Automated TLS certificates for Microsoft SQL Server
SQL Server needs three things for a certificate to work: the certificate in the machine store, read access to its private key for the service account, and the thumbprint set on the instance. The SQL Server package handles all three.
package windows-sql-target 3.0.0
importgrantKeyReadwhen configuredsetSqlCertificaterestartSqlServicewhen configuredcleanupwhen configured
At a glance
- Package
windows-sql-target 3.0.0- Compatibility
Windows Server / SQL Server >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell · Service reload or restart
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyGrant key accessUpdate bindingReload serviceRemove old certificate
- Deployment steps
- import → grantKeyRead* → setSqlCertificate → restartSqlService* → cleanup*
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
The agent imports the certificate, grants the SQL Server service account - for example NT Service\MSSQLSERVER - read access to the private key, and sets the certificate for the default or a named instance. Force Encryption can be switched on in the same step.
SQL Server only picks up a new certificate when the service restarts, so the restart is an explicit option you choose rather than something that happens unannounced.
How it runs
- 01
import
The certificate and key are imported into the machine store.
- 02
grantKeyRead
The SQL Server service account gets read access to the private key.
- 03
setSqlCertificate
The certificate is set for the instance, with Force Encryption if configured.
- 04
restartSqlService
The SQL Server service is restarted, if enabled.
- 05
cleanup
The previous certificate is removed, if enabled.
What you configure
- SQL Server instance (default MSSQLSERVER) and service name
- Service account to grant key read access
- Force Encryption on or off
- Restart the service after deployment
- Certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on the SQL Server host
- A certificate whose names match how clients address the server
Limitations
- Without the restart option, the new certificate takes effect at the next service restart.
- Clustered and Always On configurations need a deploy target on each node.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Frequently asked questions
Microsoft SQL Server
Will the deployment restart SQL Server?
Only if you enable the restart option. Otherwise the certificate is set and takes effect at the next restart you schedule.
Does it work with named instances?
Yes. Set the instance name; the service name is derived as MSSQL$<instance>.
Automate Microsoft SQL Server
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.