Changes for page sql-tde
Last modified by Nikhil Singh on 2026/07/03 08:32
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
-
Attachments (0 modified, 1 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,19 +1,33 @@ 1 -= TDE(backup from smsstoazure)=1 += **1. Steps for Implementing Transparent Data Encryption (TDE) FROM SQL Server** = 2 2 3 3 4 - 1Createmasterkey inmaster database(setmasterkey)4 +This document outlines the process of **encrypting SQL Server databases** using **Transparent Data Encryption (TDE)** and backing them up to **Azure Storage**. TDE ensures data at rest is encrypted, leveraging a **Master Key (MK)**, **TDE Certificate**, and **Database Encryption Key (DEK)** for encryption. 5 5 6 - 2CreateTDEcertificate(encrypted byMK)6 +The process also includes creating a **credential** for secure backup to **Azure Blob Storage**, providing a scalable and secure solution for storing encrypted databases in the cloud. 7 7 8 -3 Backup the Certificate and private key, By encryption with a password ( did not do it in this case due to storage blog problems) 9 9 10 - 4 Choose DB to create the DEK ,Create database encryption key (DEK) withalgorithm( AES= 256)andencryptionby certificate9 +[[image:image-20250305152543-1.png]] 11 11 12 -5 Set encryption on for the database 13 13 12 +**~1. Create a Master Key in the master Database** 13 +The first step is to create a **Master Key** in the master database. This key will be used to encrypt other cryptographic objects, such as certificates and symmetric keys, within SQL Server. 14 14 15 -6 Create credential with SAS token 16 16 16 +**2. Create a TDE Certificate (Encrypted by the Master Key)** 17 +Next, generate a **TDE certificate** that will be used to encrypt the **Database Encryption Key (DEK)**. This certificate is encrypted by the **Master Key** created in step 1, providing an additional layer of security. 18 + 19 + 20 +**3. Choose the Database to Create the Database Encryption Key (DEK)** 21 +For the selected database, create the **Database Encryption Key (DEK)**. The DEK will be encrypted by the **TDE certificate** and will use the **AES-256 encryption algorithm** to ensure data is securely encrypted at rest. 22 + 23 + 24 +**4. Enable Encryption for the Database** 25 +Once the **DEK** has been created, enable **TDE** for the database. This ensures that all data written to the database is automatically encrypted at rest, providing full protection for sensitive information. 26 + 27 + 28 +**5. Create a Credential with a SAS Token** 29 +Finally, create a **credential** that allows SQL Server to access Azure Blob Storage. This credential is created using a **Shared Access Signature (SAS) token**, which ensures secure and authenticated access to the storage account for backup purposes. 30 + 17 17 {{code language="sql"}} 18 18 drop credential [https://zagpebslab.blob.core.windows.net/sql-backups] 19 19 CREATE CREDENTIAL [https://zagpebslab.blob.core.windows.net/sql-backups] ... ... @@ -24,95 +24,106 @@ 24 24 {{/code}} 25 25 26 26 27 - 741 +**~ 6. Use a Stored Procedure to Back Up to Azure Storage Account** 28 28 29 29 {{code language="sql"}} 30 30 EXECUTE dba.dbo.DatabaseBackup 31 - @Databases =@DatabaseName,32 - @URL =@BackupContainerURL,33 - @BackupType = 'Full',34 - @CopyOnly = 'Y',35 - @Compress = 'Y',36 - @Verify = 'N';45 +@Databases = 'dba', 46 +@URL = 'https://zagpebslab.blob.core.windows.net/sql-backups', 47 +@BackupType = 'Full', 48 +@CopyOnly = 'Y', 49 +@Compress = 'Y', 50 +@Verify = 'N' 37 37 {{/code}} 38 38 39 - Thebackupwas unable to be done from smss to azure ( the MI does not support encrypted DBs to be backed up from smss to azure)53 +=== === 40 40 41 - Wehave unencrypted a database andbacked itupfrom ssmstoazureblobsuccessfully55 +=== Conclusion: Backup to Azure Storage Account with TDE Encrypted Databases === 42 42 57 +The attempt to back up an **encrypted database** (with Transparent Data Encryption - TDE) from **SQL Server Management Studio (SSMS)** to an Azure Storage Account was unsuccessful. This issue arises because **Azure does not permit TDE-encrypted databases to be backed up directly to Azure Storage using SSMS**. 43 43 44 - Conclusion:Canbedonewith and unencryptedDBbut notwithanEncryptedone>59 +However, after decrypting the database, we were able to successfully back it up to the Azure Storage Account via SSMS. This confirms that **backups can be performed on an unencrypted database**, but **not on an encrypted database**. 45 45 46 46 47 47 48 48 49 49 50 -= ** Using TDE directlyfromazureportal** =65 += **2. Enabling Transparent Data Encryption (TDE) Using Azure Key Vault** = 51 51 52 52 53 - =====1Go to azurekeyvault(DemoTestRudi)togenerate akey=====68 +**Introduction:** This document outlines the process of enabling **Transparent Data Encryption (TDE)** on an **Azure SQL Managed Instance (SQL MI)** using a **Customer-Managed Key (CMK)** stored in **Azure Key Vault**. The encryption is managed using an asymmetric key from **Azure Key Vault**, ensuring that all data within the SQL Managed Instance is encrypted using a strong encryption algorithm. 54 54 55 55 56 - -Gotokeysandclickgenerate71 +===== **1. Generate a Key in Azure Key Vault** ===== 57 57 58 -- Name your key (mysqlmikey) 59 59 60 -- Chooseakeytype(RSA)74 +**- Navigate to Azure Key Vault:** 61 61 62 - -ChooseRSAkeysize (2048-bit)76 +* Go to the **Azure Portal** and select **Key Vault** (DemoRudiTest). 63 63 64 - Note:78 +**- Generate a New Key:** 65 65 66 -* switching from 2048-bit RSA to 4096-bit RSA for TDE will affect performance, but the actual impact might be minor, especially on modern hardware and typical workloads. 67 -* **It will likely affect CPU usage** more than disk I/O, and the impact might be more noticeable during key management operations (key generation, encryption, etc.). 68 -* If your database is not under heavy load and your hardware can handle the extra processing, the trade-off for better security may be worth it. 80 +* Go to the **Keys** section and click **Generate** to create a new key. 69 69 70 -- C lick create82 +**- Configure Key Settings:** 71 71 84 +* **Name the Key**: Choose a name for your key, e.g., mysqlmikey. 85 +* **Key Type**: Select **RSA** as the key type. 86 +* **RSA Key Size**: Choose an **RSA key size** of **2048-bit**. (optional) 72 72 73 - [[image:image-20250228120622-1.png||height="236"width="542"]]88 + Note: 74 74 90 +* switching from 2048-bit RSA to 4096-bit RSA for TDE will affect performance, but the actual impact might be minor, especially on modern hardware and typical workloads. 91 +* **It will likely affect CPU usage** more than disk I/O, and the impact might be more noticeable during key management operations (key generation, encryption, etc.). 92 +* If your database is not under heavy load and your hardware can handle the extra processing, the trade-off for better security may be worth it. 75 75 76 - =====2 EnableTDE=====94 +**- Create the Key:** 77 77 96 +* Click **Create** to generate the key. 78 78 79 - -Go toyourManagedinstance( sqlmi-ebs-lab)98 +===== **2. Enable TDE on the SQL Managed Instance** ===== 80 80 81 - -Clickon security and choose Transparent data encryption100 +===== ===== 82 82 83 -- Selectthe typeofmanagedkey ( Customer-managed key0102 +**- Navigate to Your Managed Instance:** 84 84 85 - -Selectthe key fromthe keyvaultwegeneratedinthekey vault(mysqlmikey)104 +* Go to your **SQL Managed Instance** (sqlmi-ebs-lab). 86 86 87 -- MakethekeythedefaultTDEprotector106 +**- Enable Transparent Data Encryption (TDE):** 88 88 89 - -Clicksave108 +* Under **Security**, select **Transparent Data Encryption**. 90 90 110 +**- Configure TDE with a Customer-Managed Key (CMK):** 91 91 92 -[[image:image-20250228122106-2.png||height="19" width="241"]] 112 +* Select **Customer-managed key** as the encryption type. 113 +* Choose the key you created earlier from **Azure Key Vault** (mysqlmikey). 93 93 115 +**- Set the Key as Default TDE Protector:** 94 94 95 - -TDEhasnowbeenenabledontheManagedinstance117 +* Make the key the **default TDE protector** for your instance. 96 96 119 +**- Save Configuration:** 97 97 98 -C onclusion:All the databases havebeen encryptedbyan asymmetrickey. The key isthesame for eachdatabase(same encryption thumbprint).121 +* Click **Save** to apply the changes. 99 99 100 - Weare now able to backup databases fromSSMS to Azure storage.123 +=== **Conclusion** === 101 101 125 +After following these steps, **TDE** has been successfully enabled on your **SQL Managed Instance** using an **asymmetric key** stored in **Azure Key Vault**. All databases within the instance are now encrypted using the same encryption key (identified by the same encryption thumbprint). You can now securely back up these encrypted databases from **SSMS** to **Azure Storage**. 102 102 127 +This process ensures that your data is protected both at rest and during backup, offering enhanced security for your managed databases in the cloud. 103 103 104 -=== Backup specific databases using SQL server agent jobs === 105 105 106 106 107 - wearecreating a job to automatically backuponly the DBA databases inthe instance via theSQLserveragent.131 +=== **1. Backup Specific Databases Using SQL Server Agent Jobs** === 108 108 109 -The backup willbedonedailyat3am. The backups will bebackedupintheAzurestorageaccount.133 +This document describes the process of creating an automated **SQL Server Agent Job** to back up only the **DBA databases** in a SQL Server instance. The backups will occur **daily at 3:00 AM** and will be stored in an **Azure Storage Account** for secure and reliable cloud storage. 110 110 135 +---- 111 111 112 -1 Create the script137 +==== **1. Create the Backup Script** ==== 113 113 114 114 115 -=== ** 1.Declaring Variables** ===140 +====== **- Declaring Variables** ====== 116 116 117 117 {{code language="sql"}} 118 118 DECLARE @DatabaseName NVARCHAR(128) ... ... @@ -126,7 +126,7 @@ 126 126 127 127 ---- 128 128 129 -=== **2. Setting the Azure Blob Storage URL** === 154 +====== **2. Setting the Azure Blob Storage URL** ====== 130 130 131 131 {{code language="sql"}} 132 132 SET @BackupContainerURL = 'https://<your_storage_account>.blob.core.windows.net/sql-backups/' ... ... @@ -135,7 +135,7 @@ 135 135 136 136 ---- 137 137 138 -=== **3. Declaring the Cursor** === 163 +====== **3. Declaring the Cursor** ====== 139 139 140 140 141 141 {{code language="sql"}} ... ... @@ -152,7 +152,7 @@ 152 152 153 153 ---- 154 154 155 -=== **4. Opening the Cursor** === 180 +====== **4. Opening the Cursor** ====== 156 156 157 157 {{code language="sql"}} 158 158 OPEN db_cursor ... ... @@ -166,7 +166,7 @@ 166 166 167 167 ---- 168 168 169 -=== **5. Looping Through Databases** === 194 +====== **5. Looping Through Databases** ====== 170 170 171 171 {{code language="sql"}} 172 172 -- Loop through each database and execute the stored procedure ... ... @@ -204,7 +204,7 @@ 204 204 205 205 ---- 206 206 207 -=== **6. Fetch the Next Database** === 232 +====== **6. Fetch the Next Database** ====== 208 208 209 209 {{code language="sql"}} 210 210 -- Fetch the next database in the cursor ... ... @@ -218,7 +218,7 @@ 218 218 219 219 ---- 220 220 221 -=== **7. Closing and Deallocating the Cursor** === 246 +====== **7. Closing and Deallocating the Cursor** ====== 222 222 223 223 {{code language="sql"}} 224 224 -- Close and deallocate the cursor to clean up resources ... ... @@ -231,8 +231,9 @@ 231 231 * **CLOSE db_cursor**: This closes the cursor once the loop finishes processing all databases. 232 232 * **DEALLOCATE db_cursor**: This deallocates the cursor, freeing up any resources used by the cursor. It’s a good practice to always deallocate cursors to avoid resource leaks. 233 233 259 +====== ====== 234 234 235 -===== 8. Full Script ===== 261 +====== **8. Full Script** ====== 236 236 237 237 238 238 {{code language="sql"}} ... ... @@ -271,349 +271,21 @@ 271 271 {{/code}} 272 272 273 273 274 -=== 2. Set up a new job === 275 275 276 276 277 - -GotoSSMS and click on SQL Server Agent302 +=== === 278 278 279 - Drop down menu and left click jobs and select new job 280 280 281 281 282 -====== General: ====== 283 283 284 -- Enter Job name (DBA databases backup) 285 285 286 -- Owner (ebssqladmin) 287 287 288 -- Category (Database maintenance) 289 289 290 - - Description (Description of the job) 291 291 292 292 293 -====== Steps: Create the steps for the job to follow ====== 294 294 295 - - Step name (Backup only DBA database) 296 296 297 - - Type (Transact-SQL script) 298 298 299 - - Database (master) 300 300 301 - - Command (paste the script we created) 302 302 303 - 304 - Schedule: Create a schedule for the job to run 305 - 306 - - Name (DBA database backup) 307 - 308 - - Schedule Type (recurring) 309 - 310 - - Frequency (Occurs: Daily) 311 - 312 - (Recurs every: 1 day(s)) 313 - 314 - 315 - 316 - 317 - 318 - 319 - 320 - 321 - 322 -1 CREATE MASTER KEY ENCRYPTION BY PASSWORD = 'YourStrongPasswordHere!'; 323 -GO 324 - 325 -CREATE CERTIFICATE TDE_Certificate 326 -WITH SUBJECT = 'TDE Certificate'; 327 -GO 328 - 329 -2 USE master; 330 -GO 331 - 332 -SELECT 333 - cert.name AS Certificate_Name, 334 - cert.subject AS Certificate_Subject, 335 - cert.issuer_name AS Issuer_Name, 336 - cert.pvt_key_encryption_type AS Private_Key_Encryption_Type 337 -FROM 338 - sys.certificates cert 339 -WHERE 340 - cert.name LIKE 'TDE%'; 341 - 342 - 343 -3 BACKUP CERTIFICATE TDE_Certificate 344 -TO FILE = https://zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D\TDE_Certificate.cer' 345 -WITH PRIVATE KEY ( 346 - FILE = https://zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D\TDE_PrivateKey.pvk', 347 - ENCRYPTION BY PASSWORD = 'AnotherStrongPasswordHere!' 348 -); 349 -GO 350 - 351 - 352 -USE Normal; 353 -GO 354 - 355 --- 6. Create a Database Encryption Key (DEK) and encrypt it with the TDE certificate 356 -CREATE DATABASE ENCRYPTION KEY 357 -WITH ALGORITHM = AES_256 358 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 359 -GO-- 360 - 361 -USE [dba] 362 -GO 363 - 364 -CREATE DATABASE ENCRYPTION KEY 365 -WITH ALGORITHM = AES_256 366 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 367 -GO 368 - 369 - 370 -USE [dba1] 371 -GO 372 - 373 -CREATE DATABASE ENCRYPTION KEY 374 -WITH ALGORITHM = AES_256 375 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 376 -GO 377 - 378 - 379 -USE [dba2] 380 -GO 381 - 382 -CREATE DATABASE ENCRYPTION KEY 383 -WITH ALGORITHM = AES_256 384 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 385 -GO 386 - 387 - 388 -USE [dba3] 389 -GO 390 - 391 -CREATE DATABASE ENCRYPTION KEY 392 -WITH ALGORITHM = AES_256 393 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 394 -GO 395 - 396 -USE [xwiki] 397 -GO 398 - 399 -CREATE DATABASE ENCRYPTION KEY 400 -WITH ALGORITHM = AES_256 401 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 402 -GO 403 - 404 - 405 --- 7. Enable Transparent Data Encryption (TDE) on the database 406 -ALTER DATABASE dba 407 -SET ENCRYPTION ON; 408 -GO-- 409 - 410 - 411 -select name, database_id, state_desc 412 -from sys.databases 413 - 414 - 415 -SELECT 416 - database_id, 417 - key_algorithm, 418 - key_length, 419 - encryption_state_desc 420 - encryptor_type 421 - 422 -FROM 423 - sys.dm_database_encryption_keys; 424 - 425 - 426 - Select * from sys.dm_database_encryption_keys 427 - 428 - 429 - BACKUP DATABASE [dba2] 430 -TO URL = '[[https:~~/~~/zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D'>>https://zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D']] 431 -With copy_only 432 -GO 433 - 434 - 435 -BACKUP DATABASE [dba2] 436 -TO URL = '[[https:~~/~~/zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D'>>https://zagpebslab.blob.core.windows.net/sql-backups?sp=racwl&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=eQKxB%2F0bg5cX71PmhUTlGHLCnIwSbe5CLOWVVkaDR1g%3D']], 437 -\\ COPY_ONLY, -- Ensures the backup does not affect the regular backup chain 438 - COMPRESSION, -- Optional: Compresses the backup to save storage space 439 - STATS = 10 -- Optional: Provides backup progress status 440 -GO-- 441 - 442 - 443 - 444 --- Step 1: Drop the existing credential (if needed) 445 -DROP CREDENTIAL [https://zagpebslab.blob.core.windows.net/sql-backups]; 446 -GO-- 447 - 448 --- Step 2: Create a new credential with the SAS token 449 -CREATE CREDENTIAL [https://zagpebslab.blob.core.windows.net/sql-backups] 450 -WITH IDENTITY = 'SHARED ACCESS SIGNATURE', 451 -SECRET = 'sp=racwdli&st=2025-02-25T13:28:42Z&se=2026-02-25T21:28:42Z&spr=https&sv=2022-11-02&sr=c&sig=kBFwlj5S5eqBEE32LM1EFebBY0W94uEFiwOXo3R0yt4%3D'; 452 -GO-- 453 - 454 --- Step 3: Perform the database backup with the provided parameters 455 -EXECUTE dba.dbo.DatabaseBackup 456 - @Databases = 'dba', -- Replace with your database name 457 - @URL = '[[https:~~/~~/zagpebslab.blob.core.windows.net/sql-backups'>>https://zagpebslab.blob.core.windows.net/sql-backups']], -- Azure Blob Storage URL 458 - @BackupType = 'Full', -- Full backup 459 - @CopyOnly = 'Y', -- Copy-only backup to avoid breaking backup chain 460 - @Compress = 'Y', -- Compress the backup 461 - @Verify = 'N'; -- No verification of backup 462 -GO-- 463 - 464 - 465 - 466 - 467 - 468 -select name, database_id, state_desc 469 -from sys.databases 470 - 471 - 472 -SELECT 473 - database_id, 474 - key_algorithm, 475 - key_length, 476 - encryption_state_desc 477 - encryptor_type 478 - 479 -FROM 480 - select * from sys.dm_database_encryption_keys; 481 - 482 - 483 - select name, is_encrypted from sys.databases 484 - 485 - 486 - SELECT 487 - cert.name AS Certificate_Name, 488 - cert.subject AS Certificate_Subject, 489 - cert.issuer_name AS Issuer_Name, 490 - cert.pvt_key_encryption_type AS Private_Key_Encryption_Type 491 -FROM 492 - sys.certificates cert 493 -WHERE 494 - cert.name LIKE 'TDE%'; 495 - 496 - ALTER DATABASE dba1 497 -SET ENCRYPTION off; 498 -GO 499 - 500 - 501 -Use dba1; 502 -DROP DATABASE ENCRYPTION KEY; 503 - 504 - 505 -USE [dba1] 506 -GO 507 - 508 -CREATE DATABASE ENCRYPTION KEY 509 -WITH ALGORITHM = AES_256 510 -ENCRYPTION BY SERVER CERTIFICATE TDE_Certificate; 511 -GO 512 - 513 - 514 - 515 -ALTER DATABASE dba1 516 -SET ENCRYPTION ON 517 - 518 - 519 - 520 - 521 - 522 - 523 - 524 - 525 - 526 - 527 - 528 - 529 - 530 - 531 - 532 - 533 - 534 - 535 - 536 - 537 -{{code language="sql"}} 538 -USE master; 539 -GO 540 -CREATE MASTER KEY ENCRYPTION BY PASSWORD = '******'; 541 -GO 542 - 543 -CREATE CERTIFICATE EBSphere_TDE_SQL2019_Cert WITH SUBJECT = 'Database_Encryption'; 544 -GO 545 - 546 -BACKUP CERTIFICATE EBSphere_TDE_SQL2019_Cert TO FILE = 'D:\temp\EBSphere_TDE_SQL2019_Cert' 547 -WITH PRIVATE KEY (file = 'D:\temp\EBSphere_TDE_SQL2019_Cert_Key.pvk', 548 -ENCRYPTION BY PASSWORD='*****') 549 - 550 -USE Everest_TDE_Master; 551 -GO 552 -CREATE DATABASE ENCRYPTION KEY 553 -WITH ALGORITHM = AES_256 554 -ENCRYPTION BY SERVER CERTIFICATE EBSphere_TDE_SQL2019_Cert; 555 -GO 556 -ALTER DATABASE Everest_TDE_Master 557 -SET ENCRYPTION ON; 558 -GO 559 - 560 -USE Everest_TDE_Master_Documents; 561 -GO 562 -CREATE DATABASE ENCRYPTION KEY 563 -WITH ALGORITHM = AES_256 564 -ENCRYPTION BY SERVER CERTIFICATE EBSphere_TDE_SQL2019_Cert; 565 -GO 566 -ALTER DATABASE Everest_TDE_Master_Documents 567 -SET ENCRYPTION ON; 568 -GO 569 -{{/code}} 570 - 571 - 572 - 573 - 574 - 575 - 576 - 577 - 578 - 579 - 580 - 581 - 582 - 583 -{{code language="sql"}} 584 -USE master; 585 -GO 586 -CREATE MASTER KEY ENCRYPTION BY PASSWORD = '******'; 587 -GO 588 - 589 -CREATE CERTIFICATE EBSphere_TDE_SQL2019_Cert WITH SUBJECT = 'Database_Encryption'; 590 -GO 591 - 592 -BACKUP CERTIFICATE EBSphere_TDE_SQL2019_Cert TO FILE = 'D:\temp\EBSphere_TDE_SQL2019_Cert' 593 -WITH PRIVATE KEY (file = 'D:\temp\EBSphere_TDE_SQL2019_Cert_Key.pvk', 594 -ENCRYPTION BY PASSWORD='*****') 595 - 596 -USE Everest_TDE_Master; 597 -GO 598 -CREATE DATABASE ENCRYPTION KEY 599 -WITH ALGORITHM = AES_256 600 -ENCRYPTION BY SERVER CERTIFICATE EBSphere_TDE_SQL2019_Cert; 601 -GO 602 -ALTER DATABASE Everest_TDE_Master 603 -SET ENCRYPTION ON; 604 -GO 605 - 606 -USE Everest_TDE_Master_Documents; 607 -GO 608 -CREATE DATABASE ENCRYPTION KEY 609 -WITH ALGORITHM = AES_256 610 -ENCRYPTION BY SERVER CERTIFICATE EBSphere_TDE_SQL2019_Cert; 611 -GO 612 -ALTER DATABASE Everest_TDE_Master_Documents 613 -SET ENCRYPTION ON; 614 -GO 615 -{{/code}} 616 - 617 - 618 - 619 619
- image-20250305152543-1.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +XWiki.rudim - Size
-
... ... @@ -1,0 +1,1 @@ 1 +19.6 KB - Content