Applies ToSQL Server 2014 Developer - duplicate (do not use) SQL Server 2014 Enterprise - duplicate (do not use) SQL Server 2014 Express - duplicate (do not use) SQL Server 2014 Standard - duplicate (do not use)

Symptoms

You create a certificate for Transparent Data Encryption (TDE) in Microsoft SQL Server 2014 Service Pack 1 (SP1). However, if you use a certificate whose serial number is greater than 16 bytes, you receive the following error message:

Msg 15297, Level 16, State 56, Line 1The certificate, asymmetric key, or private key data is invalid.

Resolution

This problem was first fixed in the following cumulative update for SQL Server:

Cumulative Update 2 for SQL Server 2014 Service Pack 1 Note After you install this update, you can create the certificate even though the serial number is greater than 16 bytes. Additionally, you will not receive the error message that's mentioned in the "Symptoms" section. However, the serial number will be truncated to 16 bytes when it's saved into the cert_serial_number column in the sys.certificates catalog view. The truncate action occurs only in catalog view. This means that the certificate still preserves the original length of the serial number.

Each new cumulative update for SQL Server contains all the hotfixes and all the security fixes that were included with the previous cumulative update. Check out the latest cumulative updates for SQL Server:

SQL Server 2014 build versions

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

References

Learn about the terminology Microsoft uses to describe software updates.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.