Configure SSL
Learn how to configure the Pdftools Licensing Gateway Service (LGS) to use the SSL and create HTTPS communication for your license key validation.
Before configuring SSL with the LGS, review Configure the LGS section.
SSL configuration
To enable SSL compatibility with LGS, follow these steps depending on how you installed the LGS:
- Windows
- Snap
- DEB and RPM
- Archive
- Docker
- Find the
appsettings.jsonLGS configuration file. It is located in the installation folder. For example:C:\Program Files\Pdftools\Licensing Gateway Service\appsettings.json - Add the following keys to your configuration file.
- Specify the port where SSL communication occurs:
LicensingServiceHTTPSPortNumber: 9990
- Add path to the certificate file:
CertPemFile: C:/certs/certificate.pem
- Add path to the private key file:
CertKeyFile: C:/certs/privatekey.keywarning
Include all files and configuration keys mentioned above. If you miss any of them the LGS doesn’t activate SSL and defaults to HTTP communication.
- Specify the port where SSL communication occurs:
- Example configuration file:
{"LicensingServicePortNumber": 9999,"LogFilePath": "C:/logs/pdftls/log.txt","LogRetentionDays": 7,"IsOfflineMode": false,"LicensingServiceHTTPSPortNumber": 9990,"CertPemFile": "C:/certs/cert.pem","CertKeyFile": "C:/certs/private-key.key"}
- Restart service after changing configuration by running the following command:
Stop-Service -Name "Licensing Gateway Service"Start-Service -Name "Licensing Gateway Service"
- Find the
appsettings.jsonLGS configuration file. It is located in the$SNAP_DATAdirectory. For example:/var/snap/licgwy/current/appsettings.json - Add the following keys to your configuration file.
- Specify the port where SSL communication occurs:
LicensingServiceHTTPSPortNumber: 9990
- Add path to the certificate file:
CertPemFile: /etc/lgs/ssl/cert.pem
- Add path to the private key file:
CertKeyFile: /etc/lgs/ssl/private-key.keywarning
Include all files and configuration keys mentioned above. If you miss any of them the LGS doesn’t activate SSL and defaults to HTTP communication.
- Specify the port where SSL communication occurs:
- Example configuration file:
{"LicensingServicePortNumber": 9999,"LogFilePath": "/usr/share/Pdftools/lgs/logs/log.txt","LogRetentionDays": 7,"IsOfflineMode": false,"LicensingServiceHTTPSPortNumber": 9990,"CertPemFile": "/etc/lgs/ssl/cert.pem","CertKeyFile": "/etc/lgs/ssl/private-key.key"}
- Restart service after changing configuration by running the following command:
sudo snap restart licgwy
- Open the configuration file
/etc/pdftools/lgs/appsettings.json. - Add the SSL keys. Keep the
DataDirectoryandLogFilePathvalues that the package sets, as in this example:Add all three SSL keys. If one is missing, the LGS doesn’t enable SSL and uses HTTP.{"LicensingServicePortNumber": 9999,"DataDirectory": "/var/lib/pdftools/lgs","LogFilePath": "/var/log/pdftools/lgs/lgs.log","LogRetentionDays": 7,"IsOfflineMode": false,"LicensingServiceHTTPSPortNumber": 9990,"CertPemFile": "/etc/lgs/ssl/cert.pem","CertKeyFile": "/etc/lgs/ssl/private-key.key"} - Restart the service:
sudo systemctl restart pdftools-lgs
The pdftools account must be able to read the certificate and key files. Keep the files outside /home and /root, which the service can’t access.
- Open the configuration file in the program folder, for example
/opt/pdftools-lgs/current/appsettings.json. - Add the SSL keys. Don’t set
DataDirectoryorLogFilePath, which the service definition sets. For example:Add all three SSL keys. If one is missing, the LGS doesn’t enable SSL and uses HTTP.{"LicensingServicePortNumber": 9999,"LogRetentionDays": 7,"IsOfflineMode": false,"LicensingServiceHTTPSPortNumber": 9990,"CertPemFile": "/etc/lgs/ssl/cert.pem","CertKeyFile": "/etc/lgs/ssl/private-key.key"} - Restart the service as the
lgsaccount:systemctl --user restart pdftools-lgs
The lgs account must be able to read the certificate and key files.
- Add the following keys to your configuration file.
- Specify the port where SSL communication occurs:
LicensingServiceHTTPSPortNumber: 9990
- Add path to the certificate file:
CertPemFile: /etc/lgs/ssl/cert.pem
- Add path to the private key file:
CertKeyFile: /etc/lgs/ssl/private-key.pemwarning
Include all files and configuration keys mentioned above. If you miss any of them the LGS doesn’t activate SSL and defaults to HTTP communication.
- Specify the port where SSL communication occurs:
- Example of the complete run command:
docker run --name lgsdocker \-e LICENSE_KEYS="YOUR_LICENSE_KEY" \-e LicensingServicePortNumber=9999 \-e LicensingServiceHTTPSPortNumber=9990 \-e CertPemFile=/etc/lgs/ssl/cert.pem \-e CertKeyFile=/etc/lgs/ssl/private-key.pem \-v /etc/lgs/ssl/:/etc/lgs/ssl/ \-p 9999:9999 \-p 9990:9990 \-d \pdftoolsag/license-gateway:latest
- Replace
YOUR_LICENSE_KEYwith the value of your license key. - Ensure that you certificates are reachable by storing them at
/etc/lgs/ssl/in your host system. You can alternatively replace and customise all port numbers, values, and file paths, but ensure to edit the previous command example accordingly.
- Replace
If a firewall protects the host, open the HTTPS port that you set in LicensingServiceHTTPSPortNumber, for example TCP port 9990.
If your configuration is correct, the LGS logs include information similar to:
[Information] Now listening on: "https://[::]:9990"