- Confirm the wallet status from both the CDB and PDB.
- Verify that the wallet key is available for encryption operations.
- Test TDE functionality by closing the wallet and trying to access the data.
Validate Wallet is open
To validate that the wallet is open, run the following command:Sql
If the wallet is configured properly,
STATUS of HSM will show as OPEN as shown below:Sql
Validate if TDE is active
1
Connect to the Oracle database, and make sure that the database instance is running.
Shell
Sql
2
Switch to a preferred PDB container
SQL
3
Check if the PDB container has a HSM keystore set up:
Sql
ImportantEach PDB must have its own keystore opened and a TDE master key generated. This process should be performed only after the CDB’s keystore has been opened and its TDE master key created. Repeat the steps from the previous page for every PDB requiring TDE encryption.
4
Create a test userGrant basic privileges to the userGrant quota unlimited to the user
SQL
SQL
Sql
5
In a separate terminal, connect to the newly created user
Shell
ImportantTo check which hostname and port the PDB is connected to, check the
listener.ora or tnsnames.ora filesShell
6
Create a table
Sql
7
Insert test data into the table
Sql
8
Encrypt a column using the TDE key on CryptoHub
Sql
9
Check if the column is encrypted
Sql
A successful output will look similar to the output below
None
Test if TDE is active
1
In the terminal that is logged in as the newly created user, run the following command to see the data in the
CREDIT_LIMIT column in the tableSql
Output should look similar to
None
2
In another terminal that is logged in as SYS, close the PDB wallet.
Sql
3
In the terminal that is logged in as the newly created user, try to view the data in the
CREDIT_LIMIT columnSql
A successful TDE output will look similar to below
None

