Uninstallation
Uninstalling the EKM Provider
Properly remove the DuoKey SQL EKM Provider from your SQL Server
When to Uninstall
You may need to uninstall the EKM provider in these scenarios:
Troubleshooting
Resolving installation or configuration issues
Upgrading
Installing a newer version of the provider
Decommissioning
Removing SQL EKM from the server
Migration
Moving to a different encryption solution
If you have encrypted databases, removing the EKM provider will prevent access to those databases unless you first decrypt them or preserve the key configuration. Decrypt first, or keep the provider, credential, and master key in place.
Prerequisites
- Backup all encrypted databases
- Document current configuration (credentials, keys, etc.)
- Administrator privileges on the server
- Verify no active encrypted databases (or plan for re-encryption)
Pre-Uninstallation Steps
Inventory Encrypted Databases
First, identify all databases protected by TDE:
SELECT
d.name AS DatabaseName,
d.is_encrypted,
dek.encryption_state,
dek.encryptor_type
FROM sys.databases d
LEFT JOIN sys.dm_database_encryption_keys dek
ON d.database_id = dek.database_id
WHERE d.is_encrypted = 1;
GODocument Configuration
Record the current provider, key, and credential details before uninstalling:
-- Document cryptographic providers
SELECT
name AS ProviderName,
guid,
is_enabled,
dll_path
FROM sys.cryptographic_providers;
GO
-- Document asymmetric keys and the provider they are bound to
USE master;
SELECT
ak.name AS KeyName,
ak.algorithm_desc,
ak.thumbprint,
cp.name AS ProviderName
FROM sys.asymmetric_keys ak
LEFT JOIN sys.cryptographic_providers cp
ON ak.cryptographic_provider_guid = cp.guid;
GO
-- Document credentials
SELECT
name AS CredentialName,
credential_identity
FROM sys.credentials
WHERE name LIKE '%Dke%' OR name LIKE '%EKM%';
GOBackup Databases
Always back up all encrypted databases before proceeding with uninstallation.
BACKUP DATABASE <DatabaseName>
TO DISK = 'C:\Backups\<DatabaseName>_PreUninstall.bak'
WITH COMPRESSION, CHECKSUM;
GOSQL Server Cleanup
Remove the SQL Server objects in this order: credential mappings, then logins, then credentials, then the asymmetric key, and finally the provider. A provider cannot be dropped while any key or credential still references it.
If any database is still encrypted, decrypt it first (see Decrypt Before Uninstalling). Dropping the master key or provider while a database is encrypted makes that database unrecoverable.
Remove Credential Mappings
Remove the credential from every login it is mapped to:
-- List logins with the EKM credential mapped
SELECT
l.name AS LoginName,
c.name AS CredentialName
FROM sys.server_principals l
INNER JOIN sys.credentials c
ON l.credential_id = c.credential_id
WHERE c.name LIKE '%Dke%';
GO
-- Drop the mappings
ALTER LOGIN [sa]
DROP CREDENTIAL DkeEkmCredential;
GO
ALTER LOGIN [TDE_Master_Login]
DROP CREDENTIAL DkeEkmCredential;
GODrop the Key Login
DROP LOGIN TDE_Master_Login;
GODrop the Credential
DROP CREDENTIAL DkeEkmCredential;
GOIf dropping the credential fails, ensure every login mapping from Step 1 has been removed first.
Drop the Asymmetric Key
USE master;
DROP ASYMMETRIC KEY TDE_Master;
GOThis removes only the SQL Server reference to the key. The key itself remains in DuoKey and can be reopened later with OPEN_EXISTING.
Drop the Cryptographic Provider
DROP CRYPTOGRAPHIC PROVIDER DkeEkm;
GOYou cannot drop a cryptographic provider while it is still referenced by an asymmetric key or credential. Complete Steps 1 to 4 first.
Remove the Provider Files
With the SQL objects gone, remove the deployed files from the host.
Stop SQL Server (if needed)
The provider library is loaded by SQL Server. If the file is locked, stop the service before deleting it.
Stop-Service MSSQLSERVERDelete the Provider Library
Remove-Item "C:\Program Files\DKE\EKM\DuoKeyCryptoProvider.dll" -Force
# Optionally remove the folder if now empty
Remove-Item "C:\Program Files\DKE\EKM" -Recurse -ForceRemove the Configuration and Runtime Files
Delete the ProgramData folder, which holds config.toml, keystore.json, and dke-ekm.log.
Remove-Item "C:\ProgramData\DKE\EKM" -Recurse -ForceKeeping databases encrypted? Do not delete keystore.json. The provider needs it to reopen TDE-protected databases after a restart.
Restart SQL Server
Start-Service MSSQLSERVERPost-Uninstallation Verification
Verify File Removal
Files to Verify Removed
If the optional HKLM\SOFTWARE\DKE\EKM key was created for advanced settings, you can remove it as well. A standard installation does not create any registry entries.
Verify SQL Server State
-- Should return no rows
SELECT name, guid, is_enabled
FROM sys.cryptographic_providers
WHERE name = 'DkeEkm';
GOHandling Encrypted Databases
Option 1: Keep Databases Encrypted
If you plan to reinstall or maintain encryption:
Keep Backups
Maintain backups of encrypted databases
Preserve the Keystore
Retain config.toml and keystore.json so the key can be reopened
Plan Reinstall
Redeploy the provider and reopen the master key when ready
Option 2: Decrypt Before Uninstalling
If you want to remove encryption entirely, decrypt every database before dropping any SQL objects or deleting files:
-- Disable TDE
ALTER DATABASE <DatabaseName>
SET ENCRYPTION OFF;
GO
-- Monitor decryption progress
SELECT
DB_NAME(database_id) AS DatabaseName,
encryption_state,
percent_complete
FROM sys.dm_database_encryption_keys;
GO
-- Wait until encryption_state = 1 (Unencrypted)
-- Drop the Database Encryption Key
USE <DatabaseName>;
DROP DATABASE ENCRYPTION KEY;
GO
-- Verify decryption
SELECT
name,
is_encrypted
FROM sys.databases
WHERE name = '<DatabaseName>';
GOTroubleshooting
Emergency Uninstallation
Emergency uninstallation may leave encrypted databases inaccessible. Only use in critical situations with proper backups.
-- Force remove references, then the provider
USE master;
DROP ASYMMETRIC KEY TDE_Master;
GO
DROP CREDENTIAL DkeEkmCredential;
GO
DROP CRYPTOGRAPHIC PROVIDER DkeEkm;
GOThen remove the provider files as described above.