# “cPanel license is invalid”: troubleshooting manage2, IP changes and firewalls

Source: https://srvscripts.com/guides/cpanel-license-is-invalid/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A licence error takes cPanel and WHM offline for logins while the underlying sites keep running, so it usually arrives as a customer complaint rather than a monitoring alert. The message is generic, but the cause is one of a small number of things: the licence server cannot see this IP as licensed, the server cannot reach the licence server, or the local licence file is stale. Work through the checks below in order; most cases are resolved in the first two.

In short: Check the IP on cPanel’s public licence verification page, then run /usr/local/cpanel/cpkeyclt –verbose on the server and read the response line.

**Short answer:** Check the IP on cPanel’s public licence verification page, then run `/usr/local/cpanel/cpkeyclt --verbose` on the server and read the response line. If the licence server says the IP is unlicensed, fix it in manage2 or with your distributor; if the server cannot reach `auth.cpanel.net` on port 2089, open the port in CSF `TCP_OUT` or the provider firewall; if both are fine, delete `/usr/local/cpanel/cpanel.lisc`, run `cpkeyclt` again and restart cpsrvd.

## Confirm what the licence server thinks

Before touching the server, check the public verification page from any browser: the cPanel licence verification tool accepts an IP and tells you whether it is licensed, for which product, and through which distributor. If the IP shows as unlicensed, the problem is on the account side (manage2 or your provider’s billing), not the server. If it shows as licensed, the problem is on the server or the network path.

From the server itself, run the licence update in verbose mode:

```
/usr/local/cpanel/cpkeyclt --verbose
```

The output tells you which IP it presented, which licence host it contacted, and the response. The response text is the single most useful line in this whole process, so read it before assuming anything.

## IP address changed or does not match

The licence is bound to the IP the server uses to reach the licence servers, which is normally the main shared IP in WHM. Common ways this goes wrong:

- The server was migrated or re-addressed and the licence was not moved in manage2.

- The provider changed the main IP, or a new interface came up first and the outbound route now uses a different address.

- The server sits behind NAT and the outbound public IP differs from the WHM main IP.

Check what the outside world sees and what WHM thinks:

```
curl -s https://myip.cpanel.net/v1.0/
cat /var/cpanel/mainip
ip route get 1.1.1.1
```

All three should agree. If the outbound address differs from `mainip`, either add a source-route so licence traffic leaves from the licensed IP, or update the licence to the new address. On NAT installs, the licence must be issued to the public NAT address, and `/var/cpanel/cpnat` must map the private main IP to it; run `/scripts/build_cpnat` after network changes.

## The server cannot reach the licence servers

The licence check is an outbound HTTPS request to the cPanel licence hosts on port 2089 and 443. Anything that blocks it produces an “unable to contact” message in `cpkeyclt --verbose` output. Test connectivity directly:

```
curl -sv https://auth.cpanel.net:2089/ 2>&1 | grep -E 'Connected|refused|timed out'
```

If that hangs or is refused, look at:

- **CSF outbound rules**: port 2089 must be in `TCP_OUT`. Check with `grep ^TCP_OUT /etc/csf/csf.conf`. If you moved to the cPanel CSF fork or another fork recently, confirm the port list survived the migration.

- **Provider firewalls or security groups** that allow only 80 and 443 outbound.

- **DNS**: `dig +short auth.cpanel.net` must resolve. A resolver that only answers for internal zones after a network change is a classic cause.

- **Proxy or egress filtering** in corporate environments; `cpkeyclt` does not honour `https_proxy`.

Once the path is open, run `/usr/local/cpanel/cpkeyclt` again and the licence file at `/usr/local/cpanel/cpanel.lisc` is refreshed within seconds.

## Trial expired or licence cancelled

Trial licences last 15 days and cannot be renewed on the same IP. Licences bought through a hosting provider or reseller are tied to their manage2 account; if their invoice lapsed, your licence goes with it. In this case `cpkeyclt` succeeds in contacting the server but returns a message saying the IP is not licensed. The fix is administrative: contact the distributor named on the verification page, or in manage2 check the licence list for that IP and its expiry.

Note that the licence type must match the account count. A Solo licence on a server with two accounts, or an Admin licence (5 accounts) with six, will validate and then refuse account creation rather than showing a licence error, but it is easy to confuse the two.

## Stale local licence file

If the licence server and the network are both fine but WHM still complains, the local file may be corrupt or from a previous IP. Force a full refresh:

```
rm -f /usr/local/cpanel/cpanel.lisc
/usr/local/cpanel/cpkeyclt
/scripts/restartsrv_cpsrvd
```

A common pitfall after a migration with the [WHM Transfer Tool](/guides/whm-transfer-tool/) or an in-place OS upgrade is copying the old server’s `cpanel.lisc` along with the rest of `/usr/local/cpanel`. The file is per-IP and must be regenerated on the new host.

## Update tier and version lockouts

Occasionally the error is not really a licence problem. A server running a cPanel version far past its tier’s end of life, or one on an operating system that the current licence type no longer supports, can show licence-related errors during `upcp`. Check `/var/cpanel/updatelogs/last` and `whmapi1 version`. If the message references an unsupported version or OS, see our [upcp failure guide](/guides/cpanel-upcp-failed-upgrade-blocked/) rather than chasing the licence.

## Verify

A working licence shows in three places: `/usr/local/cpanel/cpkeyclt --verbose` ends with a success line, WHM » Home loads without the banner, and `whmapi1 licenseinfo` (or the licence panel under **WHM » Server Configuration » Update Preferences**) shows the expected product and account limit. Finally, check `/var/log/messages` and `/usr/local/cpanel/logs/license_log` for repeated update failures during the past days; the licence check runs periodically, and a pattern of intermittent failures usually points to a flaky firewall rule or resolver that will bite again.

## CPanel license is invalid at a glance

**Official documentation:** [cPanel & WHM documentation](https://docs.cpanel.net/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [cPanel 2026 pricing and licensing explained: Solo, Admin, Pro, Premier and WP Squared](https://srvscripts.com/guides/cpanel-pricing-2026-licensing/) · [Account quotas show “unlimited”: fixquotas and XFS/ext4 quota repair on cPanel](https://srvscripts.com/guides/cpanel-quotas-unlimited-fixquotas/) · [Disk full on a cPanel server: cleaning /var/log, /backup, mail queues and cPanel caches](https://srvscripts.com/guides/cpanel-disk-full-cleanup/).

## Frequently asked questions

### Does a cPanel licence error take customer websites offline?

No. Only cPanel and WHM logins are blocked; Apache, mail, DNS and databases keep running, which is why the error usually surfaces as a customer complaint rather than a monitoring alert.

### How long does a licence change in manage2 take to reach the server?

Almost no time. Once the IP is licensed, running `/usr/local/cpanel/cpkeyclt` refreshes the local licence file within seconds; without a manual run the periodic check picks it up within a few hours.

### Can I use a cPanel licence behind NAT or on a private IP?

Yes. The licence must be issued to the public NAT address and `/var/cpanel/cpnat` must map the private main IP to it; run `/scripts/build_cpnat` after any network change so the mapping is current.
