Once the Database Mirroring is configured, one or more Utimaco HSMs can be used along with internal/external keystore. For the illustration purpose one HSM is configured in this SQL Server Database Mirroring configuration.
To configure EKM Provider on the cluster nodes, refer section Enable Extensible Key Management
The Keys can be used from internal keystore or the external keystore, for creating keys refer section Creating Keys
RSA algorithm is not supported in FIPS mode.
-
On Principal Server Instance use the Mirrored Database for creating keys using Utimaco HSMs.
-
Create an asymmetric key in the TestDB1 database.
|
SQL Statement |
|
SQL
|
-
Insert the data into the table
|
SQL Statement |
|
SQL
|
-
The Key and the Database is created in the Principal Server using Utimaco HSM. This data gets synchronized automatically in Mirror Server.