TweetFollow Us on Twitter

Using Sassafras' KeyServer to Manage Licenses

Volume Number: 25
Issue Number: 09
Column Tag: System administration

Using Sassafras' KeyServer to Manage Licenses

by Criss Myers

Preface to the issues involved with licensing

One of the many challenges that face an Apple Mac Network System Manager is the control and management of Application software. One of the issues involved in this is licensing. Anyone who installs a piece of software has a legal duty to comply with the license agreement shipped with the software. On a network, this challenge becomes much harder when we take into account that we may have many more client machines than available software licenses. There is naturally no reason to purchase a single license for every Mac on the network when each application is not used concurrently on all the clients [Ed. Note: This depends on the End User License Agreement itself.]. With this in mind there is a legal need to comply with the installed license agreements. Some software developers have their own means of controlling their license agreements. Apple offers a "network aware volume license," Quark has their own license server and many others use an iLok or USB dongle control feature. However, the majority of software available does not offer a network license; it is shipped with a single use license. Even those that do come with a network license come with no means of enforcing this, or of preventing unauthorized launching of the software when all licenses are used.

Further licensing issues occur when a client imaging system is used. One of the easiest ways to manage a large number of networked Macs is to image them centrally. This means that each Mac has the same software installed onto it. Which also means that the same license code is installed on to every client during imaging. Some software licenses are network aware, but in general, the same license code will allow you to launch the software on every client at once. This, of course, would breach the license agreement.

The Solution: Sassafras KeyServer

One approach to this problem is to use KeyServer by Sassafras Software. Sassafras has been around for nearly 20 years (since 1990). With KeyServer, you can control and monitor the usage of each license on your network. The KeyServer manages your list of available licenses and grants access based on your license preferences; each client requires a KeyServer license.

The server software can be installed on a OS X-based server (can be OS X, or OS X Sever), a Windows server, a Novell server or a Linux server. The client software can be run on a Mac, Linux or Windows client, which means that the same solution can help you to control both your Mac and Windows licenses from a single setup. A single KeyServer license will work on both platforms, as the license is per client machine registered with the server, irrelevant of the platform from which it runs.

In addition to controlling the software licenses, Keyserver has the ability to monitor software usage, because it can be set up to log all activity and display it as a graph over a given period of time. This can help you to comply with auditor's requirements as well as facilitating the planning of future software purchases.

Some of the benefits of using a KeyServer

A license entry can be created for any piece of software.

A license entry can be keyed, preventing the software from being launched, when there is no access to the server.

A queuing feature places those that request an unavailable license in a queue, informing them when a license becomes available.

Releasing idle licenses for those who are queued

A report of software usage can help to plan future software purchase and save money on unnecessary purchases.

Can be used for tracking computer usage and logons as well as license usage.

Compare usage stats for various Applications such as Safari vs Firefox giving you an idea of clients preferences.

Setup and configuration of the Keyserver K2

Installing the K2 Server and Shadows

The KeyServer is easy to install and setup. A full version of the software can be downloaded and installed from Sassafras for a limit period of time, for a limited number of clients for evaluation. Once you have downloaded the "K2" software to the server you need to install the K2Server.app on the server. When you purchase a license from Sassafras you will receive a single license file, (".lic") extension, for the number of clients that you purchased. Place this in the KeyServer folder located at "/Library/KeyServer/KeyServer Data Folder". If you purchase an increase to your number of clients you simply replace this file.

Figure 1 shows the server's library folder containing the ks-StartStop application,, the ks, KeyServer Data Folder containing the .lic license file and the KSddConsist Application, which checks the consistency of the KeyServer files.


Fig 1. Library Folder.

Once installed, the server can be started and stopped via the "ks-StartStop" or via the command line executing the "ks" executable. The server requires very little processor power, memory or disk space. The K2Server will launch at startup after its first run.

Figure 2 shows the ks-StartStop window confirming that the KeyServer is running.


Fig 2. ks-StartStop

The KeyServer supports what are called "shadows", which are replicas of the main server, so that if the main server is offline, the shadows can be used to authorize license requests and log usage.

To create a shadow, you need to create a shadow license file via the K2 Admin tool, KeyConfigure. Then, on a second server, replace the .lic file with the Shadow.lic file. The first time you start the Shadow KeyServer you will need to start it via the command line, as you will need to enter the password you created when creating the Shadow license file.


Figure 3. The KeyConfigure menu for creating a Shadow license.

You will need to add the KeyServer to your firewall on both the main and shadow servers, the K2 port is UPD ports 19283 and 19315 and TCP port 19283.

Installing the K2Client / K2Mobile and K2Admin tools

The client software is installed via the K2Client.mkpg or the K2Mobile.mkpg. The difference between these two is that the mobile version allows you to sign out licenses on mobile clients for use offline. The client installer installs KeyAccess, KeyVerify and a PreferencePane. When you install the client, it asks for the address of the server, either via FQDNS or IP address.


Figure 4. The K2 Client installer, the KeyServer Address is required before the installation starts.

The PreferencePane allows you to logon to the Keyserver, and lists the available shadows. Once connected, the client will reconnect at each logon. Every time you login to the computer it will connect to the KeyServer and log the activity along with the logging of each license that is granted, denied or queued.


Figure 5. The PreferencePane shows you the status of the connection between the client and the server as well as known Shadow servers as well as the version number, i.e. 6.1.4.4 The first time you logon you get the above message.

The K2 Server is administered from a client computer. Installing the K2Admin.mpkg will install the KeyConfigure application in the Applications folder. When you launch the KeyConfigure Application it asks for the Server address and authentication. The default password is "Sassafras".

Figure 6 and 7 show the logon and password change windows.


Figure 6. The KeyConfigure login window.


Figure 7. KeyConfigure's request to change the default password.

Configuration of the KeyServer

KeyConfigure is the Administration program for the entire configuration and monitoring of the KeyServer. The "Window" menu gives you access to the various different windowpanes for monitoring and setting up the KeyServer.

Figure 8 shows the Window menu in KeyConfigure, this is where you open the various windowpanes.


Fig 8. KeyConfigure's Window menu.

The first task after you have created a Shadow license is to setup the license entries for the programs you wish to manage. Open the "Licenses" windowpane. This lists all the license entries you create.

Figure 9 shows the license entries that have been setup.


Fig 9. License window pane

To create a license entry, just drag the application icon onto this license window. A new window then opens where you can select the appropriate options. Choose from a "Keyed Program" or an "Unkeyed Program". The difference between Key and Unkeyed is that the applications.app folder is modified by the KeyServer so that the program cannot be launched without a valid connection to the Keyserver. This prevents the program from being copied to another computer via CD or external drive. Some applications are self-contained within their .app bundle folder, which makes it easy to copy them to another machine. By keying the application, it can never be opened anywhere else. Some programs do like being keyed and once you key an application, you cannot unkey it without reinstalling, so make sure you test the applications you key. Click "Ok": the entry is created and the advance window is opened.

Figure 10 and Figure 11 show the configuration windows for setting up a license.


Fig 10. The new license entry creation window. Select between Keyed or Unkeyed and whether to allow the application to launch when the KeyServer is offline.


Fig 11. This window opens automatically after you create the license entry but can be accessed later by double clicking the entry in the license window.

Some of the main features that can be set are:

Limits: Choose the type of license you possess, and the number of concurrent licenses. Under Custom limits you can limit a license to certain groups, or create priority schedules for certain times. You can connect the KeyServer to a directory, such as active Directory, or LDAP to access existing groups.

Idle: Here you can set what happens when the user stops using the program for a certain length of time. Each program can have its own settings or you can set global settings, which allows you to set the queuing preferences. This can be very useful if you have a limited number of licenses but you expect that users may use the program for a short while and then leave it open. This would normally prevent other uses from using the program, but there is an option to queue new requests for the program and either warn users who are idle, or quit the program from them. Once a license is released due to idle settings the queued user will be notified that a license is now available for them.

Custom Message: Here you can create a message that gets displayed on screen when the application is launched. You can create a 'custom deny' or a queued message informing the user of the reason why they cannot launch the program. You can also create a one-time or on going general launch message, for example, "This program may crash if you remove the camera before quitting the application".

Once you have create the licenses you then need to add the computers, Every computer running keyAccess that logs on to the KeyServer gets audited by the KeyServer and added to the "Computers" window's discovery list.

Figure 12 shows the "Computers" windowpane.


Fig 12. Computers window.

Each new computer has a pink discovery icon next to it, to acknowledge the computer, right click on the name and select acknowledge. You can customize the categories to display such as MAC address and IP address. Under the divisions menu you can create separate divisions or computer groups. This can help you when you create reports so that you can view usage or activity based on computer groups.

Now you have the KeyServer installed and setup the final thing to do is monitor usage and create reports.

Figure 13 shows the currently logged in computers and users. This windowpane shows the maximum clients available for the purchased license as well as the name of the KeyServer.


Fig 13 The Users of the KeyServer

Double click on a user and you can view the licenses they have signed out as well as the times that they logged in. You can also send a bulletin message to the user.

Creating various reports and graphs

When you have used the KeyServer for a few months and built up a database of usage, you can build reports. These will allow you to gather useful information that can help you to plan for the future. There are many reports you can create, to include data such as: computer usages, license usages, weekly and daily reports, logins, list of denials etc. The data can be displayed as histograms. To create a report you select the appropriate report from the "Reports" menu. You then get a popup box to edit the criteria. You can select other reports to run and then choose the time period in which to run the reports. The resulting report can then be saved as either an html file or an xml file.


Fig 14. The KeyConfigure's reports popup window.

Conclusion

One of the many issues Mac system administrators have to address is software licensing and tracking. A KeyServer solution offers a great way of solving this issue as well as offering other services. The software is easy to setup, requires limited resources and can have multiple backup servers. It can manage any program as well as monitoring logins and logouts. You can add the KeyServer to a directory service and then use existing groups to assign licenses. If you divide your computers into divisions you can track software and computer use by division, if you wish to assign a division to a particular building then you can compare usage between different physical locations. Then once setup you can use the reporting feature to analyse different usage patterns to enable you to plan for the future. There are many other features that have not been discussed here, that a KeyServer can offer. Not only can the KeyServer monitor usage of license it can also control who has access and when, which means much greater flexibility in license management. For more information and to obtain a trial copy, go to www.sassafras.com.


Criss Myers is a Business Support Analyst (Mac Services), for Learning and Information Services, at the University of Central Lancashire, Preston, United Kingdom. He has been a Systems Server Administrator from the very first version of OS X Server. He Works with Macs as well as Linux, Unix and Windows and specializes in image deployment and maintenance as well as client management.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

TunnelBear 3.5.1 - Subscription-based pr...
TunnelBear is a subscription-based virtual private network (VPN) service and companion app, enabling you to browse the internet privately and securely. Features Browse privately - Secure your data... Read more
Typinator 7.4 - Speedy and reliable text...
Typinator turbo-charges your typing productivity. Type a little. Typinator does the rest. We've all faced projects that require repetitive typing tasks. With Typinator, you can store commonly used... Read more
Monosnap 3.4.9 - Versatile screenshot ut...
Monosnap lets you capture screenshots, share files, and record video and .gifs! Features Capture Capture full screen, just part of the screen, or a selected window Make your crop area pixel... Read more
Fantastical 2.4.5 - Create calendar even...
Fantastical 2 is the Mac calendar you'll actually enjoy using. Creating an event with Fantastical is quick, easy, and fun: Open Fantastical with a single click or keystroke Type in your event... Read more
TunnelBear 3.5.1 - Subscription-based pr...
TunnelBear is a subscription-based virtual private network (VPN) service and companion app, enabling you to browse the internet privately and securely. Features Browse privately - Secure your data... Read more
Typinator 7.4 - Speedy and reliable text...
Typinator turbo-charges your typing productivity. Type a little. Typinator does the rest. We've all faced projects that require repetitive typing tasks. With Typinator, you can store commonly used... Read more
Fantastical 2.4.5 - Create calendar even...
Fantastical 2 is the Mac calendar you'll actually enjoy using. Creating an event with Fantastical is quick, easy, and fun: Open Fantastical with a single click or keystroke Type in your event... Read more
Monosnap 3.4.9 - Versatile screenshot ut...
Monosnap lets you capture screenshots, share files, and record video and .gifs! Features Capture Capture full screen, just part of the screen, or a selected window Make your crop area pixel... Read more
Skim 1.4.32 - PDF reader and note-taker...
Skim is a PDF reader and note-taker for OS X. It is designed to help you read and annotate scientific papers in PDF, but is also great for viewing any PDF file. Skim includes many features and has a... Read more
ForkLift 3.1.1 - Powerful file manager:...
ForkLift is a powerful file manager and ferociously fast FTP client clothed in a clean and versatile UI that offers the combination of absolute simplicity and raw power expected from a well-executed... Read more

Latest Forum Discussions

See All

What mobile gaming can learn from the Ni...
While Nintendo might not have had things all its own way since it began developing for mobile, one thing it has got right is the release of the Switch. After the disappointment of the WiiU, which I still can't really explain, the Switch felt a... | Read more »
Programmer of Sonic The Hedgehog launche...
Japanese programmer Yuji Naka is best known for leading the team that created the original Sonic The Hedgehog. He’s moved on from the speedy blue hero since then, launching his own company based in Tokyo – Prope Games. Legend of Coin is the... | Read more »
Why doesn't mobile gaming have its...
The Overwatch League is a pretty big deal. It's an attempt to really push eSports into the mainstream, by turning them into, well, regular sports. But slightly less sweaty. It's a lavish affair with teams from all around the world, and more... | Read more »
Give Webzen’s new billiard game PoolTime...
Best known for producing hugely popular MMO titles, South Korean publisher Webzen is now taking aim at a different genre altogether. PoolTime is a realistic eight ball pool simulator, allowing you to compete in real-time matches against players... | Read more »
Let Them Come Guide - How to survive aga...
Let Them Come is all about making it as far as possible against overwhelming odds. Check out some of these tips to help you last a little longer in your unwinnable fight: [Read more] | Read more »
All the best games on sale for iPhone an...
Happy last day of the week. I hope you've been having a good one. I have. I saw ten doggos today. So because I'm in a good mood, I thought I'd round up all of the best games that are currently on sale on the App Store. [Read more] | Read more »
The very best games that came out for iP...
We're getting to the end of the first real, full, proper week of 2018. And in that time we've seen some pretty awesome games landing on the App Store. Of course, we've seen some absolute duffers as well. The sort of games that you look at and... | Read more »
Rusty Lake Paradise (Games)
Rusty Lake Paradise 1.4 Device: iOS Universal Category: Games Price: $2.99, Version: 1.4 (iTunes) Description: Jakob, the oldest son of the Eilander family, is returning to Paradise island after his mother passed away. Since her... | Read more »
Antihero Guide - Sneaky tricks to get ah...
Games of Antihero start out small and streamlined, but they quickly turn into long strategic conquests as you fight for control of the Victorian-era streets. If you find yourself struggling in the skullduggery department, here are a few things you... | Read more »
Here's why Niantic pulling Pokemon...
If there's one thing that Pokemon GO did well, it was bringing people together. I still remember seeing groups of people around the marina near where I live in the weeks after the game came out, all of them trying to grab some water Pokemon. There... | Read more »

Price Scanner via MacPrices.net

10″ iPad Pros on sale for $50-$75 off MSRP, n...
B&H Photo has 10″ and #Apple #iPad Pros on sale for up to $75 off MSRP. Shipping is free, and B&H charges sales tax in NY & NJ only. Note that some sale prices are restricted to certain... Read more
Apple refurbished Mac minis available startin...
Apple has restocked Certified Refurbished Mac minis starting at $419. Apple’s one-year warranty is included with each mini, and shipping is free: – 1.4GHz Mac mini: $419 $80 off MSRP – 2.6GHz Mac... Read more
Amazon offers Silver 13″ Apple MacBook Pros f...
Amazon has new Silver 2017 13″ #Apple #MacBook Pros on sale today for up to $150 off MSRP, each including free shipping: – 13″ 2.3GHz/128GB Silver MacBook Pro (MPXR2LL/A): $1199.99 $100 off MSRP – 13... Read more
Sale: 12″ 1.3GHz MacBooks on sale for $1499,...
B&H Photo has Space Gray and Rose Gold 12″ 1.3GHz #Apple MacBooks on sale for $100 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 12″ 1.3GHz Space... Read more
Apple offers Certified Refurbished 2017 iMacs...
Apple has a full line of Certified Refurbished iMacs available for up to $350 off original MSRP. Apple’s one-year warranty is standard, and shipping is free. The following models are available: – 27... Read more
13″ MacBook Airs on sale for $120-$100 off MS...
B&H Photo has 2017 13″ 128GB MacBook Airs on sale for $120 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 13″ 1.8GHz/128GB MacBook Air (MQD32LL/A): $... Read more
15″ Touch Bar MacBook Pros on sale for up to...
Adorama has Space Gray 15″ MacBook Pros on sale for $200 off MSRP. Shipping is free, and Adorama charges sales tax in NJ and NY only: – 15″ 2.8GHz MacBook Pro Space Gray (MPTR2LL/A): $2199, $200 off... Read more
21″ 3.4GHz 4K iMac on sale for $1399, $100 of...
Adorama has the 21″ 3.4GHz 4K #Apple #iMac on sale today for $1399. Their price is $100 off MSRP. Shipping is free, and Adorama charges sales tax in NJ and NY only: – 21″ 3.4GHz 4K iMac (MNE02LL/A... Read more
B&H offering 13″ Apple MacBook Pros for u...
B&H Photo has 13″ MacBook Pros on sale for up to $75-$120 off MSRP. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 13-inch 2.3GHz/128GB Space Gray MacBook Pro (... Read more
B&H continues to offer clearance 2016 15″...
B&H Photo has clearance 2016 15″ #MacBook Pros available for up to $800 off original MSRP. Shipping is free, and B&H charges NY & NJ sales tax only: – 15″ 2.7GHz Touch Bar MacBook Pro... Read more

Jobs Board

Commerce Engineer, *Apple* Media Products -...
# Commerce Engineer, Apple Media Products Job Number: 113161479 Santa Clara Valley, California, United States Posted: 01-Nov-2017 Weekly Hours: 40.00 **Job Summary** Read more
*Apple* Retail - Multiple Positions - Apple,...
Job Description:SalesSpecialist - Retail Customer Service and SalesTransform Apple Store visitors into loyal Apple customers. When customers enter the store, Read more
Site Reliability Engineer, *Apple* Pay - Ap...
# Site Reliability Engineer, Apple Pay Job Number: 113356036 Santa Clara Valley, California, United States Posted: 12-Jan-2018 Weekly Hours: 40.00 **Job Summary** Read more
UI Tools and Automation Engineer, *Apple* M...
# UI Tools and Automation Engineer, Apple Media Products Job Number: 86351939 Santa Clara Valley, California, United States Posted: 11-Jan-2018 Weekly Hours: 40.00 Read more
*Apple* Retail - Multiple Positions - Apple,...
Job Description: Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.