1
0
mirror of https://github.com/Wind4/vlmcsd.git synced 2024-11-28 21:11:03 +08:00
vlmcsd/man/vlmcsd.8.unix.txt

807 lines
40 KiB
Plaintext
Raw Permalink Normal View History

2015-11-29 17:30:52 +08:00
VLMCSD(8) KMS Activation Manual VLMCSD(8)
NAME
vlmcsd - a fully Microsoft compatible KMS server
SYNOPSIS
vlmcsd [ options ]
DESCRIPTION
vlmcsd is a fully Microsoft compatible KMS server that provides product
activation services to clients. It is meant as a drop-in replacement
for a Microsoft KMS server (Windows computer with KMS key entered). It
currently supports KMS protocol versions 4, 5 and 6.
vlmcsd is designed to run on POSIX compatible operating systens. It
only requires a basic C library with a BSD-style sockets API and either
fork(2) or pthreads(7). That allows it to run on most embedded systems
like routers, NASes, mobile phones, tablets, TVs, settop boxes, etc.
Some efforts have been made that it also runs on Windows.
Although vlmcsd does neither require an activation key nor a payment to
anyone, it is not meant to run illegal copies of Windows. Its purpose
is to ensure that owners of legal copies can use their software without
restrictions, e.g. if you buy a new computer or motherboard and your
key will be refused activation from Microsoft servers due to hardware
changes.
vlmcsd may be started via an internet superserver like inetd(8) or
xinetd(8) as well as an advanced init system like systemd(8) or
launchd(8) using socket based activation. If vlmcsd detects that
stdin(3) is a socket, it assumes that there is already a connected
2016-12-02 15:56:18 +08:00
client on stdin that wants to be activated.
All options that control setting up listening sockets will be ignored
2017-06-22 15:21:58 +08:00
when in inetd mode. The sockets will be set up by your internet super-
2016-12-02 15:56:18 +08:00
server. You also cannot limit the number of simultanous clients (option
-m). You need to configure the limit in your internet superserver.
The followong features that require that vlmcsd is permanently loaded
will not work if started from an internet superserver:
You cannot maintain a client list (option -M1)
EPID Randomization Level 1 (option -r1) works like Level 2
(-r2). You may want to use Level 0 (-r0) or custom EPIDs
2017-06-22 15:21:58 +08:00
(options -w, -G, -0, -3 and -6) instead.
2015-11-29 17:30:52 +08:00
OPTIONS
Since vlmcsd can be configured at compile time, some options may not be
available on your system.
2017-06-22 15:21:58 +08:00
All options that do no require an argument may be combined with a sin-
2015-11-29 17:30:52 +08:00
gle dash, for instance "vlmcsd -D -e" is identical to "vlmcsd -De". For
all options that require an argument a space between the option and the
2016-12-02 15:56:18 +08:00
option argument is optional. Thus "vlmcsd -r 2" and "vlmcsd -r2" are
2015-11-29 17:30:52 +08:00
identical too.
-h or -?
Displays help.
2017-06-22 15:21:58 +08:00
-V Displays extended version information. This includes the com-
2016-12-02 15:56:18 +08:00
piler used to build vlmcsd, the intended platform and flags
(compile time options) to build vlmcsd. If you have the source
2016-06-06 10:36:00 +08:00
code of vlmcsd, you can type make help (or gmake help on systems
2016-12-02 15:56:18 +08:00
that do not use the GNU version of make(1) by default) to see
2016-06-06 10:36:00 +08:00
the meaning of those flags.
2015-11-29 17:30:52 +08:00
-L ipaddress[:port]
2016-12-02 15:56:18 +08:00
Instructs vlmcsd to listen on ipaddress with optional port
(default 1688). You can use this option more than once. If you
2015-11-29 17:30:52 +08:00
do not specify -L at least once, IP addresses 0.0.0.0 (IPv4) and
:: (IPv6) are used. If the IP address contains colons (IPv6) you
2016-12-02 15:56:18 +08:00
must enclose the IP address in brackets if you specify the
2015-11-29 17:30:52 +08:00
optional port, e.g. [2001:db8::dead:beef]:1688.
2016-12-02 15:56:18 +08:00
If no port is specified, vlmcsd uses the default port according
to a preceding -P option. If you specify a port, it can be a
number (1-65535) or a name (usually found in /etc/services if
2015-11-29 17:30:52 +08:00
not provided via LDAP, NIS+ or another name service).
2016-12-02 15:56:18 +08:00
If you specify a link local IPv6 address (fe80::/10, usually
2015-11-29 17:30:52 +08:00
starting with fe80::), it must be followed by a percent sign (%)
2016-12-02 15:56:18 +08:00
and a scope id (=network interface name or number) on most
unixoid OSses including Linux, Android, MacOS X and iOS, e.g.
2015-11-29 17:30:52 +08:00
fe80::1234:56ff:fe78:9abc%eth0 or
2016-12-02 15:56:18 +08:00
[fe80::1234:56ff:fe78:9abc%2]:1688. Windows (including cygwin)
does not require a scope id unless the same link local address
is used on more than one network interface. Windows does not
2015-11-29 17:30:52 +08:00
accept a name and the scope id must be a number.
2016-08-02 22:39:39 +08:00
-o level
2016-12-02 15:56:18 +08:00
Sets the level of protection against activations from public IP
2016-08-02 22:39:39 +08:00
addresses. The default is -o0 for no protection.
2017-06-22 15:21:58 +08:00
-o1 causes vlmcsd not to listen on all IP addresses but on pri-
2016-12-02 15:56:18 +08:00
vate IP addresses only. IPv4 addresses in the 100.64.0.0/10
2016-08-02 22:39:39 +08:00
range (see RFC6598) are not treated as private since they can be
reached from other users of your ISP. Private IPv4 addresses are
2016-12-02 15:56:18 +08:00
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16 and
127.0.0.0/8. vlmcsd treats all IPv6 addresses not within
2016-08-02 22:39:39 +08:00
2000::/3 as private addresses.
2016-12-02 15:56:18 +08:00
If -o1 is combined with -L, it will listen on all private IP
addresses plus the ones specified by one or more -L statements.
If -o1 is combined with -P, only the last -P statement will be
2016-08-02 22:39:39 +08:00
used.
Using -o1 does not protect you if you enable NAT port forwarding
2016-12-02 15:56:18 +08:00
on your router to your vlmcsd machine. It is identical to using
multiple -L statements with all of your private IP addresses.
2016-08-02 22:39:39 +08:00
What -o1 does for you, is automatically enumerating your private
IP addresses.
-o2 does not affect the interfaces, vlmcsd is listening on. When
2016-12-02 15:56:18 +08:00
a clients connects, vlmcsd immediately drops the connection if
the client has a public IP address. Unlike -o1 clients will be
2016-08-02 22:39:39 +08:00
able to establish a TCP connection but it will be closed without
2016-12-02 15:56:18 +08:00
a single byte sent over the connection. This protects against
clients with public IP addresses even if NAT port forwarding is
used. While -o2 offers a higher level of protection than -o1,
2017-06-22 15:21:58 +08:00
the client sees that the KMS TCP port (1688 by default) is actu-
2016-08-02 22:39:39 +08:00
ally accepting connections.
2016-12-02 15:56:18 +08:00
If vlmcsd is compiled to use MS RPC, -o2 can only offer very
poor protection. Control is passed from MS RPC to vlmcsd after
the KMS protocol has already been negotiated. Thus a client can
always verify that the KMS protocol is available even though it
2016-08-15 18:35:59 +08:00
receives an RPC_S_ACCESS_DENIED error message. vlmcsd will issue
2016-12-02 15:56:18 +08:00
a warning if -o2 is used with MS RPC. For adaequate protection
2016-08-15 18:35:59 +08:00
do not use a MS RPC build of vlmcsd with -o2.
2016-12-02 15:56:18 +08:00
-o3 combines -o1 and -o2. vlmcsd listens on private interfaces
2016-08-02 22:39:39 +08:00
only and if a public client manages to connect anyway due to NAT
port forwarding, it will be immediately dropped.
2016-12-02 15:56:18 +08:00
If you use any form of TCP level port forwarding (e.g. nc(1),
netcat(1), ssh(1) port forwarding or similar) to redirect KMS
requests to vlmcsd, there will be no protection even if you use
-o2 or -o3. This is due to the simple fact that vlmcsd sees the
IP address of the redirector and not the IP address of the
2016-08-02 22:39:39 +08:00
client.
-o1 (and thus -o3) is not (yet) available in some scenarios:
2017-06-22 15:21:58 +08:00
FreeBSD: There is a longtime unfixed bug <https://
bugs.freebsd.org/bugzilla/show_bug.cgi?id=178881> in the
32-bit ABI of the 64-bit kernel. If you have a 64-bit Free-
2016-12-02 15:56:18 +08:00
BSD kernel, you must run the 64-bit version of vlmcsd if
you use -o1 or -o3. The 32-bit version causes undefined
2017-06-22 15:21:58 +08:00
behavior up to crashing vlmcsd. Other BSDs (NetBSD, Open-
2016-08-02 22:39:39 +08:00
BSD, Dragonfly and Mac OS X) work correctly.
2016-12-02 15:56:18 +08:00
If vlmcsd was started by an internet superserver or was
compiled to use Microsoft RPC (Windows only) or simple
2016-08-02 22:39:39 +08:00
sockets, -o1 and -o3 are not available by design.
2015-11-29 17:30:52 +08:00
-P port
2016-12-02 15:56:18 +08:00
Use TCP port for all subsequent -L statements that do not
2017-06-22 15:21:58 +08:00
include an optional port. If you use -P and -L, -P must be spec-
2015-11-29 17:30:52 +08:00
ified before -L.
2016-12-11 12:25:30 +08:00
-O vpn-adapter-name[=ipv4-address][/cidr-mask][:dhcp-lease-duration]
Enables a compatible VPN adapter to create additional local IPv4
addresses (like 127.0.0.1) that appear as remote IPv4 addresses
to the system. This allows product activation using a local
instance of vlmcsd. This feature is only available in Windows
and Cygwin builds of vlmcsd since it is not of any use on other
2017-06-22 15:21:58 +08:00
operating systems. Compatible VPN adapters are Tap-windows ver-
2016-12-11 12:25:30 +08:00
sion 8.2 or higher (from OpenVPN) and the TeamViewer VPN
adapter. There are two special vpn-adapter-names. A single
2017-06-22 15:21:58 +08:00
period (.) instructs vlmcsd to use the first available compati-
2016-12-11 12:25:30 +08:00
ble VPN adapter. A single dash (-) disables the use of a VPN
adapter if one has been configured in vlmcsd.ini(5). The vpn-
2017-06-22 15:21:58 +08:00
adapter-name is not case-sensitive. If the vpn-adapter-name con-
2016-12-11 12:25:30 +08:00
tains spaces (e.g. Ethernet 3), you must enclose it in quotes.
The default ipv4-address is 10.10.10.9 and the default cidr-mask
is 30. If you are using the default values, your VPN adapter
2017-06-22 15:21:58 +08:00
uses an IPv4 address of 10.10.10.9 and you can set your activa-
2016-12-11 12:25:30 +08:00
tion client to use the easy to remember address 10.10.10.10
(e.g. slmgr /skms 10.10.10.10 or cscript ospp.vbs
/sethst:10.10.10.10).
The dhcp-lease-duration is a number optionally followed by s, m,
h, d or w to indicate seconds, minutes, hours, days or weeks.
The default dhcp-lease-duration is 1d (one day). It is normally
not required to change this value.
It is advised not to manually configure your OpenVPN TAP or
TeamViewer VPN adapter in "Network Connections". If you set the
IPv4 configuration manually anyway, the IPv4 address and the
subnet mask must match the -O parameter. It is safe leave the
IPv4 configuration to automatic (DHCP). vlmcsd will wait up to
2017-06-22 15:21:58 +08:00
four seconds for the DHCP configuration to complete before bind-
2016-12-11 12:25:30 +08:00
ing to and listenin on any interfaces.
You should be aware that only one program can use a VPN adapter
at a time. If you use the TeamViewer VPN adapter for example,
you will not be able to use the VPN feature of TeamViewer as
long as vlmcsd is running. The same applies to OpenVPN TAP
adapters that are in use by other programs (for example OpenVPN,
2017-06-22 15:21:58 +08:00
QEMU, Ratiborus VM, aiccu, etc.). The best way to avoid con-
2016-12-11 12:25:30 +08:00
flicts is to install Tap-Windows from OpenVPN, cd to C:\Program
2017-06-22 15:21:58 +08:00
Files\TAP-Windows\bin and run addtap.bat to install an addi-
2016-12-11 12:25:30 +08:00
tional TAP adapter. Go to "Network Connections" and rename the
new adapter to "vlmcsd" and specify -O vlmcsd to use it.
2017-06-22 15:21:58 +08:00
Example: -O "Ethernet 7"=192.168.123.1/24 (uses VPN adapter Eth-
2016-12-11 12:25:30 +08:00
ernet 7 with IPv4 address 192.168.123.1 and have 192.168.123.2
to 192.168.123.254 as additional local (but apparently remote)
IPv4 addresses.
2017-02-11 17:39:52 +08:00
-x0 and -x1
Controls under what circumstances vlmcsd will exit. Using the
default of -x0 vlmcsd stays active as long as it can perform
2017-06-22 15:21:58 +08:00
some useful operations. If vlmcsd is run by any form of a watch-
2017-02-11 17:39:52 +08:00
dog, e.g. NT service manager (Windows), systemd (Linux) or
launchd (Mac OS / iOS), it may be desirable to end vlmcsd and
let the watchdog restart it. This is especially true if some
pre-requisites are not yet met but will be some time later, e.g.
network is not yet fully setup.
By using -x0 vlmcsd will
exit if none of the listening sockets specified with -L can
be used. It continues if at least one socket can be setup
for listening.
exit any TAP mirror thread (Windows version only) if there
is an error condition while reading or writing from or to
the VPN adapter but continue to work without utilizing a
VPN adapter.
By using -x1 vlmcsd will
exit if not all listening sockets specified with -L can be
used.
exit completely if there is a problem with a VPN adapter it
is using. This can happen for instance if the VPN adapter
has been disabled using "Control Panel - Network - Adapter
Settings" while vlmcsd is using it.
Please note that -x1 is kind of a workaround option. While it
may help under some circumstances, it is better to solve the
problem at its origin, e.g. properly implementing dependencies
in your startup script to ensure all network interfaces and the
VPN adapter you will use are completely setup before you start
vlmcsd.
2016-06-06 10:36:00 +08:00
-F0 and -F1
2017-02-11 17:39:52 +08:00
Allow (-F1) or disallow (-F0) binding to IP addresses that are
2016-06-06 10:36:00 +08:00
currently not configured on your system. The default is -F0. -F1
allows you to bind to an IP address that may be configured after
2017-02-11 17:39:52 +08:00
you started vlmcsd. vlmcsd will listen on that address as soon
as it becomes available. This feature is only available under
Linux (IPv4 and IPv6) and FreeBSD (IPv4 only). FreeBSD allows
this feature only for the root user (more correctly: processes
that have the PRIV_NETINET_BINDANY privilege). Linux does not
2016-06-06 10:36:00 +08:00
require a capability for this.
2015-11-29 17:30:52 +08:00
-t seconds
2017-06-22 15:21:58 +08:00
Timeout the TCP connection with the client after seconds sec-
2017-02-11 17:39:52 +08:00
onds. After sending an activation request. RPC keeps the TCP
2017-06-22 15:21:58 +08:00
connection for a while. The default is 30 seconds. You may spec-
2017-02-11 17:39:52 +08:00
ify a shorter period to free ressources on your device faster.
This is useful for devices with limited main memory or if you
2017-06-22 15:21:58 +08:00
used -m to limit the concurrent clients that may request activa-
2017-02-11 17:39:52 +08:00
tion. Microsoft RPC clients disconnect after 30 seconds by
default. Setting seconds to a greater value does not make much
2015-11-29 17:30:52 +08:00
sense.
-m concurrent-clients
2017-02-11 17:39:52 +08:00
Limit the number of clients that will be handled concurrently.
2015-11-29 17:30:52 +08:00
This is useful for devices with limited ressources or if you are
2017-02-11 17:39:52 +08:00
experiencing DoS attacks that spawn thousands of threads or
forked processes. If additional clients connect to vlmcsd, they
2017-06-22 15:21:58 +08:00
need to wait until another client disconnects. If you set con-
2015-11-29 17:30:52 +08:00
current-clients to a small value ( <10 ), you should also select
2017-02-11 17:39:52 +08:00
a reasonable timeout of 2 or 3 seconds with -t. The default is
2015-11-29 17:30:52 +08:00
no limit.
2017-02-11 17:39:52 +08:00
-d Disconnect each client after processing one activation request.
This is a direct violation of DCE RPC but may help if you
receive malicous fake RPC requests that block your threads or
forked processes. Some other KMS emulators (e.g. py-kms) behave
2015-11-29 17:30:52 +08:00
this way.
2017-02-11 17:39:52 +08:00
-k Do not disconnect clients after processing an activation
2015-11-29 17:30:52 +08:00
request. This selects the default behavior. -k is useful only if
you used an ini file (see vlmcsd.ini(5) and -i). If the ini file
contains the line "DisconnectClientsImmediately = true", you can
use this switch to restore the default behavior.
-N0 and -N1
2017-02-11 17:39:52 +08:00
Disables (-N0) or enables (-N1) the use of the NDR64 transfer
syntax in the RPC protocol. Unlike Microsoft vlmcsd supports
2015-11-29 17:30:52 +08:00
NDR64 on 32-bit operating systems. Microsoft introduced NDR64 in
2017-06-22 15:21:58 +08:00
Windows Vista but their KMS servers started using it with Win-
2017-02-11 17:39:52 +08:00
dows 8. Thus if you choose random ePIDs, vlmcsd will select
ePIDs with build numbers 9200 and 9600 if you enable NDR64 and
2015-11-29 17:30:52 +08:00
build numbers 6002 and 7601 if you disable NDR64. The default is
to enable NDR64.
-B0 and -B1
2017-02-11 17:39:52 +08:00
Disables (-B0) or enables (-B1) bind time feature negotiation
2017-06-22 15:21:58 +08:00
(BTFN) in the RPC protocol. All Windows operating systems start-
ing with Vista support BTFN and try to negotiate it when initi-
2015-11-29 17:30:52 +08:00
ating an RPC connection. Thus consider turning it off as a debug
2017-06-22 15:21:58 +08:00
/ troubleshooting feature only. Some older firewalls that selec-
2017-02-11 17:39:52 +08:00
tively block or redirect RPC traffic may get confused when they
2015-11-29 17:30:52 +08:00
detect NDR64 or BTFN.
-l filename
Use filename as a log file. The log file records all activations
2017-02-11 17:39:52 +08:00
with IP address, Windows workstation name (no reverse DNS
lookup), activated product, KMS protocol, time and date. If you
2015-11-29 17:30:52 +08:00
do not specify a log file, no log is created. For a live view of
the log file type tail -f file.
2017-02-11 17:39:52 +08:00
If you use the special filename "syslog", vlmcsd uses syslog(3)
for logging. If your system has no syslog service (/dev/log)
2017-06-22 15:21:58 +08:00
installed, logging output will go to /dev/console. Syslog log-
2017-02-11 17:39:52 +08:00
ging is not available in the native Windows version. The Cygwin
2015-11-29 17:30:52 +08:00
version does support syslog logging.
2016-08-02 22:39:39 +08:00
-T0 and -T1
2017-02-11 17:39:52 +08:00
Disable (-T0) or enable (-T1) the inclusion of date and time in
each line of the log. The default is -T1. -T0 is useful if you
2017-06-22 15:21:58 +08:00
log to stdout(3) which is redirected to another logging mecha-
2017-02-11 17:39:52 +08:00
nism that already includes date and time in its output, for
instance systemd-journald(8). If you log to syslog(3), -T1 is
ignored and date and time will never be included in the output
2016-08-02 22:39:39 +08:00
sent to syslog(3).
2017-02-11 17:39:52 +08:00
-D Normally vlmcsd daemonizes and runs in background (except the
native Windows version). If -D is specified, vlmcsd does not
2015-11-29 17:30:52 +08:00
daemonize and runs in foreground. This is useful for testing and
allows you to simply press <Ctrl-C> to exit vlmcsd.
2017-02-11 17:39:52 +08:00
The native Windows version never daemonizes and always behaves
2015-11-29 17:30:52 +08:00
as if -D had been specified. You may want to install vlmcsd as a
service instead. See -s.
-e If specified, vlmcsd ignores -l and writes all logging output to
2017-02-11 17:39:52 +08:00
stdout(3). This is mainly useful for testing and debugging and
2015-11-29 17:30:52 +08:00
often combined with -D.
2017-02-11 17:39:52 +08:00
-v Use verbose logging. Logs every parameter of the base request
and the base response. It also logs the HWID of the KMS server
if KMS protocol version 6 is used. This option is mainly for
2017-06-22 15:21:58 +08:00
debugging purposes. It only has an effect if some form of log-
2017-02-11 17:39:52 +08:00
ging is used. Thus -v does not make sense if not used with -l,
2015-11-29 17:30:52 +08:00
-e or -f.
2017-06-22 15:21:58 +08:00
-q Do not use verbose logging. This is actually the default behav-
2015-11-29 17:30:52 +08:00
ior. It only makes sense if you use vlmcsd with an ini file (see
2017-02-11 17:39:52 +08:00
-i and vlmcsd.ini(5)). If the ini file contains the line
2017-06-22 15:21:58 +08:00
"LogVerbose = true" you can use -q to restore the default behav-
2015-11-29 17:30:52 +08:00
ior.
-p filename
Create pid file filename. This has nothing to do with KMS ePIDs.
2017-02-11 17:39:52 +08:00
A pid file is a file where vlmcsd writes its own process id.
This is used by standard init scripts (typically found in
2015-11-29 17:30:52 +08:00
/etc/init.d). The default is not to write a pid file.
-u user and -g group
2017-02-11 17:39:52 +08:00
Causes vlmcsd to run in the specified user and group security
context. The main purpose for this is to drop root privileges
after it has been started from the root account. To use this
feature from cygwin you must run cyglsa-config and the account
from which vlmcsd is started must have the rights "Act as part
of the operating system" and "Replace a process level token".
2015-11-29 17:30:52 +08:00
The native Windows version does not support these options.
2017-02-11 17:39:52 +08:00
The actual security context switch is performed after the TCP
sockets have been created. This allows you to use privileged
2015-11-29 17:30:52 +08:00
ports (< 1024) when you start vlmcsd from the root account.
However if you use an ini, pid or log file, you must ensure that
2017-02-11 17:39:52 +08:00
the unprivileged user has access to these files. You can always
log to syslog(3) from an unprivileged account on most platforms
2015-11-29 17:30:52 +08:00
(see -l).
-w ePID
2017-02-11 17:39:52 +08:00
Use ePID as Windows ePID. If specified, -r is disregarded for
2015-11-29 17:30:52 +08:00
Windows.
-0 ePID
2017-02-11 17:39:52 +08:00
Use ePID as Office 2010 ePID (including Project and Visio). If
2015-11-29 17:30:52 +08:00
specified, -r is disregarded for Office 2010.
-3 ePID
2017-02-11 17:39:52 +08:00
Use ePID as Office 2013 ePID (including Project and Visio). If
2016-09-04 22:03:54 +08:00
specified, -r is disregarded for Office 2013.
-6 ePID
2017-02-11 17:39:52 +08:00
Use ePID as Office 2016 ePID (including Project and Visio). If
2016-09-04 22:03:54 +08:00
specified, -r is disregarded for Office 2016.
2015-11-29 17:30:52 +08:00
2017-06-22 15:21:58 +08:00
-G ePID
Use ePID as Windows China Government ePID. If specified, -r is
disregarded for Windows China Government Editions (Enterprise
G/GN).
2015-11-29 17:30:52 +08:00
-H HwId
2017-02-11 17:39:52 +08:00
Use HwId for all products. All HWIDs in the ini file (see -i)
2015-11-29 17:30:52 +08:00
will not be used. In an ini file you can specify a seperate HWID
2017-02-11 17:39:52 +08:00
for each application-guid. This is not possible when entering a
2015-11-29 17:30:52 +08:00
HWID from the command line.
2017-02-11 17:39:52 +08:00
HwId must be specified as 16 hex digits that are interpreted as
a series of 8 bytes (big endian). Any character that is not a
hex digit will be ignored. This is for better readability. The
2015-11-29 17:30:52 +08:00
following commands are identical:
vlmcsd -H 0123456789ABCDEF
vlmcsd -H 01:23:45:67:89:ab:cd:ef
vlmcsd -H "01 23 45 67 89 AB CD EF"
-i filename
2017-06-22 15:21:58 +08:00
Use configuration file (aka ini file) filename. Most configura-
2015-11-29 17:30:52 +08:00
tion parameters can be set either via the command line or an ini
2017-02-11 17:39:52 +08:00
file. The command line always has precedence over configuration
items in the ini file. See vlmcsd.ini(5) for the format of the
2015-11-29 17:30:52 +08:00
configuration file.
2017-02-11 17:39:52 +08:00
If vlmcsd has been compiled to use a default configuration file
(often /etc/vlmcsd.ini), you may use -i- to ignore the default
2015-11-29 17:30:52 +08:00
configuration file.
2016-12-02 15:56:18 +08:00
-j filename
2017-02-11 17:39:52 +08:00
Use KMS data file filename. By default vlmcsd only contains the
minimum product data that is required to perform all operations
2017-06-22 15:21:58 +08:00
correctly. You may use a more complete KMS data file that con-
2017-02-11 17:39:52 +08:00
tains all detailed product names. This is especially useful if
2016-12-02 15:56:18 +08:00
you are logging KMS requests. If you don't log, there is no need
to load an external KMS data file.
2017-02-11 17:39:52 +08:00
If vlmcsd has been compiled to use a default KMS data file, you
2016-12-02 15:56:18 +08:00
may use -j- to ignore the default configuration file.
2015-11-29 17:30:52 +08:00
-r0, -r1 (default) and -r2
These options determine how ePIDs are generated if
- you did not sprecify an ePID in the command line and
- you haven't used -i or
- the file specified by -i cannot be opened or
2017-02-11 17:39:52 +08:00
- the file specified by -i does not contain an ePID for the KMS
2016-09-04 22:03:54 +08:00
request
2015-11-29 17:30:52 +08:00
2017-02-11 17:39:52 +08:00
-r0 means there are no random ePIDs. vlmcsd simply issues
default ePIDs that are built into the binary at compile time.
Pro: behaves like real KMS server that also always issues the
same ePID. Con: Microsoft may start blacklisting again and the
2015-11-29 17:30:52 +08:00
default ePID may not work any longer.
2017-02-11 17:39:52 +08:00
-r1 instructs vlmcsd to generate random ePIDs when the program
2015-11-29 17:30:52 +08:00
starts or receives a SIGHUP signal and uses these ePIDs until it
2017-02-11 17:39:52 +08:00
is stopped or receives another SIGHUP. Most other KMS emulators
generate a new ePID on every KMS request. This is easily
2015-11-29 17:30:52 +08:00
detectable. Microsoft could just modify sppsvc.exe in a way that
2017-02-11 17:39:52 +08:00
it always sends two identical KMS requests in two RPC requests
but over the same TCP connection. If both KMS responses contain
the different ePIDs, the KMS server is not genuine. -r1 is the
default mode. -r1 also ensures that all three ePIDs (Windows,
Office 2010 and Office 2013) use the same OS build number and
2015-11-29 17:30:52 +08:00
LCID (language id).
If vlmcsd has been started by an internet superserver, -r1 works
2016-09-04 22:03:54 +08:00
almost identically to -r2. The only exception occurs if you send
2017-02-11 17:39:52 +08:00
more than one activation request over the same TCP connection.
This is simply due to the fact that vlmcsd is started upon a
2016-09-04 22:03:54 +08:00
connection request and does not stay in memory after servicing a
2017-06-22 15:21:58 +08:00
KMS request. Consider using -r0 or -w, -G, -0, -3 and -6 when
starting vlmcsd by an internet superserver.
2015-11-29 17:30:52 +08:00
2017-02-11 17:39:52 +08:00
-r2 behaves like most other KMS server emulators with random
support and generates a new random ePID on every request. -r2
should be treated as debugging option only because it allows
2016-09-04 22:03:54 +08:00
very easy emulator detection.
2015-11-29 17:30:52 +08:00
-C LCID
2017-02-11 17:39:52 +08:00
Do not randomize the locale id part of the ePID and use LCID
instead. The LCID must be specified as a decimal number, e.g.
1049 for "Russian - Russia". This option has no effect if the
ePID is not randomized at all, e.g. if it is selected from the
2015-11-29 17:30:52 +08:00
command line or an ini file.
By default vlmcsd generates a valid locale id that is recognized
2017-02-11 17:39:52 +08:00
by .NET Framework 4.0. This may lead to a locale id which is
2015-11-29 17:30:52 +08:00
unlikely to occur in your country, for instance 2155 for "Quecha
- Ecuador". You may want to select the locale id of your country
2017-06-22 15:21:58 +08:00
instead. See MSDN <http://msdn.microsoft.com/en-us/goglobal/
bb964664.aspx> for a list of valid LCIDs. Please note that some
2015-11-29 17:30:52 +08:00
of them are not recognized by .NET Framework 4.0.
2017-02-11 17:39:52 +08:00
Most other KMS emulators use a fixed LCID of 1033 (English -
2015-11-29 17:30:52 +08:00
US). To achive the same behavior in vlmcsd use -C 1033.
2016-10-24 21:32:24 +08:00
-K0, -K1, -K2 and -K3
2017-02-11 17:39:52 +08:00
Sets the whitelisting level to determine which products vlmcsd
2016-10-24 21:32:24 +08:00
activates or refuses. The default is -K0.
2017-02-11 17:39:52 +08:00
-K0: activate all products with an unknown, retail or
2016-10-24 21:32:24 +08:00
beta/preview KMS ID.
-K1: activate products with a retail or beta/preview KMS ID
but refuse to activate products with an unknown KMS ID.
2017-02-11 17:39:52 +08:00
-K2: activate products with an unknown KMS ID but refuse
2016-10-24 21:32:24 +08:00
products with a retail or beta/preview KMS ID.
-K3: activate only products with a known volume license RTM
KMS ID and refuse all others.
2017-02-11 17:39:52 +08:00
The SKU ID is not checked. Like a genuine KMS server vlmcsd
activates a product that has a random or unknown SKU ID. If you
select -K1 or -K3, vlmcsd also checks the Application ID for
correctness. If Microsoft introduces a new KMS ID for a new
product, you cannot activate it if you used -K1 or -K3 until a
2016-10-24 21:32:24 +08:00
new version of vlmcsd is available.
-c0 and -c1
2017-02-11 17:39:52 +08:00
-c1 causes vlmcsd to check if the client time differs no more
2016-10-24 21:32:24 +08:00
than four hours from the system time. -c0 (the default) disables
2017-02-11 17:39:52 +08:00
this check. -c1 is useful to prevent emulator detection. A
client that tries to detect an emulator could simply send two
subsequent request with two time stamps that differ more than
2016-10-24 21:32:24 +08:00
four hours from each other. If both requests succeed, the server
2017-02-11 17:39:52 +08:00
is an emulator. If you specify -c1 on a system with no reliable
time source, activations will fail. It is ok to set the correct
2016-10-24 21:32:24 +08:00
system time after you started vlmcsd.
2016-10-31 20:59:15 +08:00
-M0 and -M1
2017-02-11 17:39:52 +08:00
Disables (-M0) or enables (-M1) maintaining a list of client
2017-06-22 15:21:58 +08:00
machine IDs (CMIDs). The default is -M0. -M1 is useful to pre-
2017-02-11 17:39:52 +08:00
vent emulator detection. By maintaing a CMID list, vlmcsd
2017-06-22 15:21:58 +08:00
reports current active clients exactly like a genuine KMS emula-
2017-02-11 17:39:52 +08:00
tor. This includes bug compatibility to the extent that you can
2017-06-22 15:21:58 +08:00
permanently kill a genuine KMS emulator by sending an "over-
2017-02-11 17:39:52 +08:00
charge request" with a required client count of 376 or more and
then request activation for 671 clients. vlmcsd can be reset
from this condition by restarting it. If -M0 is used, vlmcsd
2016-10-31 20:59:15 +08:00
reports current active clients as good as possible. If no client
2017-06-22 15:21:58 +08:00
sends an "overcharge request", it is not possible to detect vlm-
2017-02-11 17:39:52 +08:00
csd as an emulator with -M0. -M1 requires the allocation of a
buffer that is about 50 kB in size. On hardware with few memory
2016-10-31 20:59:15 +08:00
resources use it only if you really need it.
2017-02-11 17:39:52 +08:00
If you start vlmcsd from an internet superserver, -M1 cannot be
2017-06-22 15:21:58 +08:00
used. Since vlmcsd exits after each activation, it cannot main-
2016-10-31 20:59:15 +08:00
tain any state in memory.
-E0 and -E1
These options are ignored if you do not also specify -M1. If you
use -E0 (the default), vlmcsd starts up as a fully "charged" KMS
2017-06-22 15:21:58 +08:00
server. Clients activate immediately. -E1 lets you start up vlm-
2017-02-11 17:39:52 +08:00
csd with an empty CMID list. Activation will start when the
required minimum clients (25 for Windows Client OSses, 5 for
Windows Server OSses and Office) have registered with the KMS
server. As long as the minimum client count has not been
2016-10-31 20:59:15 +08:00
reached, clients end up in HRESULT 0xC004F038 "The count
2017-02-11 17:39:52 +08:00
reported by your Key Management Service (KMS) is insufficient.
Please contact your system administrator". You may use vlmcs(1)
or another KMS client emulator to "charge" vlmcsd. -E1 does not
improve emulator detection prevention. It's primary purpose is
to help developers of KMS clients to test "charging" a KMS
2016-10-31 20:59:15 +08:00
server.
2015-11-29 17:30:52 +08:00
-R renewal-interval
2017-02-11 17:39:52 +08:00
Instructs clients to renew activation every renewal-interval.
2015-11-29 17:30:52 +08:00
The renewal-interval is a number optionally immediately followed
2017-06-22 15:21:58 +08:00
by a letter indicating the unit. Valid unit letters are s (sec-
2015-11-29 17:30:52 +08:00
onds), m (minutes), h (hours), d (days) and w (weeks). If you do
not specify a letter, minutes is assumed.
2017-02-11 17:39:52 +08:00
-R3d for instance instructs clients to renew activation every 3
2015-11-29 17:30:52 +08:00
days. The default renewal-interval is 10080 (identical to 7d and
1w).
Due to poor implementation of Microsofts KMS Client it cannot be
guaranteed that activation is renewed on time as specfied by the
2017-02-11 17:39:52 +08:00
-R option. Don't care about that. Renewal will happen well
2015-11-29 17:30:52 +08:00
before your activation expires (usually 180 days).
2017-02-11 17:39:52 +08:00
Even though you can specify seconds, the granularity of this
2017-06-22 15:21:58 +08:00
option is 1 minute. Seconds are rounded down to the next multi-
2015-11-29 17:30:52 +08:00
ple of 60.
-A activation-interval
2017-02-11 17:39:52 +08:00
Instructs clients to retry activation every activation-interval
if it was unsuccessful, e.g. because it could not reach the
2017-06-22 15:21:58 +08:00
server. The default is 120 (identical to 2h). activation-inter-
2017-02-11 17:39:52 +08:00
val follows the same syntax as renewal-interval in the -R
2015-11-29 17:30:52 +08:00
option.
2017-02-11 17:39:52 +08:00
-s Installs vlmcsd as a Windows service. This option only works
with the native Windows version and Cygwin. Combine -s with
other command line options. These will be in effect when you
start the service. The service automatically starts when you
2017-06-22 15:21:58 +08:00
reboot your machine. To start it manually, type "net start vlm-
2015-11-29 17:30:52 +08:00
csd".
2017-02-11 17:39:52 +08:00
If you use Cygwin, you must include your Cygwin system DLL
directory (usually C:\Cygwin\bin or C:\Cygwin64\bin) into the
2015-11-29 17:30:52 +08:00
PATH environment variable or the service will not start.
2017-02-11 17:39:52 +08:00
You can reinstall the service anytime using vlmcsd -s again,
e.g. with a different command line. If the service is running,
2015-11-29 17:30:52 +08:00
it will be restarted with the new command line.
2017-02-11 17:39:52 +08:00
When using -s the command line is checked for basic syntax
2015-11-29 17:30:52 +08:00
errors only. For example "vlmcsd -s -L 1.2.3.4" reports no error
2017-02-11 17:39:52 +08:00
but the service will not start if 1.2.3.4 is not an IP address
2015-11-29 17:30:52 +08:00
on your system.
2017-06-22 15:21:58 +08:00
-S Uninstalls the vlmcsd service. Works only with the native Win-
2017-02-11 17:39:52 +08:00
dows version and Cygwin. All other options will be ignored if
2015-11-29 17:30:52 +08:00
you include -S in the command line.
-U [domain\]username
2017-06-22 15:21:58 +08:00
Can only be used together with -s. Starts the service as a dif-
2017-02-11 17:39:52 +08:00
ferent user than the local SYSTEM account. This is used to run
the service under an account with low privileges. If you omit
2015-11-29 17:30:52 +08:00
the domain, an account from the local computer will be used.
You may use "NT AUTHORITY\NetworkService". This is a pseudo user
2017-06-22 15:21:58 +08:00
with low privileges. You may also use "NT AUTHORITY\LocalSer-
vice" which has more privileges but these are of no use for run-
2015-11-29 17:30:52 +08:00
ning vlmcsd.
2017-06-22 15:21:58 +08:00
Make sure that the user you specify has at least execute permis-
2015-11-29 17:30:52 +08:00
sion for your executable. "NT AUTHORITY\NetworkService" normally
has no permission to run binaries from your home directory.
2017-02-11 17:39:52 +08:00
For your convenience you can use the special username "/l" as a
2015-11-29 17:30:52 +08:00
shortcut for "NT AUTHORITY\LocalService" and "/n" for "NT
2017-06-22 15:21:58 +08:00
AUTHORITY\NetworkService". "vlmcsd -s -U /n" installs the ser-
2015-11-29 17:30:52 +08:00
vice to run as "NT AUTHORITY\NetworkService".
-W password
2017-02-11 17:39:52 +08:00
Can only be used together with -s. Specifies a password for the
2017-06-22 15:21:58 +08:00
corresponding username you use with -U. SYSTEM, "NT AUTHOR-
2017-02-11 17:39:52 +08:00
ITY\NetworkService", "NT AUTHORITY\LocalService" do not require
2015-11-29 17:30:52 +08:00
a password.
2017-02-11 17:39:52 +08:00
If you specify a user with even lower privileges than "NT
AUTHORITY\NetworkService", you must specify its password. You
2015-11-29 17:30:52 +08:00
also have to grant the "Log on as a service" right to that user.
SIGNALS
The following signals differ from the default behavior:
SIGTERM, SIGINT
2017-06-22 15:21:58 +08:00
These signals cause vlmcsd to exit gracefully. All global sema-
2017-02-11 17:39:52 +08:00
phores and shared memory pages will be released, the pid file
will be unlinked (deleted) and a shutdown message will be
2015-11-29 17:30:52 +08:00
logged.
2017-02-11 17:39:52 +08:00
SIGHUP Causes vlmcsd to be restarted completely. This is useful if you
started vlmcsd with an ini file. You can modify the ini file
while vlmcsd is running and then sending SIGHUP, e.g. by typing
2017-06-22 15:21:58 +08:00
"killall -SIGHUP vlmcsd" or "kill -SIGHUP `cat /var/run/vlm-
2015-11-29 17:30:52 +08:00
csd.pid`".
The SIGHUP handler has been implemented relatively simple. It is
2017-02-11 17:39:52 +08:00
virtually the same as stopping vlmcsd and starting it again
2015-11-29 17:30:52 +08:00
immediately with the following exceptions:
2017-06-22 15:21:58 +08:00
-- The new process does not get a new process id.
2015-11-29 17:30:52 +08:00
2017-06-22 15:21:58 +08:00
-- If you used a pid file, it is not deleted and recreated
2015-11-29 17:30:52 +08:00
because the process id stays the same.
2017-06-22 15:21:58 +08:00
-- If you used the 'user' and/or 'group' directive in an ini
2017-02-11 17:39:52 +08:00
file these are ignored. This is because once you switched to
2017-06-22 15:21:58 +08:00
lower privileged users and groups, there is no way back. Any-
2015-11-29 17:30:52 +08:00
thing else would be a severe security flaw in the OS.
2017-02-11 17:39:52 +08:00
Signaling is not available in the native Windows version and in the
2017-06-22 15:21:58 +08:00
Cygwin version when vlmcsd runs as a Windows service.
2015-11-29 17:30:52 +08:00
SUPPORTED OPERATING SYSTEMS
2017-02-11 17:39:52 +08:00
vlmcsd compiles and runs on Linux, Windows (no Cygwin required but
explicitly supported), Mac OS X, FreeBSD, NetBSD, OpenBSD, Dragonfly
BSD, Minix, Solaris, OpenIndiana, Android and iOS. Other POSIX or
unixoid OSses may work with unmodified sources or may require minor
2016-04-11 12:49:47 +08:00
porting efforts.
2015-11-29 17:30:52 +08:00
SUPPORTED PRODUCTS
2017-06-22 15:21:58 +08:00
vlmcsd can answer activation requests for the following products: Win-
dows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10 (up to 1703),
Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Win-
2017-02-11 17:39:52 +08:00
dows Server 2012 R2, Windows Server 2016, Office 2010, Project 2010,
2016-08-15 18:35:59 +08:00
Visio 2010, Office 2013, Project 2013, Visio 2013, Office 2016, Project
2017-06-22 15:21:58 +08:00
2016, Visio 2016. Newer products may work as long as the KMS protocol
2017-02-11 17:39:52 +08:00
does not change. A complete list of fully supported products can be
2016-08-15 18:35:59 +08:00
obtained using the -x option of vlmcs(1).
2015-11-29 17:30:52 +08:00
Office, Project and Visio must be volume license versions.
FILES
vlmcsd.ini(5)
EXAMPLES
2016-08-02 22:39:39 +08:00
vlmcsd -De
2017-02-11 17:39:52 +08:00
Starts vlmcsd in foreground. Useful if you use it for the first
time and want to see what's happening when a client requests
2015-11-29 17:30:52 +08:00
activation.
vlmcsd -l /var/log/vlmcsd.log
2017-06-22 15:21:58 +08:00
Starts vlmcsd as a daemon and logs everything to /var/log/vlm-
2015-11-29 17:30:52 +08:00
csd.log.
vlmcsd -L 192.168.1.17
Starts vlmcsd as a daemon and listens on IP address 192.168.1.17
2017-06-22 15:21:58 +08:00
only. This is useful for routers that have a public and a pri-
2015-11-29 17:30:52 +08:00
vate IP address to prevent your KMS server from becoming public.
vlmcsd -s -U /n -l C:\logs\vlmcsd.log
2017-02-11 17:39:52 +08:00
Installs vlmcsd as a Windows service with low privileges and
2015-11-29 17:30:52 +08:00
logs everything to C:\logs\vlmcsd.log when the service is
started with "net start vlmcsd".
BUGS
An ePID specified in an ini file must not contain spaces.
2016-08-15 18:35:59 +08:00
2015-11-29 17:30:52 +08:00
AUTHOR
2017-02-11 17:39:52 +08:00
Written by crony12, Hotbird64 and vityan666. With contributions from
2015-11-29 17:30:52 +08:00
DougQaid.
CREDITS
2017-06-22 15:21:58 +08:00
Thanks to CODYQX4, deagles, eIcn, mikmik38, nosferati87, qad, Rati-
2015-11-29 17:30:52 +08:00
borus, ...
SEE ALSO
vlmcsd.ini(5), vlmcsd(7), vlmcs(1), vlmcsdmulti(1)
2017-06-22 15:21:58 +08:00
Hotbird64 June 2017 VLMCSD(8)