TLS / SSL Status

Created: 2026-07-19 10:00:00 | Computer: SQL01, SQL02
Source: www.powershelldba.de | sqmSQLTool v1.9.103.0
Illustrative example. This lab's machines are workgroup, not domain-joined, so the remote registry/certificate-store check this command relies on for anything beyond the local computer cannot complete over WinRM here. Certificate subjects and thumbprints below are representative placeholders. Values below are representative, not measured output.

OK: 1 | Warning: 1 | Critical: 0

StatusComputerInstanceForceEncryptionCert SubjectCert ExpiryTrustedTLS 1.0TLS 1.1TLS 1.2TLS 1.3Details
OKSQL01MSSQLSERVER1CN=sql01.contoso.local2027-03-14 (238 days)YesDisabledDisabledEnabledEnabledAll checks passed
WarningSQL02MSSQLSERVER0CN=sql02.contoso.local2026-08-30 (41 days)YesEnabledDisabledEnabledEnabledForceEncryption = 0; TLS 1.0 enabled; cert expires in 41 days

Warning thresholds: certificate expiring within 60 days, ForceEncryption disabled, TLS 1.0/1.1 enabled, or no certificate explicitly bound (auto-generated self-signed cert in use). Critical: certificate not found in the local machine store, chain not trusted, or already expired.