Licences

Install a Nixt DNA Server licence, see where it stands, what it counts, and what happens when it runs out — mail is held, never refused or lost.

A licence says who a Nixt DNA Server installation is licensed to, until when, and how much it allows. The server checks it offline, against a key built into the server, so it never needs to reach us.

A licence is two files: licence.json and its signature, licence.json.sig. You get them from your account on nixtoffice.com; see Nixt DNA Server licences. The free licence, for a server you run yourself, allows 25 mailboxes, one domain, one organisation and one server, with every security feature.

Install a licence

  1. Copy both files to the server, into the same folder, keeping their names. On a server set up with init, use /etc/nixt-server/:

    sudo install -o nixt -g nixt -m 0600 licence.json licence.json.sig /etc/nixt-server/
  2. Name the licence in /etc/nixt-server/nixt-server.toml:

    [licence]
    file = "/etc/nixt-server/licence.json"

    The server finds the signature beside it, with .sig added to the name.

  3. Check it, then restart the server:

    sudo -u nixt nixt-server check --config /etc/nixt-server/nixt-server.toml
    sudo systemctl restart nixt-server

check refuses a file that is not a licence this server takes — one whose signature does not match, or a format it does not read — and says why after [licence]:. The service runs check before every start, so fix the files before you restart.

In a container, put both files in the configuration volume (/etc/nixt-server), add the same [licence] table to the configuration there, and restart the container.

To renew, put the new pair of files in place of the old ones and restart the same way. Anything the server held while the licence was out of date then goes on, in the order it arrived.

See where the licence stands

These use the nxs shell function from the Quick start.

nxs explain
nxs doctor

explain says whether a licence is installed, who it is for, its tier, when it was issued and expires, how many days are left, and what it allows — for example it allows 25 mailboxes, 1 domain, 1 organisation and 1 server. doctor warns 30, 14 and 3 days before the licence expires, and on every day of the grace period, and says what the server is holding once it is restricted.

The admin API gives the same: GET /licence for the operator, and GET /tenants/{tenant}/licence for an organisation’s administrators. See the Admin API reference.

What is counted

CountedNot counted
Mailboxes: active accounts of people who sign in.Aliases, groups, resources such as rooms, and shared mailboxes.
Domains, across every organisation.A sandbox’s organisations, and an organisation moved to another server.
Organisations (tenants) on the server.
Servers: nodes running at once.

Past what the licence allows:

  • creating an organisation, a domain or a mailbox is refused, with a sentence naming the licence. This applies however it is made: the console, the API, the command line, SCIM and reactivating an account;
  • a node that would make more servers than the licence allows is refused when it starts.

Nothing else is limited. Security features are never limited by a licence, and nothing about a licence is asked before somebody signs in or a message is scanned.

When a licence runs out

A server is never cut off, and no mail is ever lost.

  1. 10 days’ grace. The server keeps working in full for 10 days. The grace starts at the earliest of: the licence’s expiry date; the first start of a server with no licence at all; and the first moment more mailboxes are in use than the licence allows.
  2. Then the server is restricted. It carries 500 messages a calendar month (UTC), incoming and outgoing together. The count starts again on the first of each month.
  3. Past the 500, mail is held. Messages are still accepted, never refused: an incoming message is kept but not delivered, so nobody sees it yet; an outgoing one is kept and not sent.
  4. Held mail goes on by itself the moment the server is back within a licence — a valid licence installed, or the mailboxes in use brought back within it. It is delivered and sent oldest first.

While restricted, new organisations, domains and mailboxes are refused. Everything else keeps working: people sign in, read and send mail up to the allowance, and the console stays open.

Next steps

Something unclear or out of date on this page? Tell us.