Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Setting up the license service (organization mode)

This page is for whoever administers your organization’s infrastructure (systems team, or the IBM i server administrator) — you don’t need to read it to program in WARP. It covers the one-time setup of the service that hands out licenses across your whole development team. People who just use Warpgate get three final values (Host, Port, Fingerprint) from the administrator and put them in their @License — see Licensing.

1. Download

On Linux, make them executable: chmod +x license-service license-gui.

2. Request the organization license

On the server where the service will run:

license-service create-request --license-id "<Your organization's name>" --out request.json
license-service gen-hwid

The second command prints several machine details; copy the primary_os_id value (a 32-character string). Send to warpgate@softwarehouse.pe:

  • The request.json file.
  • The primary_os_id value.
  • How many simultaneous seats your team needs.

Software House replies with a license.json file for that server, valid for 90 days and renewable — same free-of-charge model as the individual license, see Licensing.

3. Install the service

Windows

license-service install-license --license license.json
license-service gen-tls-cert --subject-alt-name <server-host-or-domain>
license-service install-windows-service --bind 0.0.0.0:7443

This registers license-service as a regular Windows service (starts automatically, restarts itself on failure) — manage it from the Services console like any other. The second command prints the SHA-256 fingerprint on screen: that value is the Fingerprint needed by anyone connecting.

  1. Copy the binary and create a dedicated user for the service:
    sudo install -m 0755 license-service /usr/local/bin/license-service
    sudo useradd --system --no-create-home --shell /usr/sbin/nologin warpgate-license
    sudo install -d -o warpgate-license -g warpgate-license -m 0700 /var/lib/license-service
    
  2. Install the license and generate the certificate, as that user:
    sudo -u warpgate-license env LICENSE_SERVICE_DIR=/var/lib/license-service \
      license-service install-license --license /path/to/license.json
    sudo -u warpgate-license env LICENSE_SERVICE_DIR=/var/lib/license-service \
      license-service gen-tls-cert --subject-alt-name <server-host-or-domain>
    
    Write down the SHA-256 fingerprint the second command prints: that value is the Fingerprint.
  3. Download the systemd unit file, copy it and enable the service:
    sudo cp license-service.service /etc/systemd/system/
    sudo systemctl daemon-reload
    sudo systemctl enable --now license-service
    

This makes the service start on boot and restart itself on failure. Logs: journalctl -u license-service -f. Only open TCP port 7443 to the subnet of Warpgate users.

Linux, quick test (no systemd)

To test before installing it as a permanent service:

license-service install-license --license license.json
license-service gen-tls-cert --subject-alt-name <server-host-or-domain>
license-service run --bind 0.0.0.0:7443

Runs in the foreground; stops when you close the terminal. Useful to verify everything works before the step above.

4. Hand the values to your team

Each developer puts these three values in their project’s @License (see Licensing):

  • Host: the server where the service runs.
  • Port: 7443 (or whatever was set with --bind).
  • Fingerprint: the one gen-tls-cert printed.

If your organization uses Active Directory, the service can require Kerberos authentication — contact Software House to enable it.

5. Checking the service with license-gui

license-gui is a separate window, no command line, for checking the license status without touching the seats in use (it doesn’t consume a seat): active license and expiry, seats in use and available, and each user’s session history (including whether a session closed normally or was lost).

On opening, it asks for the same three values as any client — Host, Port, Fingerprint — plus an optional SPN if the service requires Kerberos. Whoever administers the service can also install a new license from there, with no restart needed.