SqlCertForge 2.0: every certificate on SQL Server, not just the TLS binding
SqlCertForge started as a narrow tool: bind a TLS certificate to a SQL Server instance or a Reporting Services endpoint, and then check that the server actually serves the certificate you just bound, rather than trusting that the bind returned success. Seven tools, four of them free.
That narrowness was on purpose — a tool that does one thing and proves it is worth more than one that does ten things on faith. But a SQL Server keeps certificates in far more than one place, and every one of those places has the same failure mode: it works green for months, and the gap only shows up the day someone needs it. So 2.0 keeps the philosophy and widens the surface. It is now twenty tools.
Twelve things you can check for free
The read-only half grew from four tools to twelve, and it is still free with no licence. It now inventories every certificate surface on an instance in one pass — the connection binding, Reporting Services, Transparent Data Encryption, backup encryption, mirroring and Always On endpoints, Always Encrypted column master keys, cell-level encryption, and PolyBase — one row per certificate, each with its expiry.
There is no single screen in SQL Server that lists those together, because each reads differently: a registry value for the engine binding, WMI for Reporting Services, catalog views for TDE and cell-level, DMVs for the rest. The certificate that causes an outage is rarely the one anyone was watching — it is the endpoint cert on a DR replica, or the backup-encryption cert nobody remembered was set. Inventorying all of them, read-only and free, is the first honest step before any renewal or migration.
Eight things you can change, and that check their own work
The paid half grew from three tools to eight. Alongside binding the TLS certificate for the engine and Reporting Services, it now distributes client trust to the machines that need it, registers an Always Encrypted column master key against a certificate, and sets up certificate authentication on a mirroring, Always On, or Service Broker endpoint — set the endpoint, export its public certificate, grant the partner CONNECT.
Every one of those still reads its own work back. For Reporting Services that means an actual HTTPS request to the endpoint to read the served certificate’s thumbprint; for an endpoint it means reading the authentication state back from SQL Server. The evidence is the state after the change, not the return code of the command that made it.
Proven on real SQL Server, not on mocks
The part we are most willing to stand behind is that none of this was signed off on a green unit-test suite alone. Every state-changing tool was run against real SQL Server — 2022 and 2025 — on a live lab, and the richer scenarios were proven end to end: a TDE-encrypted database backed up on one instance and recovered on a second by restoring its certificate first; a certificate-authenticated mirroring session reaching SYNCHRONIZED across two nodes; a client connection that fails untrusted and then succeeds once the issuer is distributed.
Live validation is not a formality. It found six real defects that the mocked tests could not, because a mock returns what you told it to. The one we like best: SQL Server 2025 reports a TDE certificate’s type as CERTIFICATE_OAEP_256 rather than the CERTIFICATE earlier versions report, so four separate checks were quietly skipping a real, present certificate. A test that feeds itself the expected value never catches that. A real SQL Server 2025 does, immediately.
Where the line is
Two things it deliberately does not do, because being clear about them is the point. It registers and audits the Always Encrypted column master key — the certificate-backed outer key and the metadata that points to it — but it does not create the column encryption keys or encrypt the columns; that cryptography belongs to the SqlServer module. And it reports PolyBase scale-out readiness read-only; it does not manage SQL Server’s internal PolyBase certificates. An honest tool is specific about its edges.
The free read-only tools ship on the PowerShell Gallery; the paid tools run under a licence that verifies offline — no licence-server call, no phone-home, no telemetry. The full tool list, the tiers, and how it checks its own work are on the product page.