Licensing¶
This section describes the licensing model for Fudo Enterprise modules. The ShareAccess license is managed separately and described in the ShareAccess: License section.
Warning
Starting with version 6.0, the licensing model of Fudo Enterprise has been updated.
The previously unified Fudo Enterprise license has been divided into three independent modules:
Privileged Session Management (PSM)
Password Vault (PV)
ShareAccess
Each module is licensed separately and have its own expiration date and usage limits. For more information, see the Limit of Active Users subsection.
Licensed Modules
The platform includes the following licensed modules:
Privileged Session Management (PSM) - Represents the core functionality that was previously covered by the Fudo Enterprise license, including privileged session proxying, monitoring, and access control.
Password Vault (PV) - Provides secure storage and lifecycle management of credentials such as passwords, SSH keys, API keys, certificates, and secure notes.
ShareAccess - Enables secure and simplified access for third parties, including external vendors, by providing browser-based access to shared resources and streamlining connection and credential handling.
Each module have:
its own expiration date
independent active user limits
additional feature limits
Expiration Date
Each licensed module have a separate expiration date. After the expiration date is reached, functionality of the affected module may be restricted.
Support End Date
Starting with version 6.1, license files include a technical support end date. This date indicates when technical support ends and determines whether the system is eligible for upgrades to newer versions.
Note
Existing license files remain valid in Fudo Enterprise 6.1
If the license file does not include the support end date, the support status is displayed as Unknown
An expired support end date or Unknown support status blocks upgrades to future Fudo Enterprise versions
Before upgrading beyond Fudo Enterprise 6.1, contact Fudo Presales team to obtain a license file that includes the support end date
Number of Cluster Nodes
The license specifies the number of nodes that can be part of a cluster. If this number is exceeded, the additional nodes will reject connections and log appropriate events in the system logs.
Available Servers
The license determines how many servers can be added to the system. Once this limit is exceeded, it is not possible to add new servers or modify existing ones.
Limit of Active Users (PSM Module)
Number of active users defines how many users can establish sessions to servers using the Privileged Session Management (PSM) module.
Note
A user is counted as active if they have started at least one session within the last 30 days.
A license slot is released automatically when a user has no session activity for more than 30 days.
If the licensed limit has already been reached, only users who were already active within the last 30 days can continue to establish sessions. Users who have not been active during that period cannot start new sessions until a license slot becomes available.
Following actions are not restricted by the active user limit:
Logging into the Admin Panel is always allowed. This prevents administrators from being locked out of the system due to license limits.
Users authenticated through ShareAccess are not counted against the PSM Module active users limit.
Note
You can view each user’s license consumption status in the user edit form, on the Modules subtab.
Limit of Active Users (PV Module)
The Password Vault license includes a separate active user limit, independent of the PSM module. This limit applies only to Password Vault operations.
Limitations of the Password Vault Basic License
Password Vault module is available in both full and limited license variants.
The full license provides access to the complete Password Vault functionality, including unrestricted collection management, full secret management, all supported secret types, full collection permissions, and global policy configuration.
The basic license includes selected restrictions. In this variant:
administrators cannot create child-level collections or create secrets in child-level collections.
Full access permissions for collections are not available for users and groups, and only View and View on Request permissions can be assigned.
Global Password Vault policy configuration and policy compliance status are also unavailable.
Secret creation is limited to Login, SSH Key, and Note types.
License Management Privileges
The following privileges are required to manage licenses:
license-read– allows viewing license informationlicense-upload– allows uploading or deleting license files
Note
For details about viewing license information, see the License section.
Related topics: