-04-07 13:35 SAST
Nmap scan report for login1 (172.18.0.126)
Host is up (0.022s latency).
PORT     STATE SERVICE
1055/tcp open  ansyslmd

Nmap done: 1 IP address (1 host up) scanned in 0.77 seconds

Off-site licensing

It is somewhat atypical for the CHPC to provide in-network software licensing, the availability of such a service depending largely on the marketing strategy of the software vendor. There are a number of difficulties involved with using an off-site license server:

  • The lengau compute nodes do not have direct access to the internet
  • The off-site license server is typically situated within a corporate network behind a firewall
  • Some of the license daemons may be using random port numbers, which make it difficult to set up appropriate firewall rules

SSH tunneling

It is possible for compute nodes to communicate with the outside world using ssh-tunnels. Users log into and transfer files to the cluster using the secure shell, secure copy and secure file transfer protocol, which all involve communication through port 22. SSH tunnels allow connections made to a local port to be forwarded to a remote machine via a secure channel. An example of accessing a remote license with an SSH tunnel through the node chpclic1 is the way that STAR-CCM+ users can check out a “power on demand” license from an open license server operated by the software vendor:

ssh -f jblogs@chpclic1 -L *:1999:flex.cd-adapco.com:1999 -N
export CDLMD_LICENSE_FILE=1999@localhost

In practice, the CHPC has many users making use of this system, and it has become easier for the CHPC to simply set up a permanent tunnel with the license server port forwarded to port 1999 on chplic1. Therefore the user can simply access the license with this environment variable setting

export CDLMD_LICENSE_FILE=1999@chpclic1 

even though the license server itself is actually on a different continent entirely. In the case of the STAR-CCM+ license, each user has a unique 22-character security key which is passed to the license server at runtime.

Random port numbers

The difficulty with default random port numbers is that it makes it impossible to set very tight firewall rules. Strict firewall practices restrict communication to a very small and known number of ports. It is normally very easy to set a fixed port number, by editing the license file and restarting the license server. The top 2 lines of a Flexnet license file typically look like this:

/app/dokuwiki/data/attic/howto/licensing.1649347048.txt.gz · Last modified: 2022/04/07 17:57 by ccrosby