Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image7_sqlcertforgelogo300216x216.png

SqlCertForge

by Detent Point, LLC

Certificate lifecycle for SQL Server: TLS, TDE, Always Encrypted and more, in your own environment.

SqlCertForge manages the SQL Server certificate surface end to end. It runs inside your own environment; nothing about your certificates, servers, or configuration is transmitted anywhere. It covers connection-encryption TLS for a standalone instance or the replicas of an Always On availability group. On the database engine the configuration takes effect at the next SQL Server restart, which you schedule. It binds certificates to SQL Server Reporting Services and Power BI Report Server HTTPS endpoints, including URL reservation and a functional endpoint check that performs a real HTTPS request and confirms the served certificate is the one you intended. It handles the TDE server-certificate lifecycle (create, escrow, restore, rotate) and backup-encryption readiness, including a per-backup-file restorability check. It configures certificate authentication for database mirroring, Always On and Service Broker endpoints, registers Always Encrypted column master keys, and manages cell-level encryption keys. It also checks PolyBase readiness, distributes client trust, migrates certificates between servers, schedules renewal jobs, and produces a read-only certificate inventory across your estate. Every command returns a structured, provenance-stamped result and never throws. It uses native registry, ACL and T-SQL paths; dbatools and the SqlServer module are optional and detected at run time. An issuing certificate authority is optional. Without one, the request stage produces a signing request and stops, so third-party and manual certificate workflows are first-class, not an afterthought. Read-only audit commands are free and need no license. PLANS Read-only commands are free on every plan, including the certificate inventory and the backup-encryption and PolyBase readiness checks. A plan unlocks the state-changing commands and sets how many servers you manage. Starter covers 2 servers in active use and unlocks certificate binding for SQL Server connection encryption and Reporting Services HTTPS endpoints, client-trust distribution, and Always Encrypted column-master-key registration. Professional covers 25 servers in active use and adds the full Reporting Services certificate install, the TDE server-certificate lifecycle (create, back up, restore, rotate), cell-level encryption keys, endpoint certificate authentication, and cross-server certificate migration. Enterprise removes the server cap and adds scheduled certificate renewal jobs. The count is servers in active use over a rolling 90-day window. Running against a server you already manage never uses a second place, and a server you stop using drops off the count on its own — nothing to request, no support ticket.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image4_scf01thefloormoved1280x720.png
https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image5_scf02seewhereyoustand1280x720.png
https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image0_scf03onecommand1280x720.png
https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image8_scf04proof1280x720.png
https://catalogartifact.azureedge.net/publicartifacts/detentpoint.sqlcertforge-saas-a5e95fa3-e43e-4eba-88ac-9652199b520c/image2_scf05renewal1280x720.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies