Automating BIG-IP Licensing Through iControl REST and the F5 Activation Service

Licensing a newly deployed BIG-IP normally requires interactive GUI steps or BIG-IQ. This Python utility automates direct licensing through BIG-IP iControl REST and the public F5 Activation Service without requiring BIG-IQ. It generates the hardware dossier, obtains the EULA, requires explicit operator acceptance, receives the signed license, applies it, reloads licensing, and verifies the result. This workflow follows the licensing sequence documented in F5 K000161807.

How to use this snippet

  • Use a BIG-IP running TMOS 12.0 or later with iControl REST enabled.
  • Provide a valid F5 registration key and BIG-IP administrative credentials.
  • Run the utility from a workstation that can reach the BIG-IP management interface and activate.f5.com over HTTPS.
  • Clone the repository and install the Python dependencies.
  • Run dossier-only mode first when validating connectivity or troubleshooting.
  • Confirm that the registration key is intended for the target BIG-IP.
  • Review and explicitly accept the EULA before the license is applied.

The Code

macOS/Linux

git clone https://github.com/vishnushri19/LicenseAutomation.git
cd LicenseAutomation

make setup

export BIGIP_HOST="10.10.10.10"
export BIGIP_USER="admin"
export F5_REGISTRATION_KEY="REGISTRATION-KEY"

# Generate a dossier only; no license change
make dossier

# Retrieve the EULA, request confirmation, activate, apply, and verify
make activate

Windows PowerShell

git clone https://github.com/vishnushri19/LicenseAutomation.git
cd LicenseAutomation

py -m venv .venv
.\.venv\Scripts\Activate.ps1

python -m pip install --upgrade pip
pip install -r requirements.txt

$env:BIGIP_HOST = "10.10.10.10"
$env:BIGIP_USER = "admin"
$env:F5_REGISTRATION_KEY = "REGISTRATION-KEY"

# Generate a dossier only; no license change
python scripts\license_bigip.py

# Retrieve the EULA, request confirmation, activate, apply, and verify
python scripts\license_bigip.py --activate

The password is requested interactively. For controlled non-interactive execution:

export BIGIP_PASS=“your-password”

PowerShell:

$env:BIGIP_PASS = “your-password”

Do not commit passwords, registration keys, dossiers, or license text.

The complete implementation is maintained in the GitHub repository:

The workflow uses iControl REST for BIG-IP authentication, dossier generation, license transfer, reloadlic execution, and verification. It uses SOAP for communication with the public F5 Activation Service.

The public SOAP operations are getEULA and activate . The signed license is base64-encoded in memory before being transferred to /config/bigip.license , avoiding shell-quoting problems.

Tested this on version

BIG-IP TMOS 17.5.1.9

2 Likes