Aug 24 2020 02:45 PM
Hello,
I am running into an issue regarding restoring a TDE database and I just keep getting the "thumbprint not found error". I don't know what's causing it. Here are some details. I'm hoping someone can help me.
I have many TDE databases running in an instance of SQL Server.
TDE certificate expired
Created a new TDE Cert with future expiry date
Backed up the new TDE Cert
Rotated two db's to use the new TDE Cert
Ran BACKUP DATABASE ph*** (the one starts with ph)
Uploaded the new TDE Cert to Azure
See attached screenshots as a reference. First screenshot shows the TDE cert's I have on my server (one expired and one new). Second screenshot shows three databases with two rotated to use the new cert. and their thumbprints. Third screenshot shows the error when I tried to restore the TDE database using the new cert. The thumbprint it complains is actually the old expired TDE cert. You can clearly see from the screenshot that the database name starting with "ph" has a new thumbprint and that thumbprint starts with "0x4733". The expired TDE starts with "0x90D". Here's my question: why is it still looking for the old thumbprint when I tried to restore it in Azure? If I create a brand new
database on the server, enable tde to use the new cert, do a backup, take this backup to Azure and restore it, it works PERFECTLY!!
Can someone explain what I'm doing wrong and how to fix it?
Thank you
Aug 25 2020 04:18 PM
Anyone? Looking for some help ...