LICENSEWARE

Keyfactor Command licensing and actioned certificates

This article is about how Keyfactor Command is licensed: licence files issued by component, the Actioned Certificates count, the Site-License option, licence expiry and rotation, and separately licensed modules. It is not legal advice.

On This Page

Keyfactor Command is Keyfactor’s platform for managing and automating public key infrastructure and digital certificates at scale.[1] Its documentation states that the product “is licensed by component, meaning your license may not include all the features described in this guide.”[2] A licence therefore does not simply unlock the product; it names the features and the limits that apply to one installation. Keyfactor provides one documentation set for on-premises Command and another for its managed services, and the licensing page is part of the on-premises suite.[2]

The licence file

Licence files carry the extension .cmslicense and are signed to prevent tampering. The currently installed licence appears on the License tab under System Settings, Licensing in the Management Portal, and shows the features enabled for the implementation.[2] If the customer buys a licence that adds components or extends the expiry date, it uploads the new file on the same page, compares it with the existing one, saves it, and restarts the IIS services on the Keyfactor Command server. Components added later can typically be configured without reinstalling the product.[2] Catalog proof: Keyfactor Command is licensed by component; Keyfactor Command licensed component.

Expiry and rotation

As a licence approaches expiry, warnings are written to the Keyfactor Command Service log and, for Windows installations under IIS, to the Windows event log 60 days, 30 days and 5 days before expiry. Each warning appears once per category, not at every restart, and an alert also appears in the Management Portal.[3] The Keyfactor CA Policy Module is licensed separately: when a customer installs a new licence because the existing one is expiring and uses the policy module, the licence must be installed separately for the policy module on the CA. The policy module’s licence tab takes a file with the extension CMSLICENSE, and an enrollment error of “Class is not licensed for use” can indicate that the policy module licence has expired.[2][3] Catalog proof: Command licence expiry warnings at 60, 30 and 5 days; Keyfactor CA Policy Module has its own licence.

Actioned certificates

The Actioned Certificates licence model was introduced in Keyfactor Command 25.1.1, released in April 2025. If a licence enables the feature and its type is not Site-License, the number of certificates deemed actioned is counted each night. The licence contains a maximum number of actioned certificates, though exceeding the count does not hamper functionality, and the licence and count can be downloaded to a file for review.[4] Licences that pre-date the model do not show the Actioned Certificates features on the licence tab.[2] Catalog proof: Actioned Certificates licence model arrived in Command 25.1.1; Actioned Certificates licence model.

What makes a certificate actioned

On the Actioned Certificates tab the documentation lists the categories. A certificate is actioned if it falls into one or more of them.[2]

Category Condition Exclusions 
Requested via Enrollment Requested through Command by CSR or PFX enrollment Revoked and expired certificates not counted 
Revoked in the Past Week Revoked within the previous week, in or outside Command Expired certificates not counted 
Has Non-Excluded Metadata A metadata field not marked as excluded from actioned certificates has a value Revoked and expired not counted 
Certificate stores Found in one or more certificate stores managed with Command Revoked and expired not counted 
Private Key Stored in Command The private key is stored in Command, including imported certificates with private keys Revoked and expired not counted 
In Collection Workflow or Expiration Alert In a collection referenced by an expiration alert or by a certificate entered or left collection workflow Revoked and expired not counted; collections linked to a disabled or unpublished workflow are not counted in this category 

A certificate that meets several categories is counted only once.[2] Release 25.4 (November 2025) added two clarifications for licensing: a certificate is not counted as actioned under the workflow or alert category when the workflow cannot run, for example because it has no published version or is disabled; and a certificate is not counted as actioned in any category if it is discovered using SSL Discovery or managed with SSL Monitoring, although it can still be actioned under another criterion.[5] The distinction matters when sizing a licence. A very large discovered inventory does not by itself consume actioned certificates, while the same certificates become actioned once enrolled through Command, held with their keys, tagged with non-excluded metadata or placed in alert collections. Catalog proof: Actioned certificate categories; Discovered or monitored certificates are not actioned on that basis alone.

Counting schedule and visibility

By default the count runs every day at 2:00 am UTC. The tab shows the count in the database as of the most recent run.[2] Customers whose licence type is Actioned Certificates can click Download Usage Log at the top of the licensing page to download the signed XML licence containing information about the Keyfactor Command instance, licence features and actioned certificate counts.[2] Catalog proof: Actioned certificates are counted daily at 2:00 am UTC.

Exceeding the limit and the Site-License

If the total exceeds the licensed actioned certificate count, Command generates a warning alert and its functionality is not interrupted.[2] That is a technical position, not a contractual one: the End User License Agreement lets Keyfactor request a quarterly report of usage by the Order Form’s metrics and invoice excess use at its then current list price.[6] If the licence type is Site-License, the certificate count is not limited and the count values show N/A.[2] Catalog proof: Exceeding the actioned certificate count only raises a warning; Site-License has no actioned certificate cap; Site-License.

Separately licensed modules and third-party licences

The Risk Intelligence module integration, announced with release 25.4, appears in Keyfactor Command only with a Risk Intelligence licence in a hosted environment, and otherwise the capabilities are hidden. Keyfactor describes this as a new licence for the module that is required to access its capabilities.[5] Catalog proof: Risk Intelligence module needs its own licence; Keyfactor Command Risk Intelligence module.

The release notes also record a third-party licence change that affects the product’s own features. The licence for the Logi Analytics Platform, used by the Command dashboard and reports, expires on November 28, 2027 and is not to be renewed, and customers who have not upgraded to a version with the new reports and dashboards by then will lose the dashboard and reports. The notes name Keyfactor Command 26.1 as the version that carries the new reports and dashboards.[5] Logi Analytics also became an optional installation component of the Command server in release 25.4.[5]

Practical counting notes

  • Record the licence type on each installation: Actioned Certificates with a limit, or Site-License.
  • Use the Actioned Certificates tab and the usage log as the primary evidence of consumption, and keep the daily count in mind when comparing it with an inventory taken at a different time.
  • Remove or exclude metadata fields that are not needed, because values in fields not excluded from actioned certificates make certificates count.
  • Keep a calendar for licence expiry, including the separate policy module licence, using the 60-, 30- and 5-day warnings as the minimum notice.
  • Check the Order Form for the renewal uplift and notice period, since the EULA defaults to automatic renewal on 60 days’ notice with a price increase unless negotiated otherwise.[6]

Out of scope

This article does not cover Keyfactor Command orchestrators, gateways, certificate authority connectors or the SSH feature, because the cited pages do not state how they are licensed, and it does not cover the hosted Command environment’s contract terms. For the contract see Keyfactor End User License Agreement and Order Forms.

References

  1. Keyfactor Command Reference GuideIntroduction; Documentation Suite v25.3. Undated.Retrieved 2026-10-08.
  2. Licensing (Keyfactor Command Reference Guide)Licensing by component; actioned certificates; Site-License. Documentation Suite v26.2.1.Retrieved 2026-10-08.
  3. License Expiration Monitoring and RotationExpiry warnings; policy module licence. Documentation Suite v26.2.1.Retrieved 2026-10-08.
  4. 2025 First Quarterly Release - 25.1.1 NotesLicensing section: Actioned Certificates licence model introduced. April 2025.Retrieved 2026-10-08.
  5. 2025 Fourth Quarterly Release - 25.4 NotesLicensing section and Risk Intelligence module licence. November 2025.Retrieved 2026-10-08.
  6. End User License AgreementSections 2.01 to 2.06, 3.01 to 3.02, 8.02, 9.01 to 9.04, 11.06. No version stated.Retrieved 2026-10-08.

See also

Catalog Rows Cited

10Rules3Metrics2Programs1SKUs

Esc