Skip to main content

Create SQL EKM App

Applies to:
DuoKey Cloud PlatformAdmin Access Required

Overview​

This guide walks you through creating a DuoKey SQL EKM application in the DuoKey cloud platform. The app provides the credentials and configuration needed to connect SQL Server to DuoKey's key management service.

Cockpit v2

App creation happens entirely in the Cockpit v2 console: every app — SQL EKM, Oracle TDE, DKE 365, PKI/SSL — is created through the same Apps section and a common install wizard (catalog → role assignment → vault selection → setup file download). If you want to see this flow before running it yourself, try the click-through Interactive Demo of the Cockpit v2 console.

Prerequisites

  • Access to the DuoKey cloud platform
  • Valid user credentials for your tenant
  • Appropriate permissions to create applications

Step-by-Step Guide​

1

Access DuoKey Cloud Platform

Navigate to the DuoKey cloud platform and log in with your credentials.

Tip

Bookmark the DuoKey platform URL for quick access during configuration.

2

Select Your Tenant

If you have access to multiple tenants, select the appropriate tenant where you want to create the SQL EKM app.

3

Navigate to Apps Section

From the dashboard, navigate to the Apps section in the main menu.

4

Create New Application

In the Apps section of the Cockpit v2 console, click "Create New APP". This opens the app catalog, listing every DuoKey application available to your tenant.

5

Select SQL EKM

In the app catalog, locate "SQL EKM" and click "Install Now" to launch the SQL EKM app creation wizard.

6

Enter Application Details

The "Create an SQL EKM encryption module" page will appear. Enter the following details:

FieldDescriptionRequired
App NameUnique identifier for your SQL EKM appYes
DescriptionBrief description of the app's purposeNo
EnvironmentTarget environment (Production, Development, etc.)Yes

Click "Next" to proceed.

7

Assign Roles for Access Control

Configure role-based access control (RBAC) for the SQL EKM app:

  1. Select users or groups that should have access to this app
  2. Assign appropriate roles (Admin, User, etc.)
  3. Click "Next Step" to continue
8

Select a Vault

Choose the vault that will contain your SQL EKM encryption keys:

  1. Choose an existing vault from the dropdown list
  2. Alternatively, create a new vault if needed
  3. Click "Next Step" to proceed
9

Download Setup Files

The "Verify your EKM module" screen will be displayed:

  1. Review the configuration details
  2. Download the setup file (installer) from the page
  3. Save the setup file to a secure location
Important

Keep the setup file secure as it contains configuration specific to your SQL EKM app.

10

Save Your Setup File

Click "Submit" to save the app. The app will appear in the applications grid.

Warning

Store the setup file and its enrolled agent key securely. The agent key cannot be retrieved later from the DuoKey platform.

Credential Information​

When the app is created, the setup file carries the values SQL Server needs:

Setup File

Delivers the provider and its config.toml (server URL, tenant/app identifiers)

duokey-sql-ekm-setup

Enrolled Agent Key

The single secret SQL Server uses to authenticate to DuoKey

••••••••••••••••

Credential Format for SQL Server​

When creating credentials in SQL Server, the value SQL Server needs is the single enrolled agent key from the setup file. The IDENTITY is just a label:

SQL Server Credential FormatSQL
CREATE CREDENTIAL credential_name
WITH IDENTITY = 'dke-ekm-service',
SECRET = '<agent-key>'
FOR CRYPTOGRAPHIC PROVIDER provider_name;
Caution

The SECRET is the single enrolled agent key from your setup file. There is no Client ID / Client Secret / Password combination and no delimiter syntax - use the agent key exactly as delivered.

Troubleshooting​

Next Steps​