It is highly recommended that you check the connections with each SQL Server node after you run the setup.ps1 command. If the connection test fails due to an invalid TDE connector, then you should manually create a new TDE connector and access token, and copy them to the access token file.
You can check the connection between the SQL Server VM and CSP Vault for Databases using the following commands:
PS> hcl status
This command shows if the VM is able to communicate with the CSP Vault for Databases. It also shows if the VM is properly authenticated and has a regular heartbeat with the CSP Vault for Databases.
PS> check-connection <Access Token File Path>
This command creates a test RSA-2048 key on the CSP Vault for Databases. The name of the key is _rsa_2048_test_key_. CSP Vault uses this key to test encrypt and decrypt operations and then destroys the key.
This command executes all the tasks using the TDE library installed by the Entrust Policy Agent. The TDE library can be found in the Policy Agentinstallation directory, for example, in C:\Program Files\hcs\bin\htsqlekm_provider.dll