aethercert
Microsoft and Windows Server

Automated TLS certificates for Microsoft SQL Server

SQL Server needs three things for a certificate to work: the certificate in the machine store, read access to its private key for the service account, and the thumbprint set on the instance. The SQL Server package handles all three.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-sql-target 3.0.0
Compatibility
Windows Server / SQL Server >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell · Service reload or restart
Authentication
Local - no remote login
Capabilities
Import certificate and keyGrant key accessUpdate bindingReload serviceRemove old certificate
Deployment steps
import → grantKeyRead* → setSqlCertificate → restartSqlService* → cleanup*
Rollback
None
Key usage
Server authentication

* conditional step

What it does

The agent imports the certificate, grants the SQL Server service account - for example NT Service\MSSQLSERVER - read access to the private key, and sets the certificate for the default or a named instance. Force Encryption can be switched on in the same step.

SQL Server only picks up a new certificate when the service restarts, so the restart is an explicit option you choose rather than something that happens unannounced.

How it runs

  1. 01

    import

    The certificate and key are imported into the machine store.

  2. 02

    grantKeyRead

    The SQL Server service account gets read access to the private key.

  3. 03

    setSqlCertificate

    The certificate is set for the instance, with Force Encryption if configured.

  4. 04

    restartSqlService

    The SQL Server service is restarted, if enabled.

  5. 05

    cleanup

    The previous certificate is removed, if enabled.

What you configure

  • SQL Server instance (default MSSQLSERVER) and service name
  • Service account to grant key read access
  • Force Encryption on or off
  • Restart the service after deployment
  • Certificate store, friendly name and clean-up

Prerequisites

  • A Windows agent on the SQL Server host
  • A certificate whose names match how clients address the server

Limitations

  • Without the restart option, the new certificate takes effect at the next service restart.
  • Clustered and Always On configurations need a deploy target on each node.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Microsoft SQL Server

Will the deployment restart SQL Server?

Only if you enable the restart option. Otherwise the certificate is set and takes effect at the next restart you schedule.

Does it work with named instances?

Yes. Set the instance name; the service name is derived as MSSQL$<instance>.

Automate Microsoft SQL Server

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.