You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: public/New-DbaComputerCertificate.ps1
+22-4Lines changed: 22 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,8 @@ function New-DbaComputerCertificate {
6
6
.DESCRIPTION
7
7
Creates a new computer certificate - self-signed or signed by an Active Directory CA, using the Web Server certificate.
8
8
9
-
By default, a key with a length of 2048 bits and a friendly name of "SQL Server" is generated.
9
+
By default, a key with a length of 2048 bits and a friendly name of "SQL Server" is generated. The private key
10
+
is created by the legacy Microsoft RSA SChannel Cryptographic Provider unless -Provider asks for a Key Storage Provider.
10
11
11
12
This command was originally intended to help automate the process so that SSL certificates can be available for enforcing encryption on connections.
12
13
@@ -62,6 +63,12 @@ function New-DbaComputerCertificate {
62
63
Defaults to 2048 bits which meets current industry security standards for production environments.
63
64
4096 bits can be used for high-security environments, though it may slightly impact performance during SSL handshakes.
64
65
66
+
.PARAMETERProvider
67
+
Specifies the cryptographic provider that generates and holds the private key.
68
+
Defaults to "Microsoft RSA SChannel Cryptographic Provider", a legacy Cryptographic Service Provider (CSP) that creates the key with KeySpec AT_KEYEXCHANGE, which is what the Microsoft certificate requirements for SQL Server name.
69
+
Use "Microsoft Software Key Storage Provider" for a Cryptography Next Generation (CNG) key. SQL Server 2019 and later load such a key as well, and Set-DbaNetworkCertificate and Test-DbaNetworkCertificate handle both key types.
70
+
The key is generated on the machine that runs the command and travels with the PFX to a remote computer, so the provider is the same on the target.
71
+
65
72
.PARAMETERStore
66
73
Specifies the certificate store location where the certificate will be installed.
67
74
Defaults to "LocalMachine" which makes certificates available to services like SQL Server.
@@ -213,6 +220,8 @@ function New-DbaComputerCertificate {
Copy file name to clipboardExpand all lines: public/New-DbaComputerCertificateSigningRequest.ps1
+20-4Lines changed: 20 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -10,7 +10,7 @@ function New-DbaComputerCertificateSigningRequest {
10
10
11
11
Supports both standalone SQL Server instances and cluster configurations, automatically resolving FQDNs and configuring appropriate DNS entries. The generated certificates work with SQL Server's encryption features including encrypted client connections, mirroring, and backup encryption scenarios.
12
12
13
-
By default, creates RSA certificates with 2048-bit keys, the minimum the dbatools network certificate commands accept as suitable for SQL Server, though this can be raised for stronger encryption requirements. All certificates are configured as machine certificateswith the Microsoft RSA SChannel Cryptographic Provider for compatibility with SQL Server's encryption stack.
13
+
By default, creates RSA certificates with 2048-bit keys, the minimum the dbatools network certificate commands accept as suitable for SQL Server, though this can be raised for stronger encryption requirements. All certificates are configured as machine certificates, by default with the legacy Microsoft RSA SChannel Cryptographic Provider; -Provider switches the private key to the Microsoft Software Key Storage Provider.
14
14
15
15
.PARAMETERComputerName
16
16
The target computer name hosting the SQL Server instance where the certificate will be installed. Accepts multiple computer names for batch processing.
@@ -35,6 +35,11 @@ function New-DbaComputerCertificateSigningRequest {
35
35
Specifies the RSA key length in bits for the certificate. Defaults to 2048, the minimum key length Test-DbaNetworkCertificate accepts as suitable for SQL Server; 4096 is possible for stronger requirements.
36
36
Higher key lengths provide stronger encryption but may impact SQL Server connection performance on older hardware.
37
37
38
+
.PARAMETERProvider
39
+
Specifies the cryptographic provider that generates and holds the private key of the request.
40
+
Defaults to "Microsoft RSA SChannel Cryptographic Provider", a legacy Cryptographic Service Provider (CSP) that creates the key with KeySpec AT_KEYEXCHANGE, which is what the Microsoft certificate requirements for SQL Server name.
41
+
Use "Microsoft Software Key Storage Provider" for a Cryptography Next Generation (CNG) key. SQL Server 2019 and later load such a key as well, and Set-DbaNetworkCertificate and Test-DbaNetworkCertificate handle both key types.
42
+
38
43
.PARAMETERDns
39
44
Additional DNS names to include in the certificate's Subject Alternative Name (SAN) field. By default includes both short and FQDN names.
40
45
Add extra DNS entries here if clients connect using aliases, load balancer names, or other DNS records that point to your SQL Server instance.
@@ -109,6 +114,8 @@ function New-DbaComputerCertificateSigningRequest {
0 commit comments