Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Enhance your career with this limited time 50% discount on Fabric and Power BI exams. Ends August 31st. Request your voucher.

Reply
shaky1289
New Member

Get server private key in Fabric

Hello all

 

As part of my day to day work, I often decrypt network traffic to get more information on the packets being transmitted. As of today, I am working with the SQL endpoint of a Lakehouse and trying to connect to the same via my client application. Since, the SQL endpoint is TDS compliant, I am trying to decrypt the TDS packets.

 

  • I tried the usual method of setting the SSLKEYLOG file path. However, it doesn't seem to work in this case. Any idea why and what can be done about this?
  • The second option for me is to somehow retrieve the private key of the server and use that to decrypt the traffic. Can you please let me know how to obtain the same here?

 

Regards

Abhishek

4 REPLIES 4
v-prasare
Community Support
Community Support

Hi @shaky1289,

May I ask if you have resolved this issue? please provide helpful answer here. This will be helpful for other community members who have similar problems to solve it faster.
If we don’t hear back, we’ll go ahead and close this thread. For any further discussions or questions, please start a new thread in the Microsoft Fabric Community Forum we’ll be happy to assist.
Thank you for being part of the Microsoft Fabric Community.

v-prasare
Community Support
Community Support

We would like to confirm if our comminity members answer resolves your query or if you need further help. If you still have any questions or need more support, please feel free to let us know. We are happy to help you.

 

Thank you for your patience and look forward to hearing from you.
Best Regards,
Prashanth Are

 

v-prasare
Community Support
Community Support

hi @shaky1289,

We would like to confirm if our comminity members answer resolves your query or if you need further help. If you still have any questions or need more support, please feel free to let us know. We are happy to help you.

 

Thank you for your patience and look forward to hearing from you.
Best Regards,
Prashanth Are

 

Vinodh247
Resolver IV
Resolver IV

You cannot retrieve the server’s private key in Microsoft Fabric, and you should not be able to, this is by design for strong security and tenant isolation.

 

SSLKEYLOGFILE Method Not Working

The SSLKEYLOGFILE env variable works only if you control the client (like browsers, curl, or custom OpenSSL-based clients). It logs pre-master secrets so tools like Wireshark can decrypt TLS.

 

In your case:

  • You are connecting to Fabric’s SQL endpoint, which is a fully managed PaaS service.
  • The SQL endpoint runs over TLS using TDS, and you do not control the Fabric server-side process. Hence, the server will never log session keys for you.

Also, Microsoft Fabric’s SQL endpoint likely terminates TLS at an azure managed reverse proxy or gateway, which is out of your control.

Getting the Server Private Key is not Possible

You asked about retrieving the private key:

  • The PK of a Fabric Lakehouse SQL endpoint is never exposed to users, by design.
  • Microsoft uses azure certificates, managed by internal Key Vaults, and private keys are hardware-backed or in secure enclaves.
  • Even Microsoft employees cannot access these keys directly, this is a core part of azure’s secure infrastructure.

So no, you cannot and should not expect to retrieve the server private key.

 

As a workaround, you can try:

 

Enable Query Logging / Diagnostic Logs

Instead of decrypting network traffic:

  • Use Fabric diagnostic settings to enable query logging and monitoring.
  • Use Log Analytics or Monitor to inspect query activity.
  • If your goal is to inspect SQL queries or performance, logging is more stable and supported.

(OR)

 

Use Azure Network Packet Capture (if VM-based)

If this was your own hosted SQL server (like Azure VM or container), you could:

  • Capture traffic using Azure Network Watcher or tcpdump.
  • Configure your own TLS cert (e.g., self-signed) so you have access to the private key.
  • This does not apply to Microsoft Fabric endpoints.


Please 'Kudos' and 'Accept as Solution' if this answered your query.

Helpful resources

Announcements
Fabric July 2025 Monthly Update Carousel

Fabric Monthly Update - July 2025

Check out the July 2025 Fabric update to learn about new features.

August 2025 community update carousel

Fabric Community Update - August 2025

Find out what's new and trending in the Fabric community.