Skip to main content
Question

Setp up TLS connection between sql agents

  • October 2, 2026
  • 1 reply
  • 20 views

Forum|alt.badge.img+17

Hello,

We are currently investigating whether Commvault SQL Server Agent supports connecting to Microsoft SQL Server using TLS with TDS 8.0 and Strict Encryption.

Our environment is configured according to Microsoft's guidance for SQL Server strict encryption:

  • SQL Server is configured with a valid trusted certificate.
  • TDS 8.0 is enabled.
  • Strict Encryption is enabled.
  • Connections using SQL Server Management Studio (SSMS) work successfully.
  • Connections using PowerShell also work successfully.

Reference: Connect to SQL Server with strict encryption

What we would like to know is:

  1. Does Commvault SQL Server Agent support connections using TDS 8.0?
  2. Does Commvault support Strict Encryption in the same way as SSMS and modern Microsoft SQL drivers?
  3. Which SQL client/driver version is used by Commvault when connecting to protected SQL Server instances?
  4. Is there any Commvault-specific configuration required to enable encrypted SQL Agent connections?
  5. Has anyone successfully protected SQL Servers that are configured for TDS 8.0 + Strict Encryption only?

We can successfully connect using Microsoft tools, but we would like to verify whether Commvault can establish the same encrypted connection before enabling this configuration in production.

Any information or experience would be greatly appreciated.

Thank you.

1 reply

Forum|alt.badge.img+17
  • Author
  • Explorer
  • October 2, 2026

Additionaal information what i did already,

 

On SQL server >  Protocools for MSSQLSERVER Propertiers> Force Encryption = YES and Force Strict Encryption = YES

On Commvault SQL agent i added 3 settings:

nCSDBConnectionOptions, nCloudDBConnectionOptions, nDM2DBConnectionOptions) set to Type: INTEGER, Value: 3, 

After restaring commvault services on SQL server i started sql backup. But i am getting error about user dont have SYSADMIN ROLE, but that not correct.