Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 33111

Error 33111: Cannot Find Server Certificate When Restoring a TDE Backup

11 min read Updated October 5, 2026 SQL Server

Fix it now

The instance cannot find the certificate that protected this backup, and the message names the thumbprint it is looking for. The backup file is intact; what is missing is the key material. Create a database master key on the target, create the certificate there from its exported files, and the restore then behaves like any other.

Run the first block on the source instance and the second on the target, then restore normally

-- On the SOURCE instance
BACKUP CERTIFICATE TDECert TO FILE = N'D:\keys\TDECert.cer'
  WITH PRIVATE KEY (FILE = N'D:\keys\TDECert.pvk', ENCRYPTION BY PASSWORD = '<strong password>');

-- On the TARGET instance
USE master;
CREATE MASTER KEY ENCRYPTION BY PASSWORD = '<different strong password>';

CREATE CERTIFICATE TDECert FROM FILE = N'D:\keys\TDECert.cer'
  WITH PRIVATE KEY (FILE = N'D:\keys\TDECert.pvk', DECRYPTION BY PASSWORD = '<the password used above>');
  1. Find the certificate the database uses: SELECT DB_NAME(database_id) AS db, encryption_state, encryptor_thumbprint FROM sys.dm_database_encryption_keys; and match it in SELECT name, thumbprint FROM sys.certificates;
  2. Copy both files to the target over a path you trust, and put them where the SQL Server service account can read them. The engine opens them, not your session.
  3. Confirm the thumbprint from the error now appears on the target before restoring anything.
  4. Restore the database normally. No restore option overrides a missing certificate, so there is nothing else to try.

If the certificate and its private key are lost, an encrypted backup cannot be read by anyone, including Microsoft. There is no recovery route and no support case that changes that.

If the restore completes and the database is online, you are done. If it fails on the master key or the certificate files, the next section covers each link in the chain.

Why it happens

Encryption here is a chain rather than a single key. The service master key protects the database master key in master; the database master key protects the certificate; the certificate protects the database encryption key that lives inside the user database; and that key encrypts the data and everything written out of it, including backups. A backup of an encrypted database is therefore encrypted with a key you cannot use unless you also hold the certificate above it.

That is why moving the .bak file alone never works, and why no restore option exists to override it. The target needs its own database master key in master, and the same certificate created from the exported file with its private key attached. Microsoft’s documented procedure for moving a TDE-protected database says exactly this: create a database master key on the destination instance, then recreate the server certificate from the backup files, then bring the database across.

Each neighbouring code sits at one link in that chain. 33111 is the top of it: cannot find the server certificate with the named thumbprint. 15581 is the master database saying you must create a master key, or open the one you have, before this operation can proceed. 15208 says the certificate, asymmetric key or private key file is not valid, does not exist, or you do not have permissions for it. 33101 is the most specific of the four: the object cannot be used because its private key is not present or is not protected by the database master key, and SQL Server requires the ability to open that private key automatically.

The certificate was never moved to the target

You have this one if 33111 names a thumbprint that does not appear in sys.certificates on the target instance.

  1. Compare thumbprints on both instances: SELECT name, thumbprint FROM sys.certificates;
  2. Export from the source with BACKUP CERTIFICATE and its private key, using the syntax above.
  3. Create it on the target from those files and confirm the thumbprint now matches the one in the error.
  4. Retry the restore.

Creating a new certificate with the same name is not the same certificate. Only the exported private key can decrypt an existing backup, and the thumbprint is how you prove you have the right one.

The target has no database master key

You have this one if 15581 when you try to create the certificate, rather than when you restore.

  1. Check: SELECT is_master_key_encrypted_by_server FROM sys.databases WHERE name = 'master';
  2. Create one if absent: USE master; CREATE MASTER KEY ENCRYPTION BY PASSWORD = '<strong password>';
  3. Record that password with your other recovery material, then create the certificate and restore.

The master key exists but cannot be opened automatically

You have this one if 15581 on an instance that already has a database master key, and a TDE database that will not recover after a restart.

  1. Run SELECT is_master_key_encrypted_by_server FROM sys.databases WHERE name = 'master'; A result of 0 is the finding.
  2. That means ALTER MASTER KEY DROP ENCRYPTION BY SERVICE MASTER KEY has been run at some point, so the key must be opened by hand on every session – which is impossible on a system session.
  3. Restore automatic decryption: USE master; OPEN MASTER KEY DECRYPTION BY PASSWORD = '<password>'; ALTER MASTER KEY ADD ENCRYPTION BY SERVICE MASTER KEY;
  4. Take the database offline and back online, and confirm it recovers.

Microsoft documents a distinctive symptom for this state: the instance can appear unresponsive, with LogWriter threads and data modifications waiting indefinitely on WRITELOG.

The certificate files cannot be read, or the password is wrong

You have this one if 15208 when creating the certificate on the target.

  1. Confirm both files copied completely and that the .pvk is present, not only the .cer.
  2. Check the password. It is the one used at BACKUP CERTIFICATE time, and it is case sensitive.
  3. Copy the files to a local path on the server and grant the SQL Server service account read access. The engine opens them, not your session.

The certificate is there but its private key is not usable

You have this one if 33101, or the database restores and does not come online with a usable encryption key.

  1. Read the message literally: the private key is not present, or it is not protected by the database master key.
  2. Confirm the certificate was created with its private key. A certificate imported from a .cer alone can verify but not decrypt.
  3. Confirm the thumbprint matches encryptor_thumbprint in sys.dm_database_encryption_keys.
  4. If the source used an asymmetric key in an external key store rather than a certificate, configure that provider on the target first.

Full reference

The chain of keys, top to bottom

Level Protected by Lives in
Service master key The Windows Data Protection API on that machine The instance
Database master key The service master key, or a password master
Certificate or asymmetric key The database master key master
Database encryption key The certificate or asymmetric key The user database
Data and backups The database encryption key The files themselves

Every link has to be present on the target for the one below it to be usable, which is why the order in the fix section is not optional. Create the master key, then the certificate, then restore.

What each error is complaining about

Code Published meaning
33111 Cannot find server certificate with the named thumbprint
15581 Please create a master key in the database, or open the master key in the session, before performing this operation
15208 The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permissions for it
33101 Cannot use the object because its private key is not present or it is not protected by the database master key. SQL Server requires the ability to automatically access the private key

Editions that can host an encrypted database

This is worth checking before you spend an afternoon on key material, because no amount of certificate handling fixes an edition that cannot host the database. Transparent Data Encryption is available in Enterprise and Standard editions in SQL Server 2019, 2022 and 2025. It is not available in Web or in Express. If the target is Express, the restore will not succeed however correct your keys are.

If you only need the data rather than the encryption, restore onto an instance that supports TDE, turn encryption off there, and take a fresh unencrypted backup to move onwards. That is a supported route and it is usually faster than arguing about the target.

Protecting yourself before the next restore

  1. Back up the certificate the moment you enable encryption, with its private key, and record the password.
  2. Store the certificate file and the password in different places. A file and its password in the same folder is one compromise away from useless.
  3. Test the restore on another instance before you rely on it. A certificate you have never imported is an assumption.
  4. Back up the certificate again whenever it is rotated or replaced.
  5. Include both the file and the password in whatever process protects your disaster recovery material, and check that process knows they exist.

Confirming the whole chain works

The strongest test is not that the restore completed. It is that the restored database is genuinely encrypted and readable on the target, which you can see in one query: SELECT DB_NAME(database_id), encryption_state FROM sys.dm_database_encryption_keys; where 3 means encrypted. Follow it with a fresh backup on the target and a test restore elsewhere, and you have proved the certificate, the master key and the encryption key all travel together.

When a licence is the actual fix

Most 33111 cases are solved by moving a certificate, which costs nothing. The exception is a target instance whose edition cannot host an encrypted database at all: no key handling fixes that, and the restore keeps failing until the instance runs an edition that supports Transparent Data Encryption. That is a lower bar than people expect. TDE is available in Standard as well as Enterprise in SQL Server 2019, 2022 and 2025, so Standard is normally the right answer and Enterprise is only warranted if you need the wider Enterprise feature set for other reasons. Arco supplies SQL Server 2025 Enterprise in two-core packs, and will tell you plainly if Standard covers your case instead.

Every code this article covers

Code What it points at Source
33111 Cannot find server certificate with the thumbprint recorded in the backup Microsoft Learn
15581 Please create a master key in the database or open the master key in the session before performing this operation Microsoft Learn
15208 The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permissions for it Microsoft Learn
33101 Cannot use the object because its private key is not present or it is not protected by the database master key. SQL Server needs to open that private key automatically Microsoft Learn

Confirm the fix worked

  1. Confirm the thumbprint from the error now appears in SELECT name, thumbprint FROM sys.certificates; on the target.
  2. Complete the restore and confirm the database is online: SELECT name, state_desc FROM sys.databases;
  3. Check the encryption state: SELECT DB_NAME(database_id), encryption_state FROM sys.dm_database_encryption_keys; where 3 means encrypted.
  4. Confirm SELECT is_master_key_encrypted_by_server FROM sys.databases WHERE name = 'master'; returns 1, so the key opens automatically after a restart.
  5. Take a fresh backup on the target and test-restore it elsewhere, to prove the whole key chain is in place.

Questions people ask about this

Do I need Enterprise edition to use TDE?

No. Transparent Data Encryption is available in Standard as well as Enterprise in SQL Server 2019, 2022 and 2025. Web and Express do not offer it. Check what the target instance is actually running before assuming you need to buy anything.

Can I recover the backup if the certificate is gone?

No. That is the point of encryption, and there is no back door, no support route and no tool that recovers it. If the certificate and private key are truly lost, so is the backup.

My master key exists and I still get 15581. Why?

Check is_master_key_encrypted_by_server for master. If it returns 0, someone has run ALTER MASTER KEY DROP ENCRYPTION BY SERVICE MASTER KEY, so the key has to be opened by hand on every session and cannot be opened on a system session at all. Restore automatic decryption with OPEN MASTER KEY followed by ALTER MASTER KEY ADD ENCRYPTION BY SERVICE MASTER KEY.

How often should I back up the certificate?

Once, when you create it, and again any time it is rotated or replaced. Store the file and its password separately, and include both in whatever process protects your disaster recovery material.

Does the certificate need the same name on the target?

No. The thumbprint identifies it, not the name. Keeping names consistent is still worth doing so scripts and documentation stay readable.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Error 20598: The Row Was Not Found at the Subscriber When Applying Commands License Error Error 18401 and 17187: SQL Server Is Not Ready to Accept Connections Free Fix Error 15023 and Orphaned Users: Fixing SID Mismatches After a Restore License Error Error 701: Insufficient System Memory on a Memory-Capped SQL Server Edition
โ† Back to Knowledge Base