Skip to main content
After setting up and opening the encryption wallet, it’s important to verify that Transparent Data Encryption (TDE) is functioning correctly. Validation ensures that the wallet is active and properly associated with your database, while testing confirms that encryption works as expected when applied to database objects. In this section, we will:
  • Confirm the wallet status from both the CDB and PDB.
  • Verify that the wallet key is available for encryption operations.
  • Test TDE functionality by closing the wallet and trying to access the data.
These steps assure that your wallet configuration is successful and that TDE is ready for secure use in your Oracle environment.

Validate Wallet is open

To validate that the wallet is open, run the following command:
Sql
If the wallet is configured properly, STATUS of HSM will show as OPEN as shown below:
Sql

Validate if TDE is active

1
Connect to the Oracle database, and make sure that the database instance is running.
Shell
Sql
2
Switch to a preferred PDB container
SQL
3
Check if the PDB container has a HSM keystore set up:
Sql
ImportantEach PDB must have its own keystore opened and a TDE master key generated. This process should be performed only after the CDB’s keystore has been opened and its TDE master key created. Repeat the steps from the previous page for every PDB requiring TDE encryption.
4
Create a test user
SQL
Grant basic privileges to the user
SQL
Grant quota unlimited to the user
Sql
5
In a separate terminal, connect to the newly created user
Shell
ImportantTo check which hostname and port the PDB is connected to, check the listener.ora or tnsnames.ora files
Shell
6
Create a table
Sql
7
Insert test data into the table
Sql
8
Encrypt a column using the TDE key on CryptoHub
Sql
9
Check if the column is encrypted
Sql
A successful output will look similar to the output below
None

Test if TDE is active

1
In the terminal that is logged in as the newly created user, run the following command to see the data in the CREDIT_LIMIT column in the table
Sql
Output should look similar to
None
2
In another terminal that is logged in as SYS, close the PDB wallet.
Sql
3
In the terminal that is logged in as the newly created user, try to view the data in the CREDIT_LIMIT column
Sql
A successful TDE output will look similar to below
None