--- title: "License & Feature Entitlements" description: "Documentation for License & Entitlements" --- ## Table of Contents 1. [Overview](#1-overview) 2. [Commercial & Licensing Architecture](#2-commercial--licensing-architecture) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Status Overview](#4-visual-interface--status-overview) 5. [Telemetry & Feature Entitlement Matrix](#5-telemetry--feature-entitlement-matrix) 6. [License Key Activation Workflow](#6-license-key-activation-workflow) 7. [Operational Best Practices](#7-operational-best-practices) 8. [Troubleshooting & Verification](#8-troubleshooting--verification) 9. [Glossary](#9-glossary) --- ## 1. Overview The **License & Feature Entitlements** module in **Ring2All SBC** governs capacity allocations, software tier validation, cryptographic hardware fingerprint binding, and advanced telecom subsystem unlocks. From small enterprise SIP trunking deployments to multi-thousand channel Tier-1 carrier networks, this module provides administrators with transparent visibility into their active concurrent channel ceiling and carrier feature entitlements. The licensing subsystem executes local cryptographic verification using asymmetric public-key cryptography (Ed25519 / RSA-4096), ensuring that carrier installations operate autonomously without requiring continuous outbound internet connectivity or cloud "phone-home" dependencies. --- ## 2. Commercial & Licensing Architecture * **Autonomous Air-Gapped Enforcement**: Carrier-grade telecommunications backbones frequently operate within secure, isolated DMZs. Ring2All SBC verifies license key signatures locally against embedded root authority certificates. * **Granular Subsystem Scaling**: Capacities scale dynamically based on licensed concurrent sessions (CPS and active channels), unlocking high-throughput features like Class 4 LCR routing, WebRTC media bridging, and STIR/SHAKEN attestation. * **Community Edition Transparency**: Every default SBC installation includes an unexpiring Community Edition license with full access to standard Kamailio SIP proxying, basic firewall controls, and up to 10 concurrent calls. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Key Capabilities | | :--- | :--- | | **SBC Administrator** | Review active concurrent call usage against license caps, copy the unique hardware fingerprint, and apply new license keys. | | **Telecom Procurement Officer** | Inspect feature entitlement tiers (Class 4 LCR, HA Clustering, WebRTC) to plan network expansion and capacity upgrades. | | **System Auditor** | Verify license authenticity, expiration milestones, and ensure regulatory compliance across telecommunications infrastructure. | --- ## 4. Visual Interface & Status Overview The License console is organized into three distinct cards: **License Status**, **Module & Feature Entitlements**, and **Activate License Key**. ![License & Feature Entitlements](/screenshots/sbc/account-menu/license.png) --- ## 5. Telemetry & Feature Entitlement Matrix ### License Status Card | Metric / Attribute | Sample Value | Description | | :--- | :--- | :--- | | **License Tier Badge** | `COMMUNITY EDITION` | Visual indicator denoting whether the platform is running Free Community, Professional, or Carrier Tier. | | **Concurrent Calls** | `0 / 10` | Real-time session meter displaying active SIP dialogs versus the maximum allowed concurrent call ceiling. | | **License Key** | `Not Licensed` / Cryptographic ID | Unique license token identifier registered on the host. | | **Expires** | `Never (Perpetual / Free)` / Date | Expiration threshold of the active license token. | | **Hardware Fingerprint** | `1ad76b151066...da1ac79` | SHA-256 machine hash derived from CPU, motherboard UUID, and primary network MAC address. | ### Module & Feature Entitlements | Enterprise Subsystem | Community Tier Status | Carrier / Enterprise Tier Status | Technical Capability Unlocked | | :--- | :--- | :--- | :--- | | **Class 4 LCR Engine** | `Upgrade Required` | **Fully Enabled** | High-performance dynamic least-cost routing with multi-carrier rate deck evaluation in microseconds. | | **WebRTC Media Bridge** | `Community Capped` | **Unlimited Media Channels** | RTPEngine transcoding bridge connecting browser SIP endpoints (DTLS-SRTP) to legacy carrier RTP. | | **STIR / SHAKEN Attestation** | `Carrier Tier Required` | **Fully Enabled** | Cryptographic call signing, PASSporT token generation, and Tier-A/B/C attestation verification. | | **High Availability Cluster** | `Carrier Tier Required` | **Active-Active / Active-Standby** | Multi-node state replication via VRRP and distributed DMQ clustering for zero-downtime failover. | --- ## 6. License Key Activation Workflow 1. **Obtain Hardware Fingerprint**: * Navigate to **License** from the account menu. * Copy the 64-character **Hardware Fingerprint** string displayed in the status overview. 2. **Generate / Request License**: * Provide the hardware fingerprint to your Ring2All account representative or enterprise provisioning portal. 3. **Apply the License Block**: * Paste the armored cryptographic license key string into the **Activate License Key** input area. * Click **Activate License**. * The SBC daemon verifies the signature, reloads internal htables, and updates concurrent call thresholds instantly without dropping active phone calls. --- ## 7. Operational Best Practices * **Monitor Concurrent Call Peak Ratios**: Establish automated alerts when active calls reach 80% of your licensed ceiling to ensure capacity expansions are ordered prior to trunk throttling. * **Record Fingerprint Prior to Hardware Migrations**: If planning a hypervisor host migration or server replacement, verify if network MAC changes will alter the hardware fingerprint. * **Keep Backup of License Block**: Safely archive your active license block in your organizational secret management vault for rapid disaster recovery rebuilding. --- ## 8. Troubleshooting & Verification | Issue / Symptom | Root Cause | Resolution | | :--- | :--- | :--- | | Error: "Hardware fingerprint mismatch" | The license was generated for a different server or network MAC changed | Verify that the hardware fingerprint on the target host matches the fingerprint submitted during key issuance. | | Calls rejected with SIP 503 Service Unavailable | Concurrent call volume has reached the licensed limit (e.g. 10/10) | Upgrade the license tier or review active calls to terminate orphaned sessions. | | License key fails cryptographic verification | Key block truncated or corrupted during copy-paste | Ensure the entire block (including header and footer delimiters) is copied without extra whitespaces. | --- ## 9. Glossary * **Concurrent Calls (CC)**: Active bidirectional SIP call dialogs traversing the SBC at any given moment. * **Hardware Fingerprint**: Deterministic hardware signature computed from immutable host machine parameters. * **STIR/SHAKEN**: Telecom security framework designed to prevent fraudulent caller ID spoofing via digital certificates. * **LCR (Least-Cost Routing)**: Algorithmic selection of wholesale voice paths based on real-time rate card comparison.