How to find if SQL server backup is encrypted with TDE without restoring the backup The Next CEO of Stack OverflowRestoring a backup to an older version of SQL ServerCan I recover a TDE certificate by restoring the MASTER database?How do you copy a TDE-encrypted SQL Server database using T-SQL programatically?Backup SQL Server with VMwareRestoring encrypted database on another server (using Backup Encryption)A SQL Server database backup/restore issueIs network traffic encrypted when writing remote backups using SQL Server TDE?Restore SQL Server DB encrypted by EKM - where's the asymmetric key?Always Encrypted after restoring an old database backup using C#Restoring MS SQL TDE database question

Can a PhD from a non-TU9 German university become a professor in a TU9 university?

How exploitable/balanced is this homebrew spell: Spell Permanency?

Would a grinding machine be a simple and workable propulsion system for an interplanetary spacecraft?

What did the word "leisure" mean in late 18th Century usage?

How do I keep Mac Emacs from trapping M-`?

Planeswalker Ability and Death Timing

How can I prove that a state of equilibrium is unstable?

Direct Implications Between USA and UK in Event of No-Deal Brexit

Small nick on power cord from an electric alarm clock, and copper wiring exposed but intact

Why did the Drakh emissary look so blurred in S04:E11 "Lines of Communication"?

How to pronounce fünf in 45

Can Sri Krishna be called 'a person'?

Why do we say “un seul M” and not “une seule M” even though M is a “consonne”?

Can I cast Thunderwave and be at the center of its bottom face, but not be affected by it?

What does this strange code stamp on my passport mean?

Is it a bad idea to plug the other end of ESD strap to wall ground?

pgfplots: How to draw a tangent graph below two others?

Mathematica command that allows it to read my intentions

Ising model simulation

A hang glider, sudden unexpected lift to 25,000 feet altitude, what could do this?

Is a linearly independent set whose span is dense a Schauder basis?

Does Germany produce more waste than the US?

That's an odd coin - I wonder why

What does it mean 'exit 1' for a job status after rclone sync



How to find if SQL server backup is encrypted with TDE without restoring the backup



The Next CEO of Stack OverflowRestoring a backup to an older version of SQL ServerCan I recover a TDE certificate by restoring the MASTER database?How do you copy a TDE-encrypted SQL Server database using T-SQL programatically?Backup SQL Server with VMwareRestoring encrypted database on another server (using Backup Encryption)A SQL Server database backup/restore issueIs network traffic encrypted when writing remote backups using SQL Server TDE?Restore SQL Server DB encrypted by EKM - where's the asymmetric key?Always Encrypted after restoring an old database backup using C#Restoring MS SQL TDE database question










6















Is there a way to find from the SQL Server Backup file or MSDB tables if the backup is encrypted with TDE without trying to restore the backup file?



Thanks










share|improve this question







New contributor




yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
























    6















    Is there a way to find from the SQL Server Backup file or MSDB tables if the backup is encrypted with TDE without trying to restore the backup file?



    Thanks










    share|improve this question







    New contributor




    yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.






















      6












      6








      6








      Is there a way to find from the SQL Server Backup file or MSDB tables if the backup is encrypted with TDE without trying to restore the backup file?



      Thanks










      share|improve this question







      New contributor




      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.












      Is there a way to find from the SQL Server Backup file or MSDB tables if the backup is encrypted with TDE without trying to restore the backup file?



      Thanks







      sql-server






      share|improve this question







      New contributor




      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.











      share|improve this question







      New contributor




      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      share|improve this question




      share|improve this question






      New contributor




      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked 5 hours ago









      yegnasewyegnasew

      333




      333




      New contributor




      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      yegnasew is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.




















          2 Answers
          2






          active

          oldest

          votes


















          5














          Imagine for a second that you've got a 1 terabyte database. Backing it up takes a while, and encrypting it takes a while. So imagine that:



          • 9:00 AM - you start taking a full backup

          • 9:01 AM - in another window, you start enabling TDE on the database

          • 9:05 AM - the backup completes

          • 9:10 AM - TDE completes

          What would you expect your query to return, given that as soon as you finish restoring the full backup, it's going to continue applying TDE, encrypting the rest of your database?



          Conversely, imagine that you start with an already-encrypted database, and:



          • 9:00 AM - you remove TDE (which takes some time)

          • 9:01 AM - you start a full backup

          • 9:05 AM - the data pages are no longer encrypted

          • 9:06 AM - your full backup completes

          What would you expect the query to return? These are example scenarios of why TDE encryption isn't one of the fields included in msdb.dbo.backupset.






          share|improve this answer























          • Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

            – yegnasew
            4 hours ago


















          12














          I up-voted Brent's answer, as his scenario could definitely muddy the water on whether the backup contained TDE data.



          However, if you've had TDE enabled for a while, it seems that RESTORE FILELISTONLY (Transact-SQL) might provide the information you're after. There is a column on the result set called TDEThumbprint which "Shows the thumbprint of the Database Encryption Key. The encryptor thumbprint is a SHA-1 hash of the certificate with which the key is encrypted."



          I looked at some of my backups which were both TDE encrypted and not TDE encrypted.



          The backups of my TDE databases had the certificate thumbprint in that column and the backups that did not have TDE databases had null.






          share|improve this answer


















          • 1





            +1 for answering the question

            – FreeSoftwareServers
            3 hours ago











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "182"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: false,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );






          yegnasew is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fdba.stackexchange.com%2fquestions%2f233674%2fhow-to-find-if-sql-server-backup-is-encrypted-with-tde-without-restoring-the-bac%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          2 Answers
          2






          active

          oldest

          votes








          2 Answers
          2






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          5














          Imagine for a second that you've got a 1 terabyte database. Backing it up takes a while, and encrypting it takes a while. So imagine that:



          • 9:00 AM - you start taking a full backup

          • 9:01 AM - in another window, you start enabling TDE on the database

          • 9:05 AM - the backup completes

          • 9:10 AM - TDE completes

          What would you expect your query to return, given that as soon as you finish restoring the full backup, it's going to continue applying TDE, encrypting the rest of your database?



          Conversely, imagine that you start with an already-encrypted database, and:



          • 9:00 AM - you remove TDE (which takes some time)

          • 9:01 AM - you start a full backup

          • 9:05 AM - the data pages are no longer encrypted

          • 9:06 AM - your full backup completes

          What would you expect the query to return? These are example scenarios of why TDE encryption isn't one of the fields included in msdb.dbo.backupset.






          share|improve this answer























          • Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

            – yegnasew
            4 hours ago















          5














          Imagine for a second that you've got a 1 terabyte database. Backing it up takes a while, and encrypting it takes a while. So imagine that:



          • 9:00 AM - you start taking a full backup

          • 9:01 AM - in another window, you start enabling TDE on the database

          • 9:05 AM - the backup completes

          • 9:10 AM - TDE completes

          What would you expect your query to return, given that as soon as you finish restoring the full backup, it's going to continue applying TDE, encrypting the rest of your database?



          Conversely, imagine that you start with an already-encrypted database, and:



          • 9:00 AM - you remove TDE (which takes some time)

          • 9:01 AM - you start a full backup

          • 9:05 AM - the data pages are no longer encrypted

          • 9:06 AM - your full backup completes

          What would you expect the query to return? These are example scenarios of why TDE encryption isn't one of the fields included in msdb.dbo.backupset.






          share|improve this answer























          • Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

            – yegnasew
            4 hours ago













          5












          5








          5







          Imagine for a second that you've got a 1 terabyte database. Backing it up takes a while, and encrypting it takes a while. So imagine that:



          • 9:00 AM - you start taking a full backup

          • 9:01 AM - in another window, you start enabling TDE on the database

          • 9:05 AM - the backup completes

          • 9:10 AM - TDE completes

          What would you expect your query to return, given that as soon as you finish restoring the full backup, it's going to continue applying TDE, encrypting the rest of your database?



          Conversely, imagine that you start with an already-encrypted database, and:



          • 9:00 AM - you remove TDE (which takes some time)

          • 9:01 AM - you start a full backup

          • 9:05 AM - the data pages are no longer encrypted

          • 9:06 AM - your full backup completes

          What would you expect the query to return? These are example scenarios of why TDE encryption isn't one of the fields included in msdb.dbo.backupset.






          share|improve this answer













          Imagine for a second that you've got a 1 terabyte database. Backing it up takes a while, and encrypting it takes a while. So imagine that:



          • 9:00 AM - you start taking a full backup

          • 9:01 AM - in another window, you start enabling TDE on the database

          • 9:05 AM - the backup completes

          • 9:10 AM - TDE completes

          What would you expect your query to return, given that as soon as you finish restoring the full backup, it's going to continue applying TDE, encrypting the rest of your database?



          Conversely, imagine that you start with an already-encrypted database, and:



          • 9:00 AM - you remove TDE (which takes some time)

          • 9:01 AM - you start a full backup

          • 9:05 AM - the data pages are no longer encrypted

          • 9:06 AM - your full backup completes

          What would you expect the query to return? These are example scenarios of why TDE encryption isn't one of the fields included in msdb.dbo.backupset.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered 5 hours ago









          Brent OzarBrent Ozar

          35.7k19109241




          35.7k19109241












          • Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

            – yegnasew
            4 hours ago

















          • Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

            – yegnasew
            4 hours ago
















          Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

          – yegnasew
          4 hours ago





          Thank You all for a quick response and @ScottHodgin yes I wanted to know if the backup is from a TDE database and Brent's answer made it clear.

          – yegnasew
          4 hours ago













          12














          I up-voted Brent's answer, as his scenario could definitely muddy the water on whether the backup contained TDE data.



          However, if you've had TDE enabled for a while, it seems that RESTORE FILELISTONLY (Transact-SQL) might provide the information you're after. There is a column on the result set called TDEThumbprint which "Shows the thumbprint of the Database Encryption Key. The encryptor thumbprint is a SHA-1 hash of the certificate with which the key is encrypted."



          I looked at some of my backups which were both TDE encrypted and not TDE encrypted.



          The backups of my TDE databases had the certificate thumbprint in that column and the backups that did not have TDE databases had null.






          share|improve this answer


















          • 1





            +1 for answering the question

            – FreeSoftwareServers
            3 hours ago















          12














          I up-voted Brent's answer, as his scenario could definitely muddy the water on whether the backup contained TDE data.



          However, if you've had TDE enabled for a while, it seems that RESTORE FILELISTONLY (Transact-SQL) might provide the information you're after. There is a column on the result set called TDEThumbprint which "Shows the thumbprint of the Database Encryption Key. The encryptor thumbprint is a SHA-1 hash of the certificate with which the key is encrypted."



          I looked at some of my backups which were both TDE encrypted and not TDE encrypted.



          The backups of my TDE databases had the certificate thumbprint in that column and the backups that did not have TDE databases had null.






          share|improve this answer


















          • 1





            +1 for answering the question

            – FreeSoftwareServers
            3 hours ago













          12












          12








          12







          I up-voted Brent's answer, as his scenario could definitely muddy the water on whether the backup contained TDE data.



          However, if you've had TDE enabled for a while, it seems that RESTORE FILELISTONLY (Transact-SQL) might provide the information you're after. There is a column on the result set called TDEThumbprint which "Shows the thumbprint of the Database Encryption Key. The encryptor thumbprint is a SHA-1 hash of the certificate with which the key is encrypted."



          I looked at some of my backups which were both TDE encrypted and not TDE encrypted.



          The backups of my TDE databases had the certificate thumbprint in that column and the backups that did not have TDE databases had null.






          share|improve this answer













          I up-voted Brent's answer, as his scenario could definitely muddy the water on whether the backup contained TDE data.



          However, if you've had TDE enabled for a while, it seems that RESTORE FILELISTONLY (Transact-SQL) might provide the information you're after. There is a column on the result set called TDEThumbprint which "Shows the thumbprint of the Database Encryption Key. The encryptor thumbprint is a SHA-1 hash of the certificate with which the key is encrypted."



          I looked at some of my backups which were both TDE encrypted and not TDE encrypted.



          The backups of my TDE databases had the certificate thumbprint in that column and the backups that did not have TDE databases had null.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered 4 hours ago









          Scott HodginScott Hodgin

          18.1k21635




          18.1k21635







          • 1





            +1 for answering the question

            – FreeSoftwareServers
            3 hours ago












          • 1





            +1 for answering the question

            – FreeSoftwareServers
            3 hours ago







          1




          1





          +1 for answering the question

          – FreeSoftwareServers
          3 hours ago





          +1 for answering the question

          – FreeSoftwareServers
          3 hours ago










          yegnasew is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          yegnasew is a new contributor. Be nice, and check out our Code of Conduct.












          yegnasew is a new contributor. Be nice, and check out our Code of Conduct.











          yegnasew is a new contributor. Be nice, and check out our Code of Conduct.














          Thanks for contributing an answer to Database Administrators Stack Exchange!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fdba.stackexchange.com%2fquestions%2f233674%2fhow-to-find-if-sql-server-backup-is-encrypted-with-tde-without-restoring-the-bac%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          The Calvary Singular or Plural The 2019 Stack Overflow Developer Survey Results Are InAre collective nouns always plural, or are certain ones singular?Is “audience” singular or plural?“Wasn't” vs. “weren't” in a vernacular sentence“My last couple of years” — singular or plural?Is 'rest' singular or plural?Is “all but one” singular or plural?Whether to use the singular or plural form of basis?Singular and Plural for numbersIs there a plural form of teeth?performance: plural vs singular?singular or plural nouns?Singular and Plural

          How does one intimidate enemies without having the capacity for violence?Ideas for how aliens would approach this fight?How to convey the scale of my humanoid without science or units?How does the “space drive” conserve momentum?Planet Vanishes - How does this affect the orbiting starships?How does a community of a Universe Simulator have the same language as its creator?How would US Presidential elections be affected if voters could choose the state their vote for President was counted in?How Does One Ensures the Immortality of Their ConsciousnessHow do I retain national independence while also having a one world government?How can Ganymede have an Earth-like gravity without us having realized it?How would one make a lion mount for a fantasy world?

          Output visual diagram of pictureASCII-art logic gate diagramBooks on a ShelfDetermine the Dimensions of a Rotated RectangleDraw a Houndstooth PatternDraw and label an ASCII hexagonal gridGolf me an ASCII AlphabetASCII Jigsaw PuzzleOutput a pretty boxASCII-Art Venn DiagramASCII Exact Cover with Rectangles