Emergency server help: get in touch

“cPanel license is invalid”: troubleshooting manage2, IP changes and firewalls

What to check when WHM shows a licence error, including the licence server verification tool, IP mismatches after a migration, NAT and firewall blocks on the licence check, expired trials and stale manage2 entries, with the exact commands to confirm each cause.

Published Updated 6 min read

A licence error takes cPanel and WHM offline for logins while the underlying sites keep running, so it usually arrives as a customer complaint rather than a monitoring alert. The message is generic, but the cause is one of a small number of things: the licence server cannot see this IP as licensed, the server cannot reach the licence server, or the local licence file is stale. Work through the checks below in order; most cases are resolved in the first two.

Short answer: Check the IP on cPanel’s public licence verification page, then run /usr/local/cpanel/cpkeyclt --verbose on the server and read the response line. If the licence server says the IP is unlicensed, fix it in manage2 or with your distributor; if the server cannot reach auth.cpanel.net on port 2089, open the port in CSF TCP_OUT or the provider firewall; if both are fine, delete /usr/local/cpanel/cpanel.lisc, run cpkeyclt again and restart cpsrvd.

Confirm what the licence server thinks

Before touching the server, check the public verification page from any browser: the cPanel licence verification tool accepts an IP and tells you whether it is licensed, for which product, and through which distributor. If the IP shows as unlicensed, the problem is on the account side (manage2 or your provider’s billing), not the server. If it shows as licensed, the problem is on the server or the network path.

From the server itself, run the licence update in verbose mode:

/usr/local/cpanel/cpkeyclt --verbose

The output tells you which IP it presented, which licence host it contacted, and the response. The response text is the single most useful line in this whole process, so read it before assuming anything.

IP address changed or does not match

The licence is bound to the IP the server uses to reach the licence servers, which is normally the main shared IP in WHM. Common ways this goes wrong:

  • The server was migrated or re-addressed and the licence was not moved in manage2.
  • The provider changed the main IP, or a new interface came up first and the outbound route now uses a different address.
  • The server sits behind NAT and the outbound public IP differs from the WHM main IP.

Check what the outside world sees and what WHM thinks:

curl -s https://myip.cpanel.net/v1.0/
cat /var/cpanel/mainip
ip route get 1.1.1.1

All three should agree. If the outbound address differs from mainip, either add a source-route so licence traffic leaves from the licensed IP, or update the licence to the new address. On NAT installs, the licence must be issued to the public NAT address, and /var/cpanel/cpnat must map the private main IP to it; run /scripts/build_cpnat after network changes.

The server cannot reach the licence servers

The licence check is an outbound HTTPS request to the cPanel licence hosts on port 2089 and 443. Anything that blocks it produces an “unable to contact” message in cpkeyclt --verbose output. Test connectivity directly:

curl -sv https://auth.cpanel.net:2089/ 2>&1 | grep -E 'Connected|refused|timed out'

If that hangs or is refused, look at:

  • CSF outbound rules: port 2089 must be in TCP_OUT. Check with grep ^TCP_OUT /etc/csf/csf.conf. If you moved to the cPanel CSF fork or another fork recently, confirm the port list survived the migration.
  • Provider firewalls or security groups that allow only 80 and 443 outbound.
  • DNS: dig +short auth.cpanel.net must resolve. A resolver that only answers for internal zones after a network change is a classic cause.
  • Proxy or egress filtering in corporate environments; cpkeyclt does not honour https_proxy.

Once the path is open, run /usr/local/cpanel/cpkeyclt again and the licence file at /usr/local/cpanel/cpanel.lisc is refreshed within seconds.

Trial expired or licence cancelled

Trial licences last 15 days and cannot be renewed on the same IP. Licences bought through a hosting provider or reseller are tied to their manage2 account; if their invoice lapsed, your licence goes with it. In this case cpkeyclt succeeds in contacting the server but returns a message saying the IP is not licensed. The fix is administrative: contact the distributor named on the verification page, or in manage2 check the licence list for that IP and its expiry.

Note that the licence type must match the account count. A Solo licence on a server with two accounts, or an Admin licence (5 accounts) with six, will validate and then refuse account creation rather than showing a licence error, but it is easy to confuse the two.

Stale local licence file

If the licence server and the network are both fine but WHM still complains, the local file may be corrupt or from a previous IP. Force a full refresh:

rm -f /usr/local/cpanel/cpanel.lisc
/usr/local/cpanel/cpkeyclt
/scripts/restartsrv_cpsrvd

A common pitfall after a migration with the WHM Transfer Tool or an in-place OS upgrade is copying the old server’s cpanel.lisc along with the rest of /usr/local/cpanel. The file is per-IP and must be regenerated on the new host.

Update tier and version lockouts

Occasionally the error is not really a licence problem. A server running a cPanel version far past its tier’s end of life, or one on an operating system that the current licence type no longer supports, can show licence-related errors during upcp. Check /var/cpanel/updatelogs/last and whmapi1 version. If the message references an unsupported version or OS, see our upcp failure guide rather than chasing the licence.

Verify

A working licence shows in three places: /usr/local/cpanel/cpkeyclt --verbose ends with a success line, WHM » Home loads without the banner, and whmapi1 licenseinfo (or the licence panel under WHM » Server Configuration » Update Preferences) shows the expected product and account limit. Finally, check /var/log/messages and /usr/local/cpanel/logs/license_log for repeated update failures during the past days; the licence check runs periodically, and a pattern of intermittent failures usually points to a flaky firewall rule or resolver that will bite again.

CPanel license is invalid at a glance

“cPanel license is invalid” summary card: Check the IP on cPanel's public licence verification page, then run /usr/local/cpanel/cpkeyclt --verbose on the server…
In short: Check the IP on cPanel’s public licence verification page, then run /usr/local/cpanel/cpkeyclt –verbose on the server and read the response line.

Official documentation: cPanel & WHM documentation, Linux man pages.

Related guides: cPanel 2026 pricing and licensing explained: Solo, Admin, Pro, Premier and WP Squared · Account quotas show “unlimited”: fixquotas and XFS/ext4 quota repair on cPanel · Disk full on a cPanel server: cleaning /var/log, /backup, mail queues and cPanel caches.

Frequently asked questions

Does a cPanel licence error take customer websites offline?

No. Only cPanel and WHM logins are blocked; Apache, mail, DNS and databases keep running, which is why the error usually surfaces as a customer complaint rather than a monitoring alert.

How long does a licence change in manage2 take to reach the server?

Almost no time. Once the IP is licensed, running /usr/local/cpanel/cpkeyclt refreshes the local licence file within seconds; without a manual run the periodic check picks it up within a few hours.

Can I use a cPanel licence behind NAT or on a private IP?

Yes. The licence must be issued to the public NAT address and /var/cpanel/cpnat must map the private main IP to it; run /scripts/build_cpnat after any network change so the mapping is current.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.