942 B
942 B
Security policy
Version 1.6.x is the supported line in this project archive.
License integration
- Customer installations configure only
LICENSE_TOKENand optional client settings. LICENSE_PUBLIC_KEY, private keys and signing keys are not supported.- Public issuer and lease keys are embedded from
internal/app/trusted_keys.jsonat build time. - Key generation, license issuance, token registries, revocation and lease signing exist only in the standalone Universal License Platform.
- Use HTTPS for hybrid and online verification.
- Protect the hybrid cache directory from other local users; it contains only signed lease tokens, not private keys.
Online mode fails closed if the platform is unavailable. Hybrid mode may continue only while a previously signed lease remains valid within the grace period encoded in the license.
Report suspected vulnerabilities privately to the project operator before public disclosure.