CipherTrust licensing covers the Thales CipherTrust Data Security Platform, a family of data protection products centred on CipherTrust Manager, a key and policy management appliance, plus “connectors” that provide encryption, tokenisation, key management for clouds and databases, and data discovery. Thales states that CipherTrust Manager, available as virtual and physical appliances, uses the Entitlement Management System (EMS) to manage licence purchases, with licences covering both the appliance and its connectors.[1] The same Sentinel EMS technology is described in Thales Sentinel LDK and EMS licensing. Licence counts are set per connector, so one deployment normally holds several unrelated metrics at once.
Appliance licensing
Physical CipherTrust Manager appliances are licensed out of the box, while virtual appliances need their own licences.[1] A new virtual instance starts in Community Edition without a virtual appliance licence, and some administration features require one.[2] Features that need the virtual licence include creating child domains, clustering with other instances, LDAP and OpenID Connect authentication, configuring an HSM as root of trust, and scheduled backup or key rotation.[2] Catalog: Virtual CipherTrust Manager node, rule administration features that need the licence.
Virtual licences are node locked. Every node in a cluster and every clone of an appliance needs a separate licence, and a restore from a snapshot does not.[1] Two models exist: the k170v allows up to four CPUs and the k470v allows more than four. Community Edition and the trial equal a k170v. The most recently applied licence overrides existing ones even when older licences have not yet expired. Exceeding the k170v CPU limit produces a warning at login and an alarm that clears only when the allocation is reduced.[2] Catalog: k170v, k470v, rule one licence per node and clone, rule CPU limit.
Activation: lock codes and licence strings
Activation uses two lock codes. The Key Manager Lock Code is used for the virtual appliance licence, which is unique to each appliance and not replicated across a cluster. The Connector Lock Code is used for connector licences, which apply to all nodes of a cluster.[1] The administrator copies the lock code, generates a licence string on the Sentinel EMS licence portal using an Entitlement ID, and installs the string on the CipherTrust Manager.[9] The portal limits the number of licence strings that can be generated, so Thales advises supplying the correct lock code first, and a licence string generated for one CipherTrust Manager cannot be used on another.[9] Catalog: lock codes.
To move a connector licence between clusters, the licence must be revoked on the first cluster by contacting Thales Customer Support and then reactivated with the second cluster’s Connector Lock Code.[1] After a complete redeployment, new licences must be generated with Customer Support help until a self-service revocation process exists. For a standalone appliance both lock codes change, and for a clustered appliance only the Key Manager Lock Code changes.[10] Catalog: redeployment.
Connector licences and their metrics
| Connector | Metric | Behaviour at the limit |
|---|---|---|
| CipherTrust Transparent Encryption (CTE) | Registered client[3] | Registration fails when licences are exhausted |
| CTE for Kubernetes | Worker node with CSI attached[3] | Falls back to Community Edition’s three-node limit |
| Live Data Transformation (LDT) add-on | Needs a CTE base licence[3] | Add-on counts follow the base licence |
| CipherTrust Cloud Key Manager (CCKM) | Cloud unit per added entity[4] | No further accounts can be added |
| Data Discovery and Classification (DDC) | Data allowance in terabytes[5] | New scans stop; reports cannot be generated |
| KMIP | Registered KMIP client[6] | Non-compliance mode warning |
| ProtectFile | Registered client[7] | Registration fails; managed clients limited after expiry |
| ProtectV | Registered client including clones[8] | Registration fails |
| CTE UserSpace | Registered client[12] | Registration fails |
Transparent Encryption
CTE comprises the base licence, CTE for Kubernetes and the LDT add-on. The base licence is standalone and is required to use LDT; the SAP HANA, Teradata and Efficient Storage capabilities are part of the base licence.[3] CTE base is required to register CTE clients, which are the rebranded Vormetric Transparent Encryption clients, and differs from CTE UserSpace, the rebranded ProtectFile FUSE.[3] Every node of a Kubernetes cluster consumes one CTE for Kubernetes licence, applied to worker nodes where the Container Storage Interface is attached to the application pod.[3] If a Kubernetes licence is unavailable or expired, enforcement switches to Community Edition, which allows registration of at most three Kubernetes nodes.[3] Catalog: CTE client, CTE for Kubernetes node, rules add-on needs base, client cap, Kubernetes fallback.
Cloud Key Manager
CCKM licences are offered as trial and time-limited rental, in cloud units.[4] One unit is consumed for each entity added to the Containers page: AWS accounts, Azure subscriptions, Google projects, Salesforce organisations, SAP applications or Oracle OCI compartments, and Google Workspace client-side encryption consumes one unit per endpoint.[4] The count applies to containers, so a cloud connection alone consumes no unit.[4] Thales gives the example of ten units split as five AWS accounts, three Azure subscriptions and two Google Workspace endpoints, or ten AWS accounts.[4] CipherTrust Manager acting as Luna HSM client for root of trust or CCKM Embedded needs no separate Luna client licence, but partition licences still apply on the HSM.[4] Catalog: CCKM cloud unit, rules containers not connections, Luna client licence waiver.
Data Discovery and Classification
DDC ships with a trial licence for 90 days and up to 1 TB.[5] Full licences run for 1 or 3 years with an allowance of 15 TB (1-year only), 50 TB, 100 TB, 150 TB, 250 TB, 500 TB, 1 PB, 1.5 PB, 3 PB or unlimited.[5] Trial and full allowances do not add up.[5] Rescanning a folder counts changed data: Thales’s example is a 10 GB folder where 1 GB changes, which brings consumption to 11 GB.[5] When the allowance is used up, scans can continue to be stored but reports cannot be generated, and on expiry the DDC configuration becomes read-only without deleting collected data.[5] The licence status appears as the DDC_DATA_ALLOWANCE feature on the Licensing page.[5] Catalog: DDC data allowance, DDC full licence, rules scans stop when exhausted, allowances do not add.
KMIP, ProtectFile and ProtectV
KMIP is licensed per planned client, based on the number of storage controllers or servers that will communicate with the CipherTrust Manager, and the number of registrations may not exceed the licences, otherwise the manager runs in non-compliance mode with a warning.[6] ProtectFile and ProtectV follow the trial, rental and perpetual models.[7][8] ProtectV licensing is enforced on clones, and every clone of a registered client consumes a licence.[8] A CTE UserSpace client honours both the ProtectFile and CTE UserSpace features, so registrations are allowed up to the sum of both licences.[7] Catalog: KMIP client, rules KMIP non-compliance, ProtectV clones, aggregate capacity.
Flex Connector bundles
Thales simplifies connector purchasing with Flex licences: a connector licence can be redeemed to obtain another of the same bundle type, licences can be restructured later, and new features can be switched on by existing Flex connectors.[1] The bundles are Flex Connector Basic, Advanced and Premium, Flex Utilities and Flex Ability, each covering a list of connectors in a Thales table.[1] In Thales’s worked example, 30 Flex Connector Basic cover 10 CTE and 20 CAKM licences, which can later be traded one for one between CTE and CAKM.[1] Catalog: Flex Connector - Basic, Flex Connector - Advanced, Flex Utilities, Flex Ability.
Licence models and programs
Connector licences are offered through trial, time-limited rental and perpetual models.[3]
- Trial. The trial lists virtual CipherTrust Manager, Cloud Key Manager, KMIP clients, DDC, CTE, LDT, CTE for Kubernetes, Application Data Protection, ProtectV and ProtectFile, and all licences expire 90 days after the trial is first started, even if it is stopped and restarted.[11] After a connector trial expires, its configuration on the CipherTrust Manager becomes read-only.[3]
- Time-limited rental. A prepaid, fully functional licence for a period and number of clients. A 90-day grace period follows expiry, then configuration becomes read-only and only decryption of GuardPoints and GuardPolicies is allowed.[3] A system banner warns 30 days before expiry, and the licence can be renewed before it expires.[1]
- Perpetual. A prepaid licence with no time limit for a specific number of clients.[3]
- Community Edition. Thales offers a free-forever CipherTrust Manager with licences for Data Protection Gateway and CTE for Kubernetes and says there is no expiration date.[13]
Not all products are enforced. In the enforcement summary Thales lists ProtectApp, TDE, ProtectDB and tokenization as not enforced by CipherTrust Manager licence counts, and states that CipherTrust Intelligent Protection is not a licensed product but needs licences for CipherTrust Manager, DDC and CTE.[1] Contract terms may still apply to such products even where software does not enforce them.
Audit and compliance considerations
Enforcement is mostly technical: the manager refuses registrations, shows red or orange expiry banners, or moves to read-only. Thales states that connector licences are enforced through CipherTrust Manager, so the behaviour is the same regardless of the client software version.[1] KMIP is an exception where the appliance keeps working in non-compliance mode with a warning.[6] For a position review, export the installed licences list from Admin Settings > Licensing, compare used and total client counts, and keep the Entitlement IDs. Audit rights in the End User Agreement were not available for this article; see software license audit.
Out of scope
This article does not cover Luna HSM licences (see Thales Luna HSM and Data Protection on Demand licensing), the CipherTrust Data Security Platform as a Service, tokenisation licences that CipherTrust Manager does not enforce, or per-release changes after version 2.8.