Ping Identity’s self-managed software is the set of identity and access management products that customers install and operate on premises or in their own cloud. The licensing guide lists PingAccess, PingAuthorize, PingCentral, PingDirectory, PingFederate, PingAM, PingDS, PingGateway, PingIDM and an Agent Gateway, and says that licensing is enforced through licence keys, configuration, or both in each product’s admin console, using a managed (stored) identity unit of measure.[1] This article describes that unit, how each product handles licence files and expiry, and the older ForgeRock contracts that still govern part of the installed base.
Licence grant and the managed identity metric
Under the current Subscription Agreement, Ping Identity grants a limited, non-exclusive, non-sublicenseable and non-transferable licence, during the subscription term on an Order Form, to install the Software in machine-readable form and to use it solely for the customer’s business use.[17] The Software is delivered by electronic download and is deemed accepted on delivery unless the Order Form says otherwise.[17]
The licensing guide defines a managed (stored) identity as a unique identifier for a user, device or other object stored and managed by the product, regardless of activity, such as the number of records or entries in the directory or identity store governed by the licence.[1] See Managed (Stored) Identity. Because activity is irrelevant, a count for software is a count of records, not of sign-ins. For a directory the obvious source is the entry count under the licensed naming contexts; for a federation server or access gateway the guide does not state which store is counted, and the Order Form identifies the licensed population. Where the Order Form is silent, a practitioner should ask Ping Identity in writing which identity store is metered rather than assume one.
The Subscription Agreement also defines “Users” as including administrators and individuals, including non-human devices, provisioned by the customer, with the Order Form defining the number and type of Users.[17]
Product-by-product licence handling
PingFederate
PingFederate prompts for a licence file during initial setup, and the licence may carry an expiration date.[2] When upgraded with the Upgrade Utility, a valid current licence is copied automatically to the target installation; otherwise a valid licence file must be specified at upgrade.[2] The licence information is saved in the file pingfederate.lic in the server’s conf directory, and a replacement import renames the previous file with a timestamp.[3] If the new licence is for the wrong version or invalid, PingFederate keeps the existing licence, even if it has expired.[3] In a cluster the administrator must use the Replicate Configuration action to send the licence from the console node to all engine nodes; engine nodes apply it immediately without restart.[3]
A licence with an expiration date expires at the beginning of that day. PingFederate sends notifications 60 days before expiry when notification is enabled, and when the licence and any grace period lapse it stops processing requests.[4] Some licences manage connections by groups; the documentation says that adapter-to-adapter mapping is considered a connection for licensing purposes, and an administrator assigns the licence group in the console.[5] The notification checkbox appears only if the licence has an expiration date.[4]
PingAccess
PingAccess shows licence details under System, License, and compares an uploaded licence with the current one.[6] The interface warns if the new licence expires sooner than the current one, is already expired, has a different major version, or is limited to fewer applications (the Max Applications attribute).[7] The licence on the administrative node is replicated to the engine nodes and the replica administrative node; engine nodes do not require a licence to function.[6] A running configuration continues to work if the licence file is removed and the server restarted, but the administrator must install a licence to change configuration.[6] The application limit is catalogued as PingAccess licensed applications.
PingDirectory
PingDirectory documentation states that licence keys are required to install, update and renew all Ping Identity products, and that a licence is required for a new single server instance and can be used site-wide for all servers in an environment.[8] A new licence is required when moving to a new major version, such as from 8.3 to 9.0, while cloning a server with a valid licence does not require one.[8] The key is specified at setup with the licenseKeyFile option or by placing it in the server root, or after setup in the admin console or with dsconfig.[8] An expiring licence produces alerts and alarms but does not affect product functionality.[8]
PingAuthorize
PingAuthorize has the same pattern: one licence to set up a single server instance, after which multiple instances can be set up in the same environment, and a new licence for each major version upgrade.[9] The expiry consequence is different from PingDirectory. Running servers continue to work after expiry, but attempts to start or restart with an expired licence fail, and in containerized environments such as Kubernetes a pod restart repeats setup and so fails with an expired licence.[9] The practical lesson for asset managers is that “expiry” cannot be treated as one risk across the portfolio: it is a notification for PingDirectory, a start-up block for PingAuthorize and a stop of request processing for PingFederate, as the documentation states.
The ForgeRock-derived products
The guide lists PingAM, PingDS (directory server and proxy), PingGateway, PingIDM and PingGateway Edge Security - Open Finance.[1] The documentation consulted for this article does not describe a licence-file mechanism for them comparable to PingFederate’s, so the Order Form and the agreements below govern entitlement. The support lifecycle for these products is set by separate product support lifecycle policies listed on Ping Identity’s End of Life Policies page, while products not listed there follow the general End of Life Policy.[16]
Legacy ForgeRock agreements
Ping Identity continues to publish the ForgeRock Subscription License Agreement, the Managed Services Provider Subscription Agreement and the Non-Production License Agreement among its ForgeRock legal documents.[13]
Subscription License Agreement
The version published (20230131) grants a world-wide, non-exclusive, non-transferable licence for the subscription term to install the software at the customer’s facilities, a customer-controlled space in a third-party data centre, or a third-party hosting provider under a customer-controlled account, to manage Identities for the Designated System, limited to the Identity Licenses purchased.[10] An Identity is a unique identifier for devices or users managed by the Software, and an Identity License permits one Identity to be managed during the term.[10] The agreement distinguishes Internal Identities (controlled by the customer), External Identities and Business Partner Identities.[10] For agreements dated before 1 January 2015 the Product Specific Terms say that Identity means User or Subscription user and Identity License means Subscription user Account.[14]
Other points a practitioner should record from the agreement:
- All Identity Licenses in each installation must be supported at the same level unless agreed in writing.[10]
- Services may not be used with any version of the software other than the licensed version, including open source or community versions.[10]
- The customer must notify ForgeRock of use above the Identity Licenses purchased and, on request and no more than once per calendar quarter, report actual usage.[10]
- Fees are based on the Identity Licenses purchased even if usage is lower; subscriptions renew automatically unless notice is given at least 90 days before term end; and ForgeRock may modify fees at renewal.[10]
- On ten business days’ notice ForgeRock may audit the customer’s records, the customer pays for additional Identities immediately, and if the discrepancy is five percent or more the customer pays the cost of the audit.[10]
- On expiry or termination the Identity Licenses end and the customer must stop using the software, return or destroy it, and if asked certify removal by an officer.[10]
The five percent audit threshold is a distinct rule in this older agreement. The current Subscription Agreement instead has the customer reimburse reasonable audit costs whenever an audit reveals unpaid fees, with audits limited to once in any twelve-month period.[17] Which regime applies depends on the agreement the Order Form incorporates.
Managed Services Provider Agreement
The Managed Services Provider Agreement (version 20200401) licenses a Partner to use the software to provide Managed Services to a Named Account, limited to the Designated System and the Identities for which Identity Licenses were purchased.[11] A bundling requirement applies: the Partner may use the software only as a bundled component of the Designated System, in conjunction with the Managed Services, and not on a standalone basis or for access, authentication or identity management for any other product or service.[11] The current Subscription Agreement separately prohibits operating the Products as a service bureau or managed service for third parties unless otherwise permitted.[17]
Non-Production License Agreement
The Non-Production License Agreement (Rev. 20200401) licenses employees to use non-production software and services to evaluate, test and demonstrate them in a non-production environment; production use requires a purchased production licence.[12] The agreement expires 180 days after its effective date.[12] Existing customers with a valid licence may also receive source for the non-production software under conditions that do not expand the scope of their licence.[12]
Support lifecycle and versions
The End of Life Policy distinguishes Short-Term Support and Long-Term Support versions. Long-Term Support versions have a guaranteed minimum of three years of Active Maintenance; after that period they are End of Support unless the customer buys Extended Limited Support for one further year, which requires a current Support Services subscription.[15] Using a version that is not supported under the policy is a Customer Cause, so resulting problems are not Errors that Ping Identity must resolve.[18] Since PingDirectory and PingAuthorize need a new licence key for each major version, an upgrade plan is also a licensing plan.
Open source components
The Subscription Agreement states that open source software embedded in the Products is subject to its own licences, that Ping Identity does not give warranties on it, and that the open source licences do not impose additional restrictions on use of the Products.[17] The ForgeRock Subscription License Agreement says that source code for open source components is available on request.[10]
Out of scope
This article does not cover the hosted PingOne services, the single-tenant clouds, the pricing of self-managed software (which is not published), or how to extract identity counts from each product. It does not interpret the unpublished attributes of any licence file.