License
NullWard is free to use, for both commercial and personal use, without a license. The free version includes everything in these docs apart from the paid features below. The paid features require a license. Any valid license unlocks all of them: ML WAF Application tunnels Waiting room (queue) High availability (clustering) HTTP/3 Activate a license Licenses are issued through the store, as LicenseEdict licenses. Go to Settings > License. Paste the license into License Key and click Activate License. Licensed features turn on without a restart. Clustering is the exception: its settings apply after a restart (see High availability). In a cluster, activate the license on any node: it reaches the other nodes automatically, and the whole cluster counts as one installation. License Information shows the plan, the end of the license key, the validity dates (or Perpetual) and which NullWard versions the license covers. A license limited to a range of versions doesn't unlock the paid features on a version outside that range. License checks NullWard checks LicenseEdict licenses with the license server at store.sageisg.com over HTTPS. It checks at first activation, then on the schedule the product's licensing policy sets (daily by default). It also renews subscription licenses automatically before they expire. In a cluster, one node's check covers every node. Revoked or suspended licenses stop unlocking the paid features after the next check. The License page shows the license server's status and message. If the license server can't be reached, nothing is revoked: the license keeps working offline until the date shown under Last Checked, 7 days by default. Once that passes without a successful check, the paid features turn off until NullWard can check again. What is sent: the signed license, an installation ID derived from your cluster's encryption key, and the licensing library's version. No hostnames, configuration or traffic data are sent. NullWard needs outbound HTTPS to store.sageisg.com. If it reaches the internet through a proxy, set it under Settings > License > License Server Connection: Proxy URL: http://, https://, socks5:// or socks5h://, with credentials in the URL if needed (http://user:password@proxy.example.com:3128). The password is stored encrypted and shown masked. Extra CA certificates (PEM): needed only behind a proxy that inspects TLS. Its CA certificate is trusted in addition to the system's. These settings apply to every cluster node without a restart. Without a proxy set here, the standard HTTPS_PROXY and NO_PROXY environment variables are used. Legacy licenses Licenses issued by NullWard's previous licensing system still work during the transition to LicenseEdict. They're marked Legacy license on the License page. If you have both a LicenseEdict license and a legacy license, the LicenseEdict license is used. The legacy license stays stored as a fallback, and applies only if the LicenseEdict license stops being valid. To remove a legacy license, click Remove legacy license on the License page. Replace legacy licenses with LicenseEdict licenses before the transition ends. Without a license Without a valid license, NullWard keeps protecting your services with everything else described in these docs. The licensed features are unavailable: The Tunnels and Machine Learning pages are hidden, or shown read-only for existing configuration. HTTP/3 isn't served, and HTTP/3 backends are reached over HTTPS on TCP. The node runs standalone instead of clustered. Administrators can subscribe to the License expiring notification to get a warning in advance. See Monitoring, notifications and audit.
NullWard documentation