Linux DEB and RPM packages
Install the Licensing Gateway Service (LGS) on Linux with a DEB or RPM package. The LGS runs as a systemd service that starts with the machine. For the snap, refer to Connected mode. For hosts that don’t allow system packages, refer to Linux archive without root.
Two packages are available:
| Package | Contains | Install it on |
|---|---|---|
pdftools-licensing-gateway | The LGS service and the ptl command-line tool | The machine that validates license keys for your Pdftools products |
pdftools-licensing-shell | The ptl command-line tool only | The machine with internet access in full offline mode |
You can’t install both packages on one machine.
The packages require x86-64 Linux with glibc 2.28 or later:
- RHEL, Rocky Linux, or AlmaLinux 8 or later
- Debian 10 or later
- Ubuntu 20.04 LTS or later
Install the LGS
Install the LGS package on the machine that validates license keys for your network.
Prerequisites
Before you install the LGS, check the following prerequisites:
- You have root privileges on the machine.
- The machine has a permanent hostname. The LGS binds its database to the machine identity, which includes the hostname. For details, refer to Before you change the machine identity.
- Pdftools products on other machines can reach port 9999 on this machine.
- The snap isn’t installed on this machine. If it is, return its license keys with
licgwy.ptl remove-all. In full offline mode, deactivate them as described in Deactivate a license key instead. Then remove the snap withsudo snap remove licgwy.
Install and start the LGS
The last two steps need a connection to the Pdftools Licensing Service. For full offline mode, skip them and continue with Use full offline mode.
-
Download the package:
-
Install the package:
- Debian, Ubuntu
- RHEL, Rocky Linux, AlmaLinux
sudo apt install ./pdftools-licensing-gateway_amd64.debsudo dnf install ./pdftools-licensing-gateway.x86_64.rpmThe package enables the
pdftools-lgsservice but doesn’t start it, because the LGS has no license keys yet. The packages aren’t GPG-signed. Ifdnfchecks the signatures of local packages, add--nogpgcheck. -
Start the service:
sudo systemctl start pdftools-lgs -
Borrow a license key:
sudo ptl add "LICENSE_KEY_VALUE"Replace
LICENSE_KEY_VALUEwith your license key, and keep the quotes. Without them, the shell reads the angle brackets of a Pdftools SDK key as a redirection. -
Check the connection to the Pdftools Licensing Service:
sudo ptl status
The configuration file can hold a proxy password, so only root and the pdftools group can read it. To run ptl without sudo, add an administrator to the group with sudo usermod -aG pdftools USER_NAME, replacing USER_NAME with the administrator’s username.
Configure the LGS
The LGS package uses the following locations:
- Configuration:
/etc/pdftools/lgs/appsettings.json - Database:
/var/lib/pdftools/lgs/pls.db, encrypted - Logs:
/var/log/pdftools/lgs/, also available withjournalctl -u pdftools-lgs
To change a setting, edit the configuration file, and then run sudo systemctl restart pdftools-lgs. For the available settings, review Configure the LGS and Configure a forward proxy. Keep the DataDirectory and LogFilePath values that the package sets.
Use full offline mode
In full offline mode, the LGS machine has no connection to the Pdftools Licensing Service. You transfer the activation tokens between the LGS machine and a machine with internet access, for example on a USB flash drive.
To set up full offline mode:
- On the LGS machine, set
"IsOfflineMode": truein/etc/pdftools/lgs/appsettings.json. - On the LGS machine, restart the service:
sudo systemctl restart pdftools-lgs
- On a machine with internet access, install the Pdftools Licensing Shell as described in Install the Pdftools Licensing Shell on its own.
To activate and deactivate license keys, follow Activate license keys offline. Wherever that page uses ptl, run sudo ptl on the LGS machine.
Upgrade the LGS
To upgrade the LGS, install the newer package:
- Debian, Ubuntu
- RHEL, Rocky Linux, AlmaLinux
sudo apt install ./pdftools-licensing-gateway_amd64.deb
sudo dnf upgrade ./pdftools-licensing-gateway.x86_64.rpm
The upgrade keeps the configuration, the database, and the logs. A running LGS restarts with the new version.
Uninstall the LGS
Return your license keys before you uninstall the LGS, with sudo ptl remove-all, or in full offline mode as described in Deactivate a license key. Each borrowed license key counts against your license until you return it.
To uninstall the LGS, remove the package:
- Debian, Ubuntu
- RHEL, Rocky Linux, AlmaLinux
To keep the configuration, database, and logs:
sudo apt remove pdftools-licensing-gateway
To remove the configuration, database, and logs as well:
sudo apt purge pdftools-licensing-gateway
To keep the database and logs:
sudo dnf remove pdftools-licensing-gateway
Removing the package keeps a changed configuration file as appsettings.json.rpmsave.
To remove the configuration, database, and logs as well:
sudo PDFTOOLS_PURGE=1 dnf remove pdftools-licensing-gateway
Install the Pdftools Licensing Shell on its own
In full offline mode, ptl on a machine with internet access exchanges the activation tokens with the Pdftools Licensing Service. Install the pdftools-licensing-shell package on that machine instead of the LGS.
To install the Pdftools Licensing Shell:
-
Download the package:
-
Install the package:
- Debian, Ubuntu
- RHEL, Rocky Linux, AlmaLinux
sudo apt install ./pdftools-licensing-shell_amd64.debsudo dnf install ./pdftools-licensing-shell.x86_64.rpmThe packages aren’t GPG-signed. If
dnfchecks the signatures of local packages, add--nogpgcheck.
On this machine, ptl activate and ptl deactivate run without sudo.
Before you change the machine identity
The LGS encrypts its database with a key derived from the identity of the machine it runs on. That identity includes the hostname and the hardware (MAC) addresses of the network adapters, so the database works only on that machine. If the hostname or a MAC address changes, the LGS can’t open its database and doesn’t start. Its log then shows SQLite Error 26: 'file is not a database'. The license keys it borrowed stay registered to the old identity until they expire.
The following changes alter the machine identity:
- Renaming the machine
- Replacing a network adapter
- Recreating or moving a virtual machine that gets its MAC address assigned automatically
Give virtual machines a fixed MAC address. To change the identity of a machine that runs the LGS:
- Return all license keys:
- DEB and RPM packages:
sudo ptl remove-all. - Archive:
/opt/pdftools-lgs/current/ptl remove-all. - Full offline mode: Deactivate each license key as described in Deactivate a license key.
- DEB and RPM packages:
- Rename the machine or change its network adapters.
- Reset the LGS database, as described in Reset the LGS database.
- Borrow or activate the license keys again.
If the identity already changed and the LGS doesn’t start, choose the case that applies:
- You can change the hostname or MAC address back: Change it back, so that the LGS starts again. Then follow the preceding steps.
- You can’t change it back: Reset the LGS database, and then borrow or activate the license keys again. The license keys in the old database stay registered until they expire.
Reset the LGS database
Reset the database only after you return the license keys, or when the LGS can’t open its database. If you remove a database that still holds license keys, those keys stay registered until they expire.
To reset the LGS database:
- Stop the LGS:
- DEB and RPM packages:
sudo systemctl stop pdftools-lgs. - Archive:
systemctl --user stop pdftools-lgs.
- DEB and RPM packages:
- Remove the database and its SQLite side files:
- DEB and RPM packages:
sudo rm -f /var/lib/pdftools/lgs/pls.db{,-wal,-shm,-journal}. - Archive:
rm -f ~/.local/state/pdftools-lgs/pls.db*.
- DEB and RPM packages:
- Start the LGS, which creates a new, empty database:
- DEB and RPM packages:
sudo systemctl start pdftools-lgs. - Archive:
systemctl --user start pdftools-lgs.
- DEB and RPM packages:
Hardened hosts
The package installs and runs with SELinux enforcing and with FIPS mode enabled, and works on hosts that mount /tmp and /var/tmp with noexec. The service runs with systemd restrictions such as ProtectSystem=strict. To change them, create a drop-in file with sudo systemctl edit pdftools-lgs, because an upgrade replaces the service file.