A New SMK

  • Mattrick (1/6/2012)


    Steve Jones - SSC Editor (1/6/2012)


    rothj (1/6/2012)


    I got it right but I would have gotten it wrong had there been an option that it gets created automatically on sql install.

    I should have had that as an option. 😉

    You would have tripped me up with this, for sure. As it stands, I did answer this question correctly.

    Thanks and have a good weekend,

    Matt

    You would have caught me too. Not having that option let me get the point.

    Tom

  • george sibbald (1/6/2012)


    slightly crafty steve, but I got it.

    Interestingly, MS advise one of the first things you should do on installing an instance is backup the service master key, and this indeed you can do even though encryption has not been activated. So what in fact are we backing up at that point?

    I'd like to know the answer to this, also. I'm guessing it gets created when the BACKUP SERVICE MASTER KEY command gets executed?

    I got the question right because it was the only valid command.

    ----------------------------------------------------------------------------
    Sacramento SQL Server users group - http://sac.sqlpass.org
    Follow me on Twitter - @SQLDCH
    ----------------------------------------------------------------------------

    Yeah, well...The Dude abides.
  • There seem to be more sites out there that say the SMK gets created when it is needed to encrypt another key, including technet. However there are also some that say the SMK is created on install

    As there is definitely a Key available to backup immediately after install and technet says backing up the SMK should be one of the first admin functions you perform (why if its not created yet?) I am going to play it safe and presume that it is in fact created the first time SQL starts up after an install. So one of my first admin actions is to back it up.

    sites that back this up (sic)

    http://www.sql-server-performance.com/2006/encryption-2005-1/

    http://sqlblogcasts.com/blogs/martinbell/archive/2009/05/31/Service-Master-Key-Backup.aspx

    There is conflicting information out there though so it would be good if someone could nail this once and for all.

    edit: buck woody is on the side of creation on install if it helps!

    ---------------------------------------------------------------------

  • Good question. I learned something new today.

    http://brittcluff.blogspot.com/

  • Nice question, thanks.

    Need an answer? No, you need a question
    My blog at https://sqlkover.com.
    MCSE Business Intelligence - Microsoft Data Platform MVP

  • rolling

    What you don't know won't hurt you but what you know will make you plan to know better

Viewing 6 posts - 16 through 20 (of 20 total)

You must be logged in to reply to this topic. Login to reply