Install EKM Provider
Install the EKM Provider
Deploy the DuoKey cryptographic provider on your SQL Server
Overview
This guide explains how to deploy the DuoKey SQL EKM Provider on Microsoft SQL Server. The provider is a single signed library that lets SQL Server delegate Transparent Data Encryption (TDE) key operations to the DuoKey cloud key management service.
Deployment is a file-based operation: you place one code-signed provider library and one configuration file on the SQL Server host, confirm the signature is trusted, and make sure the SQL Server service account can read them. There is no setup wizard, no MSI, and no files are copied into C:\Windows\System32.
Prerequisites
- SQL EKM App created in DuoKey platform
- Setup file downloaded from DuoKey platform (provider library + config template)
- Microsoft SQL Server 2016 or later installed
- Administrator privileges on the SQL Server machine
- Network connectivity to DuoKey cloud platform (HTTPS port 443)
System Requirements
SQL Server
- SQL Server 2016 or later
- Recommended: SQL Server 2019+
- Enterprise or Developer edition
Operating System
- Windows Server 2012 R2 or later
- Windows 10/11 (dev/testing)
- 64-bit architecture
Disk Space
- Minimum 100 MB free
- Provider folder for the library
- Config & keystore under ProgramData
Network
- HTTPS (port 443) outbound
- Access to DuoKey platform
- TLS 1.2 or higher
Extensible Key Management is available only on the Enterprise and Developer editions of SQL Server on Windows. It is not available on Standard, Web, or Express editions.
Deployment Layout
The provider uses two locations on the SQL Server host:
| Path | Contents |
|---|---|
C:\Program Files\DKE\EKM | The signed provider library DuoKeyCryptoProvider.dll (any folder the SQL Server service account can read). |
C:\ProgramData\DKE\EKM | config.toml (connection settings), keystore.json (key mapping, created by the provider), and dke-ekm.log (local log). |
The provider is loaded by SQL Server through the path you register with CREATE CRYPTOGRAPHIC PROVIDER, so it does not need to live in a system directory. Keeping it in a dedicated application folder makes upgrades and auditing simpler.
Installation Steps
Extract the Setup File
- Locate the setup file downloaded from the DuoKey platform
- Extract the archive to a temporary location
- Confirm it contains the provider library
DuoKeyCryptoProvider.dlland aconfig.tomltemplate
Place the Provider Library
Create the provider folder and copy the signed library into it.
C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dllAny folder works as long as the SQL Server service account can read it. Avoid per-user profile paths and network shares.
Deploy the Configuration File
Create the ProgramData folder and copy the config.toml template from the setup file into it.
C:\ProgramData\DKE\EKM\config.tomlYou will fill in the connection values in the next guide. The provider also writes keystore.json and dke-ekm.log to this same folder at runtime, so it must be writable by the SQL Server service account.
Confirm the Signature Is Trusted
The provider library is Authenticode-signed. SQL Server refuses to load a cryptographic provider whose signature chain is not trusted on the machine, so verify it before registering the provider.
Get-AuthenticodeSignature "C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dll" |
Format-List Status, SignerCertificate, StatusMessageThe Status must be Valid. If it is not, install the DuoKey signing certificate chain into the machine Trusted Root Certification Authorities and Trusted Publishers stores, then re-run the check.
If the signature is missing, broken, or issued by an untrusted chain, CREATE CRYPTOGRAPHIC PROVIDER fails and SQL Server will not load the library.
Grant Read Access to the Service Account
Ensure the account that runs the SQL Server service can read the provider folder and read/write the ProgramData folder. Identify the service account first.
Get-CimInstance Win32_Service -Filter "Name='MSSQLSERVER'" |
Select-Object Name, StartName# Read + execute on the provider folder
icacls "C:\Program Files\DKE\EKM" /grant "NT SERVICE\MSSQLSERVER:(OI)(CI)RX"
# Read + write on the ProgramData folder (config, keystore, log)
icacls "C:\ProgramData\DKE\EKM" /grant "NT SERVICE\MSSQLSERVER:(OI)(CI)M"For a named instance the service account is typically NT SERVICE\MSSQL$InstanceName. If the service runs under a domain account, grant the same rights to that account instead.
Post-Installation Verification
Confirm the two files are present and the signature is trusted before moving on to configuration.
Files to Verify
Deployment does not require any registry changes. An optional HKLM\SOFTWARE\DKE\EKM key may be present for advanced settings, but it is not needed for a standard installation.