Software AG’s mainframe products are among the few enterprise products whose licensing is enforced by a machine-bound technical check, and the public documentation describes the check in detail. The guide, titled “Software AG Mainframe Product Licensing”, describes the licensing procedures, the licence check software and the licence file.[1] This article summarises what the guide says and what it means for an entitlement review. The guide does not state quantities, prices or contract terms, which come from the commercial licence agreement.[6]
Why the check exists
The guide explains that the vendor introduced a licence check for mainframe products “to ensure that customers run our software products only on mainframe machines for which they have valid and sufficient product licenses”, giving better control of the use of the products, and notes that on UNIX and Windows the product licence check has existed for many years.[1] The consequence is that the contract quantity (usually expressed as a machine or capacity entitlement) is turned into a signed file that the software itself verifies.
Products that need a licence
The guide lists the products that require a licence: Adabas and the add-ons Adabas for zIIP, Event Replicator for zIIP, Cluster Services, Parallel Services, Caching Facility, Online Services and Delta Save, plus Natural, EntireX, Com-plete, Entire Net-Work and Entire System Server.[1] The guide uses three-character product codes, shown as ADA for Adabas, NAT for Natural, EXX for EntireX, COM for Com-plete, WCP for Entire Net-Work and NPR for Entire System Server.[1]
Since Adabas 8.5 SP1 the installation package includes a set of sub-products or add-ons. The release notes say they must be licensed, and the corresponding product licence file must be provided with the nucleus or utility execution.[3] The release notes list a licence load module and DD name for each: Adabas (ADA), Adabas for zIIP (AZPAD), Caching Facility (ACF), Delta Save (ADE), Encryption (AEZ), Auditing (ALA), Cluster Services (ALS), Parallel Services (ASM) and Online Services (AOS).[3] From Adabas 8.5.1 the modules of several add-ons moved into the main Adabas load library, but the release notes stress that a valid licence is still needed for each component, so having the modules available is not an entitlement.[3]
The current product page for Adabas lists the add-ons customers may meet, for example Adabas Fastpath, Adabas Review, Adabas SAF Security, Adabas SQL Gateway and Entire Net-Work, with the platform each runs on (z/OS, or Linux and Cloud).[5] Whether each is separately priced is a matter for the contract.
The licence file
A product licence is a sequential file in US-ASCII XML format. It contains a Software AG header, customer information (name and ID), an encrypted licence key, the licence expiration date (or unlimited), product information (product code, version, name) and environment information. The environment information includes the operating system type, CPU ID, LPAR ID, system name and the capacity measured in million service units (MSUs).[1] IBM defines the CPU ID as the “central processing complex node descriptor sequence number”, the unique hexadecimal machine serial number without the machine model number.[1]
So the three metrics in the catalog (MSU, CPU ID and LPAR ID) are not abstract units. They are fields in a file that the software tests, and a different machine, partition or capacity step changes the answer.
Delivery and handling
The licence file is delivered on the product installation medium as a data set or as an email attachment. It must be installed on all mainframe platforms where the product is installed, must remain in ASCII format, and must not be modified, because any modification invalidates the digital signature and the check fails.[1] If the file arrives by email it should be transferred with native FTP commands in binary mode, because using other utilities may corrupt the licence key.[1] The licence file is obtained from the vendor’s sales representative, and customers are told not to edit it.[4]
When the check runs and what it tests
The licence is checked every time the product is initialised and once a day. Thirty days before the licence expires, licence check messages warn that a new licence is needed.[1] The items are checked in three groups, in this order: the licence key; product-specific information (expiration date, operating system, product code and version); and machine-specific information (CPU ID, machine capacity in MSU, and the LPAR ID if applicable).[1] If a group fails, later items in that group are also checked, then the check ends with error messages.[1]
What happens next is described in two ways. The general guide says that when a licence is incorrect, insufficient or not installed, an error message is issued and the product either continues to run or terminates.[1] The Adabas for zIIP note is stricter: if the product licence is incorrect, insufficient or not installed, Adabas terminates.[4] Behaviour therefore differs by product and version, and the product’s own installation documentation should be checked.
LICUTIL messages
The Adabas edition of the guide lists the messages of the licence utility LICUTIL:[2]
| Message | Meaning |
|---|---|
| MLC1001 | The CPU ID is not defined in the product licence: the licence is invalid or the product is run on a machine for which it is not licensed |
| MLC1002 | The LPAR name is not defined in the product licence, with the same two possible causes |
| MLC1003 | The machine or partition capacity exceeds the capacity allowed in the product licence |
| MLC1004 | Warning of the expiry date; the product can still be used until 23:59 local time that day and needs a new licence from the next day |
| MLC1005 | The CPU ID is not defined, so a disaster recovery or disaster recovery test environment is assumed |
| MLC2001 to MLC2004 | The licence or licence key is invalid, is not for the operating system, product code or version, or has expired |
The CHECK function returns return code 0 for success, 4 or 8 for warnings with the product continuing to run, and 12 when error messages are issued and the product terminates.[1] The utility can also display the licence and the machine data (CPU ID, machine type, model ID, LPAR ID, MSU), which the guide says can be used to send the vendor the data required for a licence file.[1]
Capacity, partitions and multiple machines
Because capacity is measured in MSU and checked against the machine or partition on which the product runs, an upgrade of the machine or the partition’s capacity can exceed the licensed value and trigger MLC1003.[2] The guide does not say how contractual quantities map to the licence file; a hardware change should be treated as a licensing event and discussed with the sales representative before it happens, because a new licence file will be needed.[1]
Separate product licences are not required for different machines: multiple CPU IDs can be defined in one licence file.[1] That makes the CPU ID list in the file a useful inventory of machines the vendor believes are licensed.
Disaster recovery
The guide says the licence check supports disaster recovery. A special licence file contains the parameter DisasterRecoveryCPUIDs that lists one or more CPU IDs of the machines to be used when the production machine fails; if these are unknown the value Unknown can be used, and the checker then issues a warning when a disaster recovery scenario is assumed. In a disaster recovery scenario no machine data besides the CPU ID is checked.[1] Message MLC1005 is the warning that appears when an unlisted CPU ID is assumed to be a DR or DR test environment, and the customer should obtain an updated licence if it is not one.[2]
Two points follow for compliance. First, the DR file removes the MSU check for the DR machine, so contractual DR rights (what the customer may do on the DR machine and for how long) must be read in the commercial agreement and not inferred from the licence file. Second, the warning for an unlisted CPU ID means DR tests on an unplanned machine are visible in job logs.
zIIP products
For zIIP-enabling products such as Natural Batch for zIIP, the product code can have up to five characters and the CHECK function takes the ZIIP parameter.[1] The Adabas product list includes Adabas for zIIP, described as shifting Adabas workload to IBM zIIP processors to reduce mainframe cost.[5] Whether zIIP capacity counts toward MSU limits is not addressed in the public documentation and should be confirmed with the vendor.
Audit relevance
The licence check is automatic and local. It is distinct from any contractual audit right, which is not in the public documents; the legal notices say only that use needs a corresponding licence agreement and that commercial terms are in that agreement.[6] A customer should assume that licence files, the product inventory on each LPAR and the contract quantity will be compared in any review.
Review checklist
- List every mainframe product and add-on installed, with its product code and version.
- For each, retrieve the licence file or licence module and use the DISPLAY function to record expiry, CPU IDs, LPAR IDs and MSU.
- Compare the MSU in the file with the current capacity of each machine and LPAR, including after any upgrade.
- Confirm that every add-on loaded from the Adabas library has its own licence file.
- Check disaster recovery CPU IDs against the current DR site, and diary the licence expiry 30 days earlier.
- Do not edit, convert or re-transmit licence files except by the methods in the guide.