{"id":47,"date":"2018-10-25T10:24:40","date_gmt":"2018-10-25T09:24:40","guid":{"rendered":"http:\/\/fomas.be\/blog\/?p=47"},"modified":"2018-10-25T10:24:40","modified_gmt":"2018-10-25T09:24:40","slug":"gmsa-and-ssl-in-sql-a-true-journey","status":"publish","type":"post","link":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/","title":{"rendered":"gMSA and SSL in SQL, a true journey"},"content":{"rendered":"<!-- google_ad_section_start --><h2>Info<\/h2>\n<p>Lately when I set up a Microsoft SQL server I&#8217;ll always implement SSL and a gMSA account to run SQL from.<br \/>\nWhy? Convince yourself reading <a href=\"https:\/\/hybridcloudexperts.be\/index.php\/2018\/02\/13\/how-to-prevent-man-in-the-middle-sql-injection-attacks\/\">this blog post.<\/a><\/p>\n<p>Because this post focuses on a specific issue, I&#8217;ll not explain implementing SSL as such. Here&#8217;s the Microsoft documentation I follow for my implementations:<br \/>\n<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/316898\/how-to-enable-ssl-encryption-for-an-instance-of-sql-server-by-using-mi\">https:\/\/support.microsoft.com\/en-us\/help\/316898\/how-to-enable-ssl-encryption-for-an-instance-of-sql-server-by-using-mi<\/a><br \/>\nThis is initially made for SQL 2000, but all buttons and clicks are still the same.<\/p>\n<p>However, the first time I&#8217;ve tried combining a gMSA for SQL and configure SSL, SQL wouldn&#8217;t start anymore.<\/p>\n<h2>The problem<\/h2>\n<p>Windows and SQL were friendly enough to provide me with some error messages:<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"48\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/error-windows\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=1105%2C199\" data-orig-size=\"1105,199\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Error-Windows\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=300%2C54\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=680%2C122\" class=\"alignnone wp-image-48 size-large\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?resize=680%2C122\" alt=\"\" width=\"680\" height=\"122\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?resize=1024%2C184 1024w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?resize=300%2C54 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?resize=768%2C138 768w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?w=1105 1105w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"49\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/error-sql\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?fit=1422%2C522\" data-orig-size=\"1422,522\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Error-SQL\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?fit=300%2C110\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?fit=680%2C250\" class=\"alignnone wp-image-49 size-large\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?resize=680%2C250\" alt=\"\" width=\"680\" height=\"250\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?resize=1024%2C376 1024w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?resize=300%2C110 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?resize=768%2C282 768w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?resize=1380%2C507 1380w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-SQL.jpg?w=1422 1422w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p>The error number &#8216;0x80009030d&#8217; suggested (according to a search on Google) an issue with the &#8216;common name&#8217; used in my certificate.<\/p>\n<p>In my troubleshooting process I&#8217;ve tried the following:<\/p>\n<ul>\n<li>Remove the SSL configuration from SQL: SQL started<\/li>\n<li>Tried a whole bunch of certificates since the suggestion the &#8216;common name&#8217; in the certificate was wrong.<\/li>\n<li>Grant the gMSA account the Windows Administrator role: SQL started with SSL configuration.<\/li>\n<\/ul>\n<p>After this last step I&#8217;ve concluded that the issue must be rights related. Which was actually a good thing. Rights can be added, I knew where to look.<br \/>\nA few troubleshooting hours later I came up with the solution.<\/p>\n<h2>Solution<\/h2>\n<p>Here&#8217;s what you need to do:<br \/>\nGive the gMSA account read acces on the private key of your certificate stored in the certificate store of the computer account.<\/p>\n<p>Here&#8217;s how you do it:<br \/>\n1. Open the certificate store for the local computer (when logged in to the SQL server):<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"51\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc1\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?fit=1145%2C641\" data-orig-size=\"1145,641\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc1\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?fit=300%2C168\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?fit=680%2C381\" class=\"alignnone wp-image-51 size-large\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?resize=680%2C381\" alt=\"\" width=\"680\" height=\"381\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?resize=1024%2C573 1024w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?resize=300%2C168 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?resize=768%2C430 768w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc1.jpg?w=1145 1145w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"52\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc2\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?fit=650%2C486\" data-orig-size=\"650,486\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc2\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?fit=300%2C224\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?fit=650%2C486\" class=\"alignnone size-medium wp-image-52\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?resize=300%2C224\" alt=\"\" width=\"300\" height=\"224\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?resize=300%2C224 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc2.jpg?w=650 650w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>2. Browse to the certificate you&#8217;ve imported to use for SSL encryption on SQL<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"53\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc3\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?fit=836%2C190\" data-orig-size=\"836,190\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc3\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?fit=300%2C68\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?fit=680%2C155\" class=\"alignnone wp-image-53 size-full\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?resize=680%2C155\" alt=\"\" width=\"680\" height=\"155\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?w=836 836w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?resize=300%2C68 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc3.jpg?resize=768%2C175 768w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p>3. Open the &#8216;Manage Private Keys&#8217; menu by right-clicking the certificate<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"54\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc4\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?fit=835%2C388\" data-orig-size=\"835,388\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc4\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?fit=300%2C139\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?fit=680%2C316\" class=\"alignnone size-full wp-image-54\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?resize=680%2C316\" alt=\"\" width=\"680\" height=\"316\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?w=835 835w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?resize=300%2C139 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc4.jpg?resize=768%2C357 768w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p>4. Click Add and make sure you select &#8216;Service Accounts&#8217; in the &#8216;Object Types&#8217; box<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"55\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc5\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?fit=452%2C286\" data-orig-size=\"452,286\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc5\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?fit=300%2C190\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?fit=452%2C286\" class=\"alignnone size-full wp-image-55\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?resize=452%2C286\" alt=\"\" width=\"452\" height=\"286\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?w=452 452w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc5.jpg?resize=300%2C190 300w\" sizes=\"(max-width: 452px) 100vw, 452px\" \/><\/a><br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"56\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc6\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?fit=619%2C367\" data-orig-size=\"619,367\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc6\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?fit=300%2C178\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?fit=619%2C367\" class=\"alignnone size-full wp-image-56\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?resize=619%2C367\" alt=\"\" width=\"619\" height=\"367\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?w=619 619w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc6.jpg?resize=300%2C178 300w\" sizes=\"(max-width: 619px) 100vw, 619px\" \/><\/a><\/p>\n<p>5. Add your gMSA account and give it the read rights<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"57\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc7\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?fit=574%2C300\" data-orig-size=\"574,300\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc7\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?fit=300%2C157\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?fit=574%2C300\" class=\"alignnone size-full wp-image-57\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?resize=574%2C300\" alt=\"\" width=\"574\" height=\"300\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?w=574 574w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc7.jpg?resize=300%2C157 300w\" sizes=\"(max-width: 574px) 100vw, 574px\" \/><\/a> <a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"58\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/mmc8\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?fit=443%2C500\" data-orig-size=\"443,500\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mmc8\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?fit=266%2C300\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?fit=443%2C500\" class=\"alignnone size-full wp-image-58\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?resize=443%2C500\" alt=\"\" width=\"443\" height=\"500\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?w=443 443w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/mmc8.jpg?resize=266%2C300 266w\" sizes=\"(max-width: 443px) 100vw, 443px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>After that you are good to go and SQL should launch and load the certificate:<br \/>\n<a href=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"59\" data-permalink=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/good-sql\/\" data-orig-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?fit=1344%2C405\" data-orig-size=\"1344,405\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Good-SQL\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?fit=300%2C90\" data-large-file=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?fit=680%2C205\" class=\"alignnone size-large wp-image-59\" src=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?resize=680%2C205\" alt=\"\" width=\"680\" height=\"205\" srcset=\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?resize=1024%2C309 1024w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?resize=300%2C90 300w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?resize=768%2C231 768w, https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Good-SQL.jpg?w=1344 1344w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Enjoy your secure connections and all nights without worrying that accompany it&#8230;<\/p>\n<h2>Addendum<\/h2>\n<p>If you like some extra reading material on how to use gMSA accounts:<br \/>\n<a href=\"https:\/\/blogs.msdn.microsoft.com\/markweberblog\/2016\/05\/25\/group-managed-service-accounts-gmsa-and-sql-server-2016\/\">https:\/\/blogs.msdn.microsoft.com\/markweberblog\/2016\/05\/25\/group-managed-service-accounts-gmsa-and-sql-server-2016\/<\/a><\/p>\n<!-- google_ad_section_end -->","protected":false},"excerpt":{"rendered":"<p>Info Lately when I set up a Microsoft SQL server I&#8217;ll always implement SSL and a gMSA account to run SQL from. Why? Convince yourself reading this blog post. Because this post focuses on a specific issue, I&#8217;ll not explain implementing SSL as such. Here&#8217;s the Microsoft documentation I follow for my implementations: https:\/\/support.microsoft.com\/en-us\/help\/316898\/how-to-enable-ssl-encryption-for-an-instance-of-sql-server-by-using-mi This&hellip;<a href=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\">Read more <span class=\"screen-reader-text\">gMSA and SSL in SQL, a true journey<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[2,5],"tags":[9,8,7,6],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>gMSA and SSL in SQL, a true journey - @F0mix<\/title>\n<meta name=\"description\" content=\"The catch when configuring SSL on a SQL instance running with a gMSA account\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"gMSA and SSL in SQL, a true journey - @F0mix\" \/>\n<meta property=\"og:description\" content=\"The catch when configuring SSL on a SQL instance running with a gMSA account\" \/>\n<meta property=\"og:url\" content=\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\" \/>\n<meta property=\"og:site_name\" content=\"@F0mix\" \/>\n<meta property=\"article:published_time\" content=\"2018-10-25T09:24:40+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows-1024x184.jpg\" \/>\n<meta name=\"author\" content=\"fomas\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"fomas\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\",\"url\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\",\"name\":\"gMSA and SSL in SQL, a true journey - @F0mix\",\"isPartOf\":{\"@id\":\"http:\/\/fomas.be\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage\"},\"image\":{\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows-1024x184.jpg\",\"datePublished\":\"2018-10-25T09:24:40+00:00\",\"author\":{\"@id\":\"http:\/\/fomas.be\/blog\/#\/schema\/person\/d25a64d374776dd775ddf2827081d52b\"},\"description\":\"The catch when configuring SSL on a SQL instance running with a gMSA account\",\"breadcrumb\":{\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage\",\"url\":\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=1105%2C199\",\"contentUrl\":\"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=1105%2C199\",\"width\":1105,\"height\":199},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\/\/fomas.be\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"gMSA and SSL in SQL, a true journey\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/fomas.be\/blog\/#website\",\"url\":\"http:\/\/fomas.be\/blog\/\",\"name\":\"@F0mix\",\"description\":\"Passion for SQL and POSH\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/fomas.be\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"http:\/\/fomas.be\/blog\/#\/schema\/person\/d25a64d374776dd775ddf2827081d52b\",\"name\":\"fomas\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/fomas.be\/blog\/#\/schema\/person\/image\/\",\"url\":\"http:\/\/2.gravatar.com\/avatar\/52f3d103e5bf09db931859e978d97df9?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/2.gravatar.com\/avatar\/52f3d103e5bf09db931859e978d97df9?s=96&d=mm&r=g\",\"caption\":\"fomas\"},\"url\":\"http:\/\/fomas.be\/blog\/author\/fomas\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"gMSA and SSL in SQL, a true journey - @F0mix","description":"The catch when configuring SSL on a SQL instance running with a gMSA account","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/","og_locale":"en_US","og_type":"article","og_title":"gMSA and SSL in SQL, a true journey - @F0mix","og_description":"The catch when configuring SSL on a SQL instance running with a gMSA account","og_url":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/","og_site_name":"@F0mix","article_published_time":"2018-10-25T09:24:40+00:00","og_image":[{"url":"http:\/\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows-1024x184.jpg","type":"","width":"","height":""}],"author":"fomas","twitter_card":"summary_large_image","twitter_misc":{"Written by":"fomas","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/","url":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/","name":"gMSA and SSL in SQL, a true journey - @F0mix","isPartOf":{"@id":"http:\/\/fomas.be\/blog\/#website"},"primaryImageOfPage":{"@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage"},"image":{"@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage"},"thumbnailUrl":"http:\/\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows-1024x184.jpg","datePublished":"2018-10-25T09:24:40+00:00","author":{"@id":"http:\/\/fomas.be\/blog\/#\/schema\/person\/d25a64d374776dd775ddf2827081d52b"},"description":"The catch when configuring SSL on a SQL instance running with a gMSA account","breadcrumb":{"@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#primaryimage","url":"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=1105%2C199","contentUrl":"https:\/\/i0.wp.com\/fomas.be\/blog\/wp-content\/uploads\/2018\/10\/Error-Windows.jpg?fit=1105%2C199","width":1105,"height":199},{"@type":"BreadcrumbList","@id":"http:\/\/fomas.be\/blog\/2018\/10\/25\/gmsa-and-ssl-in-sql-a-true-journey\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/fomas.be\/blog\/"},{"@type":"ListItem","position":2,"name":"gMSA and SSL in SQL, a true journey"}]},{"@type":"WebSite","@id":"http:\/\/fomas.be\/blog\/#website","url":"http:\/\/fomas.be\/blog\/","name":"@F0mix","description":"Passion for SQL and POSH","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/fomas.be\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"http:\/\/fomas.be\/blog\/#\/schema\/person\/d25a64d374776dd775ddf2827081d52b","name":"fomas","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/fomas.be\/blog\/#\/schema\/person\/image\/","url":"http:\/\/2.gravatar.com\/avatar\/52f3d103e5bf09db931859e978d97df9?s=96&d=mm&r=g","contentUrl":"http:\/\/2.gravatar.com\/avatar\/52f3d103e5bf09db931859e978d97df9?s=96&d=mm&r=g","caption":"fomas"},"url":"http:\/\/fomas.be\/blog\/author\/fomas\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p7bTMw-L","jetpack-related-posts":[],"_links":{"self":[{"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/posts\/47"}],"collection":[{"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/comments?post=47"}],"version-history":[{"count":6,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/posts\/47\/revisions"}],"predecessor-version":[{"id":65,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/posts\/47\/revisions\/65"}],"wp:attachment":[{"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/media?parent=47"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/categories?post=47"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/fomas.be\/blog\/wp-json\/wp\/v2\/tags?post=47"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}