1.TLS protocols enabled on both the SQL Server and the Application Server.
2.SQL Configuration Manager - enabled the SQL server to use the quest certificate and force encryption.
3.Change the MSSQLServer service to use the service account rather than NT Service Account.
4.Make sure the installed certificate service account has full control and read permissions.