Important: If you add the vault user password to the entrust.conf file, then it can be seen in trace log files. We recommend that you do not include the password and let the vault user type it in manually when they are prompted when running the script.

  1. Copy the script bundle to the first SQL Server node.

  2. Create a folder and extract the bundle. The bundle contains the following files: 

    • entrust.conf—The configuration file with some pre-populated values.

    • setup.ps1—A PowerShell script signed with the Entrust signature. Do not modify.

    • encryptclust.ps1—A PowerShell script signed with the Entrust signature. Do not modify.

    Note: The scripts use Windows authentication by default, and are executed in the context of the user who is logged in to the SQL Server VM.

  3. Edit the entrust.conf file and update the following parameters:

    • db_server_name—The name of the database server which contains the database to be encrypted.

    • sysadmin_user—Optional. If this parameter is set, then the SQL commands are run as this user instead of the user who is logged in to the SQL server VM

    • sysadmin_password—Optional. If you set the sysadmin_user, you can add the password for that user. If left blank, the user will be prompted for the password when you run the scripts.

      Note: You can also modify any pre-populated files if needed.

  4. Save the entrust.conf file.

  5. Run the setup.ps1 script as follows:

    PS> .\setup.ps1 -node first -config .\entrust.conf

    Where: 

    • -node is the node you are updating. This can be either first or other. This should be pre-populated with first.

    • -config is the name of the configuration file that you updated.If you have a second SQL Server node in your cluster, copy the script bundle to the second node and extract it.

    • This script displays the location of the Access Token file. You will need this to check the status of your connection.

  6. Copy your modified configuration file from the first node and overwrite the configuration file from the bundle.

  7. Run the setup.ps1 script as follows: 

PS> .\setup.ps1 -node other -config .\entrust.conf

Please ensure that the -node parameter is set to other.