Create SQL EKM App
Create the SQL EKM App
Set up your DuoKey SQL EKM application in the cloud platform
Overview
This guide walks you through creating a DuoKey SQL EKM application in the DuoKey cloud platform. The app provides the credentials and configuration needed to connect SQL Server to DuoKey's key management service.
App creation happens entirely in the Cockpit v2 console: every app — SQL EKM, Oracle TDE, DKE 365, PKI/SSL — is created through the same Apps section and a common install wizard (catalog → role assignment → vault selection → setup file download). If you want to see this flow before running it yourself, try the click-through Interactive Demo of the Cockpit v2 console.
Prerequisites
- Access to the DuoKey cloud platform
- Valid user credentials for your tenant
- Appropriate permissions to create applications
Step-by-Step Guide
Access DuoKey Cloud Platform
Navigate to the DuoKey cloud platform and log in with your credentials.
Bookmark the DuoKey platform URL for quick access during configuration.
Select Your Tenant
If you have access to multiple tenants, select the appropriate tenant where you want to create the SQL EKM app.
Navigate to Apps Section
From the dashboard, navigate to the Apps section in the main menu.
Create New Application
In the Apps section of the Cockpit v2 console, click "Create New APP". This opens the app catalog, listing every DuoKey application available to your tenant.
Select SQL EKM
In the app catalog, locate "SQL EKM" and click "Install Now" to launch the SQL EKM app creation wizard.
Enter Application Details
The "Create an SQL EKM encryption module" page will appear. Enter the following details:
| Field | Description | Required |
|---|---|---|
| App Name | Unique identifier for your SQL EKM app | Yes |
| Description | Brief description of the app's purpose | No |
| Environment | Target environment (Production, Development, etc.) | Yes |
Click "Next" to proceed.
Assign Roles for Access Control
Configure role-based access control (RBAC) for the SQL EKM app:
- Select users or groups that should have access to this app
- Assign appropriate roles (Admin, User, etc.)
- Click "Next Step" to continue
Select a Vault
Choose the vault that will contain your SQL EKM encryption keys:
- Choose an existing vault from the dropdown list
- Alternatively, create a new vault if needed
- Click "Next Step" to proceed
Download Setup Files
The "Verify your EKM module" screen will be displayed:
- Review the configuration details
- Download the setup file (installer) from the page
- Save the setup file to a secure location
Keep the setup file secure as it contains configuration specific to your SQL EKM app.
Save Your Setup File
Click "Submit" to save the app. The app will appear in the applications grid.
Store the setup file and its enrolled agent key securely. The agent key cannot be retrieved later from the DuoKey platform.
Credential Information
When the app is created, the setup file carries the values SQL Server needs:
Setup File
Delivers the provider and its config.toml (server URL, tenant/app identifiers)
duokey-sql-ekm-setupEnrolled Agent Key
The single secret SQL Server uses to authenticate to DuoKey
••••••••••••••••Credential Format for SQL Server
When creating credentials in SQL Server, the value SQL Server needs is the single enrolled agent key from the setup file. The IDENTITY is just a label:
CREATE CREDENTIAL credential_name
WITH IDENTITY = 'dke-ekm-service',
SECRET = '<agent-key>'
FOR CRYPTOGRAPHIC PROVIDER provider_name;The SECRET is the single enrolled agent key from your setup file. There is no Client ID / Client Secret / Password combination and no delimiter syntax - use the agent key exactly as delivered.