SQL2-00-024300 - Symmetric keys (other than the database master key) must use a DoD certificate to encrypt the key.

Information

Data within the database is protected by use of encryption. The symmetric keys are critical for this process. If the symmetric keys were to be compromised the data could be disclosed to unauthorized personnel.

Solution

Configure or alter symmetric keys to encrypt keys with certificates or authorized asymmetric keys.
From the query prompt:
ALTER SYMMETRIC KEY [key name] ADD ENCRYPTION BY CERTIFICATE [certificate name]
ALTER SYMMETRIC KEY [key name] DROP ENCRYPTION BY [password, symmetric key or asymmetric key]

The symmetric key must specify a certificate or asymmetric key for encryption.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_SQL_Server_2012_V1R20_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CAT|II, CCI|CCI-001199, Rule-ID|SV-53946r5_rule, STIG-ID|SQL2-00-024300, Vuln-ID|V-41417

Plugin: MS_SQLDB

Control ID: 70a9fb15ab3be20c643ab79fe561607aef8c89c781b9aa9cd70bc8575dd4d511