Skip to main content

Install EKM Provider

Applies to:
Windows Server 2012 R2+SQL Server 2016+Administrator Required

Overview​

This guide explains how to deploy the DuoKey SQL EKM Provider on Microsoft SQL Server. The provider is a single signed library that lets SQL Server delegate Transparent Data Encryption (TDE) key operations to the DuoKey cloud key management service.

Deployment is a file-based operation: you place one code-signed provider library and one configuration file on the SQL Server host, confirm the signature is trusted, and make sure the SQL Server service account can read them. There is no setup wizard, no MSI, and no files are copied into C:\Windows\System32.

Prerequisites

  • SQL EKM App created in DuoKey platform
  • Setup file downloaded from DuoKey platform (provider library + config template)
  • Microsoft SQL Server 2016 or later installed
  • Administrator privileges on the SQL Server machine
  • Network connectivity to DuoKey cloud platform (HTTPS port 443)

System Requirements​

SQL Server

  • SQL Server 2016 or later
  • Recommended: SQL Server 2019+
  • Enterprise or Developer edition

Operating System

  • Windows Server 2012 R2 or later
  • Windows 10/11 (dev/testing)
  • 64-bit architecture

Disk Space

  • Minimum 100 MB free
  • Provider folder for the library
  • Config & keystore under ProgramData

Network

  • HTTPS (port 443) outbound
  • Access to DuoKey platform
  • TLS 1.2 or higher
EKM is edition-gated

Extensible Key Management is available only on the Enterprise and Developer editions of SQL Server on Windows. It is not available on Standard, Web, or Express editions.

Deployment Layout​

The provider uses two locations on the SQL Server host:

PathContents
C:\Program Files\DKE\EKMThe signed provider library DuoKeyCryptoProvider.dll (any folder the SQL Server service account can read).
C:\ProgramData\DKE\EKMconfig.toml (connection settings), keystore.json (key mapping, created by the provider), and dke-ekm.log (local log).
Why not System32

The provider is loaded by SQL Server through the path you register with CREATE CRYPTOGRAPHIC PROVIDER, so it does not need to live in a system directory. Keeping it in a dedicated application folder makes upgrades and auditing simpler.

Installation Steps​

1

Extract the Setup File

  1. Locate the setup file downloaded from the DuoKey platform
  2. Extract the archive to a temporary location
  3. Confirm it contains the provider library DuoKeyCryptoProvider.dll and a config.toml template
2

Place the Provider Library

Create the provider folder and copy the signed library into it.

Provider Library LocationTEXT
C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dll
Tip

Any folder works as long as the SQL Server service account can read it. Avoid per-user profile paths and network shares.

3

Deploy the Configuration File

Create the ProgramData folder and copy the config.toml template from the setup file into it.

Configuration File LocationTEXT
C:\ProgramData\DKE\EKM\config.toml

You will fill in the connection values in the next guide. The provider also writes keystore.json and dke-ekm.log to this same folder at runtime, so it must be writable by the SQL Server service account.

4

Confirm the Signature Is Trusted

The provider library is Authenticode-signed. SQL Server refuses to load a cryptographic provider whose signature chain is not trusted on the machine, so verify it before registering the provider.

Verify the Authenticode SignaturePOWERSHELL
Get-AuthenticodeSignature "C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dll" |
Format-List Status, SignerCertificate, StatusMessage

The Status must be Valid. If it is not, install the DuoKey signing certificate chain into the machine Trusted Root Certification Authorities and Trusted Publishers stores, then re-run the check.

Trust is mandatory

If the signature is missing, broken, or issued by an untrusted chain, CREATE CRYPTOGRAPHIC PROVIDER fails and SQL Server will not load the library.

5

Grant Read Access to the Service Account

Ensure the account that runs the SQL Server service can read the provider folder and read/write the ProgramData folder. Identify the service account first.

Find the SQL Server Service AccountPOWERSHELL
Get-CimInstance Win32_Service -Filter "Name='MSSQLSERVER'" |
Select-Object Name, StartName
Grant Access to the Service AccountPOWERSHELL
# Read + execute on the provider folder
icacls "C:\Program Files\DKE\EKM" /grant "NT SERVICE\MSSQLSERVER:(OI)(CI)RX"

# Read + write on the ProgramData folder (config, keystore, log)
icacls "C:\ProgramData\DKE\EKM" /grant "NT SERVICE\MSSQLSERVER:(OI)(CI)M"
Named instances

For a named instance the service account is typically NT SERVICE\MSSQL$InstanceName. If the service runs under a domain account, grant the same rights to that account instead.

Post-Installation Verification​

Confirm the two files are present and the signature is trusted before moving on to configuration.

Files to Verify

DuoKeyCryptoProvider.dllC:\Program Files\DKE\EKM\ — signature Valid
config.tomlC:\ProgramData\DKE\EKM\ — readable by service account
Optional registry key

Deployment does not require any registry changes. An optional HKLM\SOFTWARE\DKE\EKM key may be present for advanced settings, but it is not needed for a standard installation.

Troubleshooting​

Next Steps​