Skip to content

Manage your license and updates

These instructions cover cPFence v4+. Use root for CLI commands. WebUI update tools require the relevant maintenance permission and access to the selected servers.

The installer normally adds your supplied key automatically. Use the task below if activation failed or you need a replacement key.

  1. Run cpfence --status and check the license status.

  2. Copy your key from the client area. Replace cPFence-XXXXXXXXXXXXXXXX with your key and run:

    Terminal window
    cpfence --install-license cPFence-XXXXXXXXXXXXXXXX
  3. Check cpfence --status again. The license should be Active.

The key must cover the server’s registered IP. Installing it also applies the server’s configured protection settings. If activation fails, resolve the displayed error before continuing. Keep license keys out of screenshots and shared messages.

For pricing and account tasks, see Choose a billing model and per-website IP synchronization.

  1. Sign in to the client area and open My Services.
  2. Choose the individual per-server license, then Reissue.
  3. On the new server, run cpfence --install-license cPFence-XXXXXXXXXXXXXXXX with your key in place of the placeholder, then check cpfence --status.

The new server IP is registered on first use. Bulk licenses must not use Reissue; ask support to update their IP list. Per-website licenses synchronize cluster IPs instead.

Cause What to do
Incorrect key Copy the correct key from the client area and run cpfence --install-license cPFence-XXXXXXXXXXXXXXXX, replacing the placeholder with your key.
New or changed server IP Use the process for your license type above.
Licensing endpoint rejects requests Contact support with the error and response status; repeated invalid requests can trigger access restrictions. A 403/503 response needs investigation and does not by itself establish the cause.
IP reputation problem Review the server IP at AbuseIPDB and contact support if it affects validation.
Per-website IP mismatch The licensed public IP must match Enhance → Servers → Server IP Address. Private/floating IPs are not supported for per-website billing. If the Enhance address is wrong, correct it to the licensed public IP and sync again; otherwise ask support about a suitable per-server plan.

To inspect the portal response from the affected server:

Terminal window
curl -s -D - -o /dev/null https://my.cpfence.app

Share the status and exact error privately with support. A 403/503 can help investigation but does not prove the cause by itself.

If the problem continues, open a support ticket with the exact error. Keep keys and account details private.

  1. Open System Settings → General Settings and choose the server.
  2. Change Automatically install cPFence updates, then Save changes.
  3. For multiple servers, use Apply to servers… and review the target list.

On automatically installs new cPFence versions. Off keeps version checks and malware signature refreshes running. Fresh installations default On; existing choices are retained during migration and reinstall.

General Settings showing the selected server and Automatically install cPFence updates switch.

Choose the server before changing automatic installation. The switch controls software installation; version checks and signature refreshes continue when it is Off. Select the image to enlarge it; use your browser's Back command to return.

CLI controls:

Action Command
Enable automatic installation cpfence --enable-auto-updates
Disable automatic installation cpfence --disable-auto-updates

Run the command for your intended choice.

  1. Open Tools & Utilities → System Utilities → Update cPFence.
  2. Choose the server or subset and select Check for Updates.
  3. Select Run cPFence Update for software, or Update Signatures Only for malware signatures.
  4. Confirm the displayed targets, including excluded secondary servers.
  5. If the result is Queued, use Refresh Update Status until the job finishes. Refresh status after a disconnect before submitting another update.

Update cPFence menu showing software, signature, availability and status controls.

Choose the intended update action for the selected servers, then use Refresh Update Status for queued work. Select the image to enlarge it; use your browser's Back command to return.

A queued job is not a completed installation. Read each server’s result and check its installed version afterward.

Terminal window
cpfence --check-updates
cpfence --update

When prompted, answer yes. The ten-second countdown allows cancellation. To refresh signatures only:

Terminal window
cpfence --update-signatures

Check progress or the final result with:

Terminal window
cpfence --update-status

Already-current messages are normal. Software updates may restart protection services and the WebUI.

  • License problem: check account status, registered IP, and network access; reinstall the key privately if needed.
  • Busy or queued: follow the existing job’s status; do not remove locks or queue duplicates.
  • Recovery package mismatch: contact support with the version and exact error. Do not replace recovery files manually.
  • Secondary server excluded: update it locally if necessary, then check its connection.

See check the installed version to inspect individual or cluster versions.

An installer reinstall is a separate backup-and-repair operation. Normal v4 updates use cpfence --update.