Back to Browse

How to Implement TDE for Oracle 12c2 Container and pluggable databases

4.7K views
Dec 3, 2017
19:36

Setup Wallet: Modify the sqlnet.ora file ENCRYPTION_WALLET_LOCATION= (SOURCE= (METHOD=FILE) (METHOD_DATA= (DIRECTORY=Directory location\))) --set password based keystore - container level ADMINISTER KEY MANAGEMENT CREATE KEYSTORE 'C:\app\AkPC\admin\tdewallet\orcl' IDENTIFIED BY password; --set auto login keystore - container level ADMINISTER KEY MANAGEMENT CREATE AUTO_LOGIN KEYSTORE FROM KEYSTORE 'C:\app\AkPC\admin\tdewallet\orcl' IDENTIFIED BY password; --open the keystore in root container ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY password; --set master key at root container level ADMINISTER KEY MANAGEMENT SET KEY IDENTIFIED BY password with backup; --open the keystore in pdb ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY password; --Set database master key in pdb ADMINISTER KEY MANAGEMENT SET KEY IDENTIFIED BY password with backup; CREATE TABLESPACE encrypted_ts DATAFILE 'C:\app\AkPC\oradata\orcl\orclpdb\encrypted_ts.dbf' SIZE 128K AUTOEXTEND ON NEXT 64K ENCRYPTION USING 'AES256' DEFAULT STORAGE(ENCRYPT); CREATE TABLESPACE unencrypted_ts DATAFILE 'C:\app\AkPC\oradata\orcl\orclpdb\unencrypted_ts.dbf' SIZE 128K AUTOEXTEND ON NEXT 64K; CREATE TABLE TEST_ENC (TEXT VARCHAR2(100)) TABLESPACE encrypted_ts; CREATE TABLE TEST_UNENC (TEXT VARCHAR2(100)) TABLESPACE unencrypted_ts; insert into TEST_ENC values ('This is a secret'); insert into TEST_UNENC values ('This is a secret');

Download

0 formats

No download links available.

How to Implement TDE for Oracle 12c2 Container and pluggable databases | NatokHD