Keyfactor Command is Keyfactor’s platform for managing and automating public key infrastructure and digital certificates at scale.[1] Its documentation states that the product “is licensed by component, meaning your license may not include all the features described in this guide.”[2] A licence therefore does not simply unlock the product; it names the features and the limits that apply to one installation. Keyfactor provides one documentation set for on-premises Command and another for its managed services, and the licensing page is part of the on-premises suite.[2]
The licence file
Licence files carry the extension .cmslicense and are signed to prevent tampering. The currently installed licence appears on the License tab under System Settings, Licensing in the Management Portal, and shows the features enabled for the implementation.[2] If the customer buys a licence that adds components or extends the expiry date, it uploads the new file on the same page, compares it with the existing one, saves it, and restarts the IIS services on the Keyfactor Command server. Components added later can typically be configured without reinstalling the product.[2] Catalog proof: Keyfactor Command is licensed by component; Keyfactor Command licensed component.
Expiry and rotation
As a licence approaches expiry, warnings are written to the Keyfactor Command Service log and, for Windows installations under IIS, to the Windows event log 60 days, 30 days and 5 days before expiry. Each warning appears once per category, not at every restart, and an alert also appears in the Management Portal.[3] The Keyfactor CA Policy Module is licensed separately: when a customer installs a new licence because the existing one is expiring and uses the policy module, the licence must be installed separately for the policy module on the CA. The policy module’s licence tab takes a file with the extension CMSLICENSE, and an enrollment error of “Class is not licensed for use” can indicate that the policy module licence has expired.[2][3] Catalog proof: Command licence expiry warnings at 60, 30 and 5 days; Keyfactor CA Policy Module has its own licence.
Actioned certificates
The Actioned Certificates licence model was introduced in Keyfactor Command 25.1.1, released in April 2025. If a licence enables the feature and its type is not Site-License, the number of certificates deemed actioned is counted each night. The licence contains a maximum number of actioned certificates, though exceeding the count does not hamper functionality, and the licence and count can be downloaded to a file for review.[4] Licences that pre-date the model do not show the Actioned Certificates features on the licence tab.[2] Catalog proof: Actioned Certificates licence model arrived in Command 25.1.1; Actioned Certificates licence model.
What makes a certificate actioned
On the Actioned Certificates tab the documentation lists the categories. A certificate is actioned if it falls into one or more of them.[2]
| Category | Condition | Exclusions |
|---|---|---|
| Requested via Enrollment | Requested through Command by CSR or PFX enrollment | Revoked and expired certificates not counted |
| Revoked in the Past Week | Revoked within the previous week, in or outside Command | Expired certificates not counted |
| Has Non-Excluded Metadata | A metadata field not marked as excluded from actioned certificates has a value | Revoked and expired not counted |
| Certificate stores | Found in one or more certificate stores managed with Command | Revoked and expired not counted |
| Private Key Stored in Command | The private key is stored in Command, including imported certificates with private keys | Revoked and expired not counted |
| In Collection Workflow or Expiration Alert | In a collection referenced by an expiration alert or by a certificate entered or left collection workflow | Revoked and expired not counted; collections linked to a disabled or unpublished workflow are not counted in this category |
A certificate that meets several categories is counted only once.[2] Release 25.4 (November 2025) added two clarifications for licensing: a certificate is not counted as actioned under the workflow or alert category when the workflow cannot run, for example because it has no published version or is disabled; and a certificate is not counted as actioned in any category if it is discovered using SSL Discovery or managed with SSL Monitoring, although it can still be actioned under another criterion.[5] The distinction matters when sizing a licence. A very large discovered inventory does not by itself consume actioned certificates, while the same certificates become actioned once enrolled through Command, held with their keys, tagged with non-excluded metadata or placed in alert collections. Catalog proof: Actioned certificate categories; Discovered or monitored certificates are not actioned on that basis alone.
Counting schedule and visibility
By default the count runs every day at 2:00 am UTC. The tab shows the count in the database as of the most recent run.[2] Customers whose licence type is Actioned Certificates can click Download Usage Log at the top of the licensing page to download the signed XML licence containing information about the Keyfactor Command instance, licence features and actioned certificate counts.[2] Catalog proof: Actioned certificates are counted daily at 2:00 am UTC.
Exceeding the limit and the Site-License
If the total exceeds the licensed actioned certificate count, Command generates a warning alert and its functionality is not interrupted.[2] That is a technical position, not a contractual one: the End User License Agreement lets Keyfactor request a quarterly report of usage by the Order Form’s metrics and invoice excess use at its then current list price.[6] If the licence type is Site-License, the certificate count is not limited and the count values show N/A.[2] Catalog proof: Exceeding the actioned certificate count only raises a warning; Site-License has no actioned certificate cap; Site-License.
Separately licensed modules and third-party licences
The Risk Intelligence module integration, announced with release 25.4, appears in Keyfactor Command only with a Risk Intelligence licence in a hosted environment, and otherwise the capabilities are hidden. Keyfactor describes this as a new licence for the module that is required to access its capabilities.[5] Catalog proof: Risk Intelligence module needs its own licence; Keyfactor Command Risk Intelligence module.
The release notes also record a third-party licence change that affects the product’s own features. The licence for the Logi Analytics Platform, used by the Command dashboard and reports, expires on November 28, 2027 and is not to be renewed, and customers who have not upgraded to a version with the new reports and dashboards by then will lose the dashboard and reports. The notes name Keyfactor Command 26.1 as the version that carries the new reports and dashboards.[5] Logi Analytics also became an optional installation component of the Command server in release 25.4.[5]
Practical counting notes
- Record the licence type on each installation: Actioned Certificates with a limit, or Site-License.
- Use the Actioned Certificates tab and the usage log as the primary evidence of consumption, and keep the daily count in mind when comparing it with an inventory taken at a different time.
- Remove or exclude metadata fields that are not needed, because values in fields not excluded from actioned certificates make certificates count.
- Keep a calendar for licence expiry, including the separate policy module licence, using the 60-, 30- and 5-day warnings as the minimum notice.
- Check the Order Form for the renewal uplift and notice period, since the EULA defaults to automatic renewal on 60 days’ notice with a price increase unless negotiated otherwise.[6]
Out of scope
This article does not cover Keyfactor Command orchestrators, gateways, certificate authority connectors or the SSH feature, because the cited pages do not state how they are licensed, and it does not cover the hosted Command environment’s contract terms. For the contract see Keyfactor End User License Agreement and Order Forms.