TDE in Oracle RAC 26ai: United Mode and Isolated Mode in the Same Database


ORACLE RAC 26ai  |  TDE  |  MULTITENANT

TDE in Oracle RAC 26ai

Oracle Advanced Security: United Mode and Isolated Mode in the Same Database

Munish Kumar Karna

Senior Database Solution Architect  |  Oracle DBA

Overview

Transparent Data Encryption (TDE) protects data at rest by encrypting it on storage while remaining transparent to applications. In a multitenant database, the TDE keystore can be managed in two ways:

•      United mode: a single keystore at the CDB root holds the master encryption keys for the CDB and its PDBs.

•      Isolated mode: a PDB maintains its own keystore and master key, independent of the CDB.

This guide is a hands-on walkthrough of configuring both modes inside the same two-node Oracle RAC 26ai database, with a screenshot for every step, including an ORA-46705 error encountered along the way and how it was resolved.

Note  All passwords shown (YourSecurePassword, PDB_SecurePassword) are placeholders. Always use strong, unique passwords in your own environment.

Prerequisites

Hostname

IP Address

Oracle RAC Version

racnode1

192.168.46.120

26ai (23.26.2.0.0)

racnode2

192.168.46.122

26ai (23.26.2.0.0)

 

Scope of This Walkthrough

Container

Keystore Mode

Purpose in this guide

ORCLDB (CDB$ROOT)

Root keystore

Foundation: wallet root, keystore, master key, local auto-login

PDB1ORCLDB

United

Uses the CDB-level keystore; master key set from within the PDB

PDB2ORCLDB

Isolated

Has its own file-based keystore, master key and auto-login

Part 1: CDB Root Keystore Configuration

Step 1.1  Configure the TDE parameters

From any node, connect with SQL*Plus and set the wallet location and TDE configuration parameters.

-- Set the centralized wallet root structure globally for the RAC cluster

ALTER SYSTEM SET WALLET_ROOT='+DATA/ORCLDB';

 

-- Configure TDE to look toward the PKCS11/OKV integration framework

ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=HSM" SCOPE=SPFILE;

Title: Figure 1 - Description: WALLET_ROOT and TDE_CONFIGURATION set; System altered

Figure 1  WALLET_ROOT and TDE_CONFIGURATION set; System altered

Step 1.2  Restart the database

Restart the RAC database so the parameters take effect.

srvctl stop database -d orcldb

srvctl start database -d orcldb

Title: Figure 2 - Description: Both RAC instances running again on racnode1 and racnode2

Figure 2  Both RAC instances running again on racnode1 and racnode2

Step 1.3  Create the keystore for CDB$ROOT

ADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY "YourSecurePassword";

Title: Figure 3 - Description: Password-based keystore created at the CDB root

Figure 3  Password-based keystore created at the CDB root

Step 1.4  Verify the wallet

Confirm from ASMCMD that the wallet file exists under +DATA/ORCLDB/tde.

Title: Figure 4 - Description: ewallet.p12 present in +DATA/ORCLDB/tde

Figure 4  ewallet.p12 present in +DATA/ORCLDB/tde

Step 1.5  Open the keystore

ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "YourSecurePassword";

Title: Figure 5 - Description: Keystore opened

Figure 5  Keystore opened

Step 1.6  Set the master encryption key (with automatic backup)

ADMINISTER KEY MANAGEMENT SET KEY IDENTIFIED BY "YourSecurePassword" WITH BACKUP;

Title: Figure 6 - Description: Master encryption key created with backup

Figure 6  Master encryption key created with backup

Step 1.7  Verify the backup

A timestamped backup copy of the wallet is created next to ewallet.p12.

Title: Figure 7 - Description: Timestamped wallet backup visible in +DATA/ORCLDB/tde

Figure 7  Timestamped wallet backup visible in +DATA/ORCLDB/tde

Step 1.8  Create the local auto-login keystore

ADMINISTER KEY MANAGEMENT CREATE LOCAL AUTO_LOGIN KEYSTORE

  FROM KEYSTORE IDENTIFIED BY "YourSecurePassword";

Title: Figure 8 - Description: Local auto-login keystore created

Figure 8  Local auto-login keystore created

Step 1.9  Verify the auto-login file (.sso)

cwallet.sso now appears alongside the password-based wallet and its backup.

Title: Figure 9 - Description: cwallet.sso, ewallet.p12 and the wallet backup in ASM

Figure 9  cwallet.sso, ewallet.p12 and the wallet backup in ASM

Part 2: United Mode (PDB1ORCLDB)

Step 2.1  Connect to the PDB where TDE will be used

alter session set container=pdb1orcldb;

Title: Figure 10 - Description: Session switched to PDB1ORCLDB

Figure 10  Session switched to PDB1ORCLDB

Step 2.2  Create the master key for the PDB

ADMINISTER KEY MANAGEMENT SET KEY IDENTIFIED BY "YourSecurePassword" with backup;

Title: Figure 11 - Description: PDB master key created in United mode

Figure 11  PDB master key created in United mode

Step 2.3  Verify the encryption wallet

Query V$ENCRYPTION_WALLET to confirm the wallet status and keystore mode.

SET LINESIZE 180

SET PAGESIZE 50

COLUMN wrl_type FORMAT A12

COLUMN wrl_parameter FORMAT A35

COLUMN status FORMAT A15

COLUMN wallet_type FORMAT A15

COLUMN keystore_mode FORMAT A15

 

SELECT con_id, wrl_type, wrl_parameter, status, wallet_type, keystore_mode

FROM   v$encryption_wallet;

Title: Figure 12 - Description: PDB1ORCLDB (CON_ID 3): wallet OPEN, LOCAL_AUTOLOGIN, KEYSTORE_MODE = UNITED

Figure 12  PDB1ORCLDB (CON_ID 3): wallet OPEN, LOCAL_AUTOLOGIN, KEYSTORE_MODE = UNITED

Part 3: Isolated Mode (PDB2ORCLDB)

Step 3.1  Starting point

Initially, the wallet was found open for all PDBs through the local auto-login keystore, all in United mode.

Title: Figure 13 - Description: All containers using LOCAL_AUTOLOGIN; PDBs in UNITED mode

Figure 13  All containers using LOCAL_AUTOLOGIN; PDBs in UNITED mode

Step 3.2  Issue encountered: ORA-46705

Creating a password-based keystore directly in the PDB failed with the following error:

SQL> ADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY "PDB_SecurePassword";

 

ERROR at line 1:

ORA-46705: Key is set for the pluggable database (PDB). Cannot create the password-based keystore.

 

Help: https://docs.oracle.com/error-help/db/ora-46705/

Step 3.3  Fix: disable auto-login at the CDB level

Back up the CDB-level auto-login file (cwallet.sso) and then remove it from the ASM wallet location.

ASMCMD> cp cwallet.sso cwallet.sso.bpk

ASMCMD> rm cwallet.sso

Title: Figure 14 - Description: Backing up cwallet.sso as cwallet.sso.bpk

Figure 14  Backing up cwallet.sso as cwallet.sso.bpk

Title: Figure 15 - Description: Removing the CDB-level cwallet.sso

Figure 15  Removing the CDB-level cwallet.sso

Step 3.4  Close the wallet at the CDB level

ADMINISTER KEY MANAGEMENT SET KEYSTORE CLOSE;

Title: Figure 16 - Description: CDB-level keystore closed

Figure 16  CDB-level keystore closed

Step 3.5  Open the CDB-level wallet manually

ADMINISTER KEY MANAGEMENT SET KEYSTORE open IDENTIFIED BY "YourSecurePassword";

Title: Figure 17 - Description: CDB-level keystore opened with the password

Figure 17  CDB-level keystore opened with the password

Step 3.6  Connect to the PDB and close its open keystore

alter session set container=PDB2ORCLDB;

 

ADMINISTER KEY MANAGEMENT SET KEYSTORE CLOSE;

Title: Figure 18 - Description: Open keystore closed in PDB2ORCLDB

Figure 18  Open keystore closed in PDB2ORCLDB

Step 3.7  Configure Isolated mode

Switch the PDB to a file-based keystore configuration.

ALTER SYSTEM SET TDE_CONFIGURATION='KEYSTORE_CONFIGURATION=FILE' SCOPE=BOTH SID='*';

Title: Figure 19 - Description: TDE_CONFIGURATION set to FILE; PDB2ORCLDB (CON_ID 4) is READ WRITE

Figure 19  TDE_CONFIGURATION set to FILE; PDB2ORCLDB (CON_ID 4) is READ WRITE

Step 3.8  Create the PDB keystore

ADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY "PDB_SecurePassword";

Title: Figure 20 - Description: PDB-level keystore created successfully

Figure 20  PDB-level keystore created successfully

Step 3.9  Open the keystore

ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN FORCE KEYSTORE IDENTIFIED BY "PDB_SecurePassword";

Title: Figure 21 - Description: PDB keystore opened with FORCE KEYSTORE

Figure 21  PDB keystore opened with FORCE KEYSTORE

Step 3.10  Create the master key

ADMINISTER KEY MANAGEMENT CREATE KEY IDENTIFIED BY "PDB_SecurePassword" WITH BACKUP;

Title: Figure 22 - Description: PDB master key created with backup

Figure 22  PDB master key created with backup

Step 3.11  Create the auto-login keystore

ADMINISTER KEY MANAGEMENT CREATE AUTO_LOGIN KEYSTORE

  FROM KEYSTORE IDENTIFIED BY "PDB_SecurePassword";

Title: Figure 23 - Description: PDB auto-login keystore created

Figure 23  PDB auto-login keystore created

Step 3.12  Restore the CDB-level auto-login file

Copy the backed-up auto-login file back so the CDB-level wallet opens automatically again.

ASMCMD> cp cwallet.sso.bpk cwallet.sso

Title: Figure 24 - Description: cwallet.sso restored from cwallet.sso.bpk in +DATA/ORCLDB/tde

Figure 24  cwallet.sso restored from cwallet.sso.bpk in +DATA/ORCLDB/tde

Step 3.13  Close the wallet at the CDB level

ADMINISTER KEY MANAGEMENT SET KEYSTORE CLOSE IDENTIFIED BY "YourSecurePassword";

Title: Figure 25 - Description: CDB-level wallet closed

Figure 25  CDB-level wallet closed

Step 3.14  Final verification: everything tested

Re-run the V$ENCRYPTION_WALLET query to confirm both modes now coexist in one database.

Title: Figure 26 - Description: CDB$ROOT, PDB1 in UNITED mode and PDB2 in ISOLATED mode, all with wallets OPEN

Figure 26  CDB$ROOT, PDB1 in UNITED mode and PDB2 in ISOLATED mode, all with wallets OPEN

Result and Key Takeaways

The final verification confirms that United and Isolated TDE modes run side by side in a single Oracle RAC database:

CON_ID

Container

Wallet Type

Keystore Mode

1

CDB$ROOT

LOCAL_AUTOLOGIN

NONE (root keystore)

2

PDB$SEED

LOCAL_AUTOLOGIN

UNITED

3

PDB1ORCLDB

LOCAL_AUTOLOGIN

UNITED

4

PDB2ORCLDB

AUTOLOGIN

ISOLATED (own keystore directory in ASM)

 

•      United mode reuses the CDB-level keystore; only a master key has to be set from within the PDB.

•      Isolated mode gives a PDB its own keystore, master key and auto-login file, so its keys are managed independently of the CDB.

•      ORA-46705 appeared because the CDB's auto-login wallet kept the keystore open for all PDBs. Temporarily disabling auto-login at the CDB level removed the blocker.

•      Back up before you change anything: backing up cwallet.sso (and using WITH BACKUP for master keys) made the switch fully reversible.

Munish Kumar Karna  |  Senior Database Solution Architect  |  Oracle DBA

 

Comments