Skip to main content

Uninstallation

Applies to:
SQL Server 2016+Administrator RequiredBackup Required

When to Uninstall​

You may need to uninstall the EKM provider in these scenarios:

Troubleshooting

Resolving installation or configuration issues

Upgrading

Installing a newer version of the provider

Decommissioning

Removing SQL EKM from the server

Migration

Moving to a different encryption solution

Warning

If you have encrypted databases, removing the EKM provider will prevent access to those databases unless you first decrypt them or preserve the key configuration. Decrypt first, or keep the provider, credential, and master key in place.

Prerequisites

  • Backup all encrypted databases
  • Document current configuration (credentials, keys, etc.)
  • Administrator privileges on the server
  • Verify no active encrypted databases (or plan for re-encryption)

Pre-Uninstallation Steps​

Inventory Encrypted Databases​

First, identify all databases protected by TDE:

Find Encrypted DatabasesSQL
SELECT
  d.name AS DatabaseName,
  d.is_encrypted,
  dek.encryption_state,
  dek.encryptor_type
FROM sys.databases d
LEFT JOIN sys.dm_database_encryption_keys dek
  ON d.database_id = dek.database_id
WHERE d.is_encrypted = 1;
GO

Document Configuration​

Record the current provider, key, and credential details before uninstalling:

Document Current ConfigurationSQL
-- Document cryptographic providers
SELECT
  name AS ProviderName,
  guid,
  is_enabled,
  dll_path
FROM sys.cryptographic_providers;
GO

-- Document asymmetric keys and the provider they are bound to
USE master;
SELECT
  ak.name AS KeyName,
  ak.algorithm_desc,
  ak.thumbprint,
  cp.name AS ProviderName
FROM sys.asymmetric_keys ak
LEFT JOIN sys.cryptographic_providers cp
  ON ak.cryptographic_provider_guid = cp.guid;
GO

-- Document credentials
SELECT
  name AS CredentialName,
  credential_identity
FROM sys.credentials
WHERE name LIKE '%Dke%' OR name LIKE '%EKM%';
GO

Backup Databases​

Important

Always back up all encrypted databases before proceeding with uninstallation.

Backup Encrypted DatabaseSQL
BACKUP DATABASE <DatabaseName>
TO DISK = 'C:\Backups\<DatabaseName>_PreUninstall.bak'
WITH COMPRESSION, CHECKSUM;
GO

SQL Server Cleanup​

Remove the SQL Server objects in this order: credential mappings, then logins, then credentials, then the asymmetric key, and finally the provider. A provider cannot be dropped while any key or credential still references it.

Warning

If any database is still encrypted, decrypt it first (see Decrypt Before Uninstalling). Dropping the master key or provider while a database is encrypted makes that database unrecoverable.

1

Remove Credential Mappings

Remove the credential from every login it is mapped to:

List and Drop Credential MappingsSQL
-- List logins with the EKM credential mapped
SELECT
  l.name AS LoginName,
  c.name AS CredentialName
FROM sys.server_principals l
INNER JOIN sys.credentials c
  ON l.credential_id = c.credential_id
WHERE c.name LIKE '%Dke%';
GO

-- Drop the mappings
ALTER LOGIN [sa]
DROP CREDENTIAL DkeEkmCredential;
GO

ALTER LOGIN [TDE_Master_Login]
DROP CREDENTIAL DkeEkmCredential;
GO
2

Drop the Key Login

Drop Login Backed by the Asymmetric KeySQL
DROP LOGIN TDE_Master_Login;
GO
3

Drop the Credential

Drop CredentialSQL
DROP CREDENTIAL DkeEkmCredential;
GO
Tip

If dropping the credential fails, ensure every login mapping from Step 1 has been removed first.

4

Drop the Asymmetric Key

Drop Asymmetric KeySQL
USE master;
DROP ASYMMETRIC KEY TDE_Master;
GO
Caution

This removes only the SQL Server reference to the key. The key itself remains in DuoKey and can be reopened later with OPEN_EXISTING.

5

Drop the Cryptographic Provider

Drop ProviderSQL
DROP CRYPTOGRAPHIC PROVIDER DkeEkm;
GO
Caution

You cannot drop a cryptographic provider while it is still referenced by an asymmetric key or credential. Complete Steps 1 to 4 first.

Remove the Provider Files​

With the SQL objects gone, remove the deployed files from the host.

1

Stop SQL Server (if needed)

The provider library is loaded by SQL Server. If the file is locked, stop the service before deleting it.

Stop the SQL Server ServicePOWERSHELL
Stop-Service MSSQLSERVER
2

Delete the Provider Library

Remove the Provider FolderPOWERSHELL
Remove-Item "C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dll" -Force
# Optionally remove the folder if now empty
Remove-Item "C:\Program Files\DKE\EKM" -Recurse -Force
3

Remove the Configuration and Runtime Files

Delete the ProgramData folder, which holds config.toml, keystore.json, and dke-ekm.log.

Remove the ProgramData FolderPOWERSHELL
Remove-Item "C:\ProgramData\DKE\EKM" -Recurse -Force
Caution

Keeping databases encrypted? Do not delete keystore.json. The provider needs it to reopen TDE-protected databases after a restart.

4

Restart SQL Server

Start the SQL Server ServicePOWERSHELL
Start-Service MSSQLSERVER

Post-Uninstallation Verification​

Verify File Removal​

Files to Verify Removed

DuoKeyCryptoProvider.dllC:\Program Files\DKE\EKM
config.tomlC:\ProgramData\DKE\EKM
keystore.jsonC:\ProgramData\DKE\EKM
dke-ekm.logC:\ProgramData\DKE\EKM
Optional registry key

If the optional HKLM\SOFTWARE\DKE\EKM key was created for advanced settings, you can remove it as well. A standard installation does not create any registry entries.

Verify SQL Server State​

Verify Provider RemovedSQL
-- Should return no rows
SELECT name, guid, is_enabled
FROM sys.cryptographic_providers
WHERE name = 'DkeEkm';
GO

Handling Encrypted Databases​

Option 1: Keep Databases Encrypted​

If you plan to reinstall or maintain encryption:

Keep Backups

Maintain backups of encrypted databases

Preserve the Keystore

Retain config.toml and keystore.json so the key can be reopened

Plan Reinstall

Redeploy the provider and reopen the master key when ready

Option 2: Decrypt Before Uninstalling​

If you want to remove encryption entirely, decrypt every database before dropping any SQL objects or deleting files:

Disable TDE and DecryptSQL
-- Disable TDE
ALTER DATABASE <DatabaseName>
SET ENCRYPTION OFF;
GO

-- Monitor decryption progress
SELECT
  DB_NAME(database_id) AS DatabaseName,
  encryption_state,
  percent_complete
FROM sys.dm_database_encryption_keys;
GO

-- Wait until encryption_state = 1 (Unencrypted)

-- Drop the Database Encryption Key
USE <DatabaseName>;
DROP DATABASE ENCRYPTION KEY;
GO

-- Verify decryption
SELECT
  name,
  is_encrypted
FROM sys.databases
WHERE name = '<DatabaseName>';
GO

Troubleshooting​

Emergency Uninstallation​

Warning

Emergency uninstallation may leave encrypted databases inaccessible. Only use in critical situations with proper backups.

Quick Force Removal of SQL ObjectsSQL
-- Force remove references, then the provider
USE master;
DROP ASYMMETRIC KEY TDE_Master;
GO

DROP CREDENTIAL DkeEkmCredential;
GO

DROP CRYPTOGRAPHIC PROVIDER DkeEkm;
GO

Then remove the provider files as described above.

Next Steps​