Creating Asymmetric Key with Key Version Enabled
To create an Asymmetric Key with Key Version enabled, you need to run the following command:
For example:
Note
To enable the key versioning while creating an asymetric key, you need to add a suffix '#' to the key name as shown in the above example.
Warning
It is recommended not to delete the intermediate keys. If the intermediate keys are deleted, the DB will go into recovery mode
and you will not be able to restore the backup of the database.
To fetch a specific version of the Key from CipherTrust Manager, you need to run the following command:
Note
Here, version
is the specific version no. of a Key to be fetched from the CipherTrust Manager.
For example:
If you increase the version of a versioned key on CipherTrust Manager, you must reboot the sql server instance to encrypt the DB with latest version of key.