Sentinel RMS is the Thales licence-management toolkit for software and device vendors that need floating (network) licences, node-locked licences and licences that report usage. A licensee encounters it as a License Manager service on a server, a licence file, or a cloud-hosted licence service that a licensed application contacts before it starts. Thales describes Sentinel Rights Management as license enforcement and compliance handled in one place for software and device vendors.[6] Thales documents it in a separate developer guide from Sentinel LDK, and the two share the Sentinel EMS entitlement system.[5] For the LDK family, which uses hardware and software keys, see Thales Sentinel LDK and EMS licensing.
The License Manager
The RMS License Manager is an on-premises network service that tracks all licences and handles requests from network users who want to run the licensed application, authorising the request or denying it when all licences are in use.[1] It usually runs on a computer in the network where clients have installed the licensed application, and it is the component behind server-locked, site and commuter licences.[1]
Licences normally sit in a licence file; on startup the License Manager reads the file and builds a licence table, while licences added dynamically exist only in memory and are lost when the manager stops.[1] The manager uses UDP, and its default network port is 5093, with 5099 also used, so firewalls matter when diagnosing failures to obtain a licence.[1] Thales states that redundancy is supported for up to 11 License Managers.[1] The License Manager may run on a different platform from its clients, for example a UNIX server administering Windows clients, and is backward but not forward compatible with client versions.[1]
Thales also states that RMS is an enterprise product functioning within an intranet and that the customer’s system administrator is responsible for ensuring the License Manager is not on a public system.[1]
RMS Cloud License Manager
Since v10.0 Thales also hosts a cloud-based License Manager, the RMS Cloud License Manager, as a service that manages RMS licences.[1] Its licences deploy automatically after an entitlement is activated in Sentinel EMS, it supports expiration dates, global concurrency, licence sharing and aggregation, and administrators can list and terminate live sessions through the Sentinel EMS Customer Portal.[1] Thales notes that the cloud manager is available only to users with the SCL add-on, and that entitlement quantities can be rebalanced between deployment modes.[1]
Deployment modes
Thales distinguishes three licensing concepts and three deployment modes.[3]
- Standalone licensing. The licence resides on the same system as the application, licensing functions are integrated into the application, there is no dependency on an external License Manager, and misuse is prevented by locking each licence to a fingerprint of the system.[3]
- Network licensing. Also known as floating or concurrent licensing: multiple application instances share a central pool of licences managed by the License Manager, usually with a limit on simultaneous sessions. The licence is typically locked to the fingerprint of the License Manager, and client locking can also be used. Extensions include redundant servers, commuter licensing, group reservation and grace-period licensing.[3]
- License leasing. A licence is split into equal-termed slices delivered sequentially as leases, with a periodic handshake between the application or License Manager and Thales cloud components to update licences and pass usage information. Thales states that periodic cloud connectivity is therefore required, and that customers can switch to consumption-based post-paid models under leasing.[3] Catalog: Sentinel RMS license leasing, rule leased licences need periodic cloud contact.
Licence models a vendor can issue
The RMS solution guide groups business models into time-based (evaluation, perpetual, subscription), number-of-users-based (node-locked and floating or concurrent), feature-based (multi-feature, also called pay-per-feature or multi-module) and network models (commuter, a mobile scheme where licences are temporarily detached from the License Manager for offline use).[2]
In Sentinel EMS the RMS SDK licence models are named templates.[5] They include Auto Checkout (a floating, node-locked licence that works like a repository licence without manual checkout days), Commuter (manual checkout for a number of days), Network Node Locked, pooled and non-pooled Capacity Node Locked, Redundant Node Locked (up to 11 License Managers), Standalone Node Locked, Subscription (with an end date in days) and four Trial models counted from first use.[5] The default network user limit in those templates is 100.[5] Pooled capacity licences allow any team to draw from the total pool until the remaining capacity runs out, whereas non-pooled capacity licences let each team work within its own limits and share only within that team.[5] A trial licence cannot have a grace period associated.[5]
Metrics: the hard limit
RMS uses one licence property, the hard limit, for two different purposes.[4]
Hard limit as concurrency (tokens)
For a network licence the hard limit is the number of concurrent instances, the licence having that many tokens. Thales gives the example of a licence for ten simultaneous users: nine more users can start the application while tokens remain, the eleventh request is denied, and a token is freed when an instance exits.[4] For standalone licences a hard limit caps the number of licensed Features used concurrently, which Thales says may hold little meaning because a standalone licence can serve any number of local application instances.[4] Catalog: License token, rule requests are denied when no token is free.
Hard limit as quantity
A device vendor can instead use the hard limit as a quantity: the device checks out a number, such as permitted connections or throughput, from the License Manager in one transaction when it initialises, and then enforces that number itself.[4] Thales gives the example of network appliances where a customer buys global totals for connections and data throughput and distributes them across devices according to topology, with the ability to redistribute as demand changes.[4] Once the hard limit is reached no more devices can use the feature unless existing allocations are redistributed.[4] Catalog: License quantity, rule quantity is drawn at device initialisation.
Limits on the value
The hard limit can be up to 2,097,150 for version 11 or later licences used with License Manager 8.2.x or later, and from RMS v9.5 up to 4,294,967,294 for licence version 20 and above, with the larger value applying only when the hard limit is used as a quantity.[4] Thales warns that a very high value should not be used to control large numbers of concurrent sessions because of the performance impact on the server.[4]
Counting and compliance in practice
- Which number is the entitlement? Ask the application vendor whether its RMS licence uses the hard limit as concurrent users or as a quantity of a capability, because the same file field means different things.[4]
- Where is the licence locked? A network licence is typically locked to the License Manager host fingerprint, so a change of License Manager host is a point to check with the vendor before it is made.[3] Catalog: network licences are locked to the License Manager fingerprint.
- Offline users. The Commuter model allows manual commuting of a licence token from the License Manager for a number of checkout days, and the Auto Checkout model works like a repository licence without manual checkout days.[5]
- Evidence. License Manager utilities such as lslic and WlmAdmin are described in the Sentinel RMS system administrator guide, a separate document.[1]
Out of scope
This article does not cover the Sentinel RMS API surface, redundant-manager configuration in detail, Sentinel Software Usage Intelligence, or the price a vendor pays Thales for the toolkit, which Thales does not publish.