TDE in Oracle RAC 26ai: United Mode and Isolated Mode in the Same Database
ORACLE RAC 26ai |
TDE | MULTITENANT
TDE in Oracle RAC 26ai
Oracle Advanced Security: United Mode
and Isolated Mode in the Same Database
Munish Kumar
Karna
Senior Database Solution Architect |
Oracle DBA
Overview
Transparent Data Encryption (TDE) protects data at rest
by encrypting it on storage while remaining transparent to applications. In a
multitenant database, the TDE keystore can be managed in two ways:
•
United mode: a single keystore at the CDB root holds the master
encryption keys for the CDB and its PDBs.
•
Isolated mode: a PDB maintains its own keystore and master key,
independent of the CDB.
This guide is a hands-on walkthrough of configuring both
modes inside the same two-node Oracle RAC 26ai database, with a screenshot for
every step, including an ORA-46705 error encountered along the way and how it
was resolved.
Note All passwords shown
(YourSecurePassword, PDB_SecurePassword) are placeholders. Always use strong,
unique passwords in your own environment.
Prerequisites
|
Hostname |
IP Address |
Oracle RAC
Version |
|
racnode1 |
192.168.46.120 |
26ai
(23.26.2.0.0) |
|
racnode2 |
192.168.46.122 |
26ai
(23.26.2.0.0) |
Scope of This Walkthrough
|
Container |
Keystore
Mode |
Purpose in
this guide |
|
ORCLDB
(CDB$ROOT) |
Root keystore |
Foundation:
wallet root, keystore, master key, local auto-login |
|
PDB1ORCLDB |
United |
Uses the
CDB-level keystore; master key set from within the PDB |
|
PDB2ORCLDB |
Isolated |
Has its own
file-based keystore, master key and auto-login |
Part 1: CDB Root Keystore
Configuration
Step 1.1
Configure the TDE parameters
From any node, connect with SQL*Plus and set
the wallet location and TDE configuration parameters.
-- Set the centralized wallet root structure globally for the
RAC cluster
ALTER SYSTEM SET
WALLET_ROOT='+DATA/ORCLDB';
-- Configure TDE to look toward
the PKCS11/OKV integration framework
ALTER SYSTEM SET
TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=HSM" SCOPE=SPFILE;
Figure 1 WALLET_ROOT and TDE_CONFIGURATION set;
System altered
Step 1.2
Restart the database
Restart the RAC database so the parameters
take effect.
srvctl stop database -d orcldb
srvctl start database -d orcldb
Figure 2 Both RAC instances running again on
racnode1 and racnode2
Step 1.3
Create the keystore for CDB$ROOT
ADMINISTER KEY MANAGEMENT CREATE
KEYSTORE IDENTIFIED BY "YourSecurePassword";
Figure 3 Password-based keystore created at the
CDB root
Step 1.4
Verify the wallet
Confirm from ASMCMD that the wallet file
exists under +DATA/ORCLDB/tde.
Figure 4 ewallet.p12 present in +DATA/ORCLDB/tde
Step 1.5
Open the keystore
ADMINISTER KEY MANAGEMENT SET
KEYSTORE OPEN IDENTIFIED BY "YourSecurePassword";
Figure 5 Keystore opened
Step 1.6 Set
the master encryption key (with automatic backup)
ADMINISTER KEY MANAGEMENT SET KEY
IDENTIFIED BY "YourSecurePassword" WITH BACKUP;
Figure 6 Master encryption key created with backup
Step 1.7
Verify the backup
A timestamped backup copy of the wallet is
created next to ewallet.p12.
Figure 7 Timestamped wallet backup visible in
+DATA/ORCLDB/tde
Step 1.8
Create the local auto-login keystore
ADMINISTER KEY MANAGEMENT CREATE LOCAL AUTO_LOGIN KEYSTORE
FROM KEYSTORE IDENTIFIED
BY "YourSecurePassword";
Figure 8 Local auto-login keystore created
Step 1.9
Verify the auto-login file (.sso)
cwallet.sso now appears alongside the
password-based wallet and its backup.
Figure 9 cwallet.sso, ewallet.p12 and the wallet
backup in ASM
Part 2: United Mode (PDB1ORCLDB)
Step 2.1
Connect to the PDB where TDE will be used
alter session set
container=pdb1orcldb;
Figure 10 Session switched to PDB1ORCLDB
Step 2.2
Create the master key for the PDB
ADMINISTER KEY MANAGEMENT SET KEY
IDENTIFIED BY "YourSecurePassword" with backup;
Figure 11 PDB master key created in United mode
Step 2.3
Verify the encryption wallet
Query V$ENCRYPTION_WALLET to confirm the
wallet status and keystore mode.
SET LINESIZE 180
SET PAGESIZE 50
COLUMN wrl_type FORMAT A12
COLUMN wrl_parameter FORMAT A35
COLUMN status FORMAT A15
COLUMN wallet_type FORMAT A15
COLUMN keystore_mode FORMAT A15
SELECT con_id, wrl_type,
wrl_parameter, status, wallet_type, keystore_mode
FROM
v$encryption_wallet;
Figure 12 PDB1ORCLDB (CON_ID 3): wallet OPEN,
LOCAL_AUTOLOGIN, KEYSTORE_MODE = UNITED
Part 3: Isolated Mode
(PDB2ORCLDB)
Step 3.1
Starting point
Initially, the wallet was found open for all
PDBs through the local auto-login keystore, all in United mode.
Figure 13 All containers using LOCAL_AUTOLOGIN;
PDBs in UNITED mode
Step 3.2
Issue encountered: ORA-46705
Creating a password-based keystore directly
in the PDB failed with the following error:
SQL> ADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY
"PDB_SecurePassword";
ERROR at line 1:
ORA-46705: Key is set for the
pluggable database (PDB). Cannot create the password-based keystore.
Help: https://docs.oracle.com/error-help/db/ora-46705/
Step 3.3
Fix: disable auto-login at the CDB level
Back up the CDB-level auto-login file
(cwallet.sso) and then remove it from the ASM wallet location.
ASMCMD> cp cwallet.sso cwallet.sso.bpk
ASMCMD> rm cwallet.sso
Figure 14 Backing up cwallet.sso as cwallet.sso.bpk
Figure 15 Removing the CDB-level cwallet.sso
Step 3.4
Close the wallet at the CDB level
ADMINISTER KEY MANAGEMENT SET
KEYSTORE CLOSE;
Figure 16 CDB-level keystore closed
Step 3.5
Open the CDB-level wallet manually
ADMINISTER KEY MANAGEMENT SET
KEYSTORE open IDENTIFIED BY "YourSecurePassword";
Figure 17 CDB-level keystore opened with the
password
Step 3.6
Connect to the PDB and close its open keystore
alter session set container=PDB2ORCLDB;
ADMINISTER KEY MANAGEMENT SET KEYSTORE CLOSE;
Figure 18 Open keystore closed in PDB2ORCLDB
Step 3.7
Configure Isolated mode
Switch the PDB to a file-based keystore
configuration.
ALTER SYSTEM SET
TDE_CONFIGURATION='KEYSTORE_CONFIGURATION=FILE' SCOPE=BOTH SID='*';
Figure 19 TDE_CONFIGURATION set to FILE; PDB2ORCLDB
(CON_ID 4) is READ WRITE
Step 3.8
Create the PDB keystore
ADMINISTER KEY MANAGEMENT CREATE
KEYSTORE IDENTIFIED BY "PDB_SecurePassword";
Figure 20 PDB-level keystore created successfully
Step 3.9
Open the keystore
ADMINISTER KEY MANAGEMENT SET
KEYSTORE OPEN FORCE KEYSTORE IDENTIFIED BY "PDB_SecurePassword";
Figure 21 PDB keystore opened with FORCE KEYSTORE
Step 3.10
Create the master key
ADMINISTER KEY MANAGEMENT CREATE
KEY IDENTIFIED BY "PDB_SecurePassword" WITH BACKUP;
Figure 22 PDB master key created with backup
Step 3.11
Create the auto-login keystore
ADMINISTER KEY MANAGEMENT CREATE AUTO_LOGIN KEYSTORE
FROM KEYSTORE IDENTIFIED
BY "PDB_SecurePassword";
Figure 23 PDB auto-login keystore created
Step 3.12
Restore the CDB-level auto-login file
Copy the backed-up auto-login file back so
the CDB-level wallet opens automatically again.
ASMCMD> cp cwallet.sso.bpk
cwallet.sso
Figure 24 cwallet.sso restored from cwallet.sso.bpk
in +DATA/ORCLDB/tde
Step 3.13
Close the wallet at the CDB level
ADMINISTER KEY MANAGEMENT SET
KEYSTORE CLOSE IDENTIFIED BY "YourSecurePassword";
Figure 25 CDB-level wallet closed
Step 3.14
Final verification: everything tested
Re-run the V$ENCRYPTION_WALLET query to
confirm both modes now coexist in one database.
Figure 26 CDB$ROOT, PDB1 in UNITED mode and PDB2 in
ISOLATED mode, all with wallets OPEN
Result and Key Takeaways
The final verification confirms that United
and Isolated TDE modes run side by side in a single Oracle RAC database:
|
CON_ID |
Container |
Wallet Type |
Keystore
Mode |
|
1 |
CDB$ROOT |
LOCAL_AUTOLOGIN |
NONE (root
keystore) |
|
2 |
PDB$SEED |
LOCAL_AUTOLOGIN |
UNITED |
|
3 |
PDB1ORCLDB |
LOCAL_AUTOLOGIN |
UNITED |
|
4 |
PDB2ORCLDB |
AUTOLOGIN |
ISOLATED (own
keystore directory in ASM) |
•
United mode reuses the CDB-level keystore; only a master key has to
be set from within the PDB.
•
Isolated mode gives a PDB its own keystore, master key and auto-login
file, so its keys are managed independently of the CDB.
•
ORA-46705 appeared because the CDB's auto-login wallet kept the
keystore open for all PDBs. Temporarily disabling auto-login at the CDB level
removed the blocker.
•
Back up before
you change anything: backing up
cwallet.sso (and using WITH BACKUP for master keys) made the switch fully
reversible.
Munish Kumar Karna
| Senior Database Solution
Architect | Oracle DBA
Comments
Post a Comment