1. Ensure that you are running on the active node for the database that you intend to encrypt. You can do this by checking the Windows Failover Cluster Manager or the SQL Server Management Studio.

  2. Encrypt the database using the following script: 

    PS> .\encryptclust.ps1 -database <my_test_db> -config .\entrust.conf

    Where -database is the name of the database to be encrypted and -config is the configuration file.

  3. Check the keys and the encryption state of the database as follows: 

    Copy
    use master
    GO

    SELECT DB_NAME(database_id) AS DatabaseName,encryption_state,percent_complete,encryptor_thumbprint, encryptor_type FROM sys.dm_database_encryption_keys
    GO

    Select * from sys.dm_database_encryption_keys
    Select * from sys.asymmetric_keys
    GO

    Note: The SQL key thumbprint is the same as the Cryptographic Security Platform Vault KEY ID.