> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate and test

> Verify the Oracle TDE wallet, master key, and encrypted data path through CryptoHub.

After setting up and opening the encryption wallet, it’s important to verify that Transparent Data Encryption (TDE) is functioning correctly. Validation ensures that the wallet is active and properly associated with your database, while testing confirms that encryption works as expected when applied to database objects.

In this section, we will:

* Confirm the wallet status from both the CDB and PDB.
* Verify that the wallet key is available for encryption operations.
* Test TDE functionality by closing the wallet and trying to access the data.

These steps assure that your wallet configuration is successful and that TDE is ready for secure use in your Oracle environment.

## Validate Wallet is open

To validate that the wallet is open, run the following command:

```sql expandable lines wrap title="Sql" theme={null}
SQL> SELECT WRL_TYPE, WRL_PARAMETER, WALLET_TYPE, STATUS FROM V$ENCRYPTION_WALLET;
```

<Check>
  If the wallet is configured properly, `STATUS` of HSM will show as `OPEN` as shown below:

  ```sql expandable lines wrap title="Sql" theme={null}
  WRLTYPE | WRLPARAMETER               | WALLETTYPE | STATUS
  ---------+-----------------------------+-------------+---------------------
  FILE     | /etc/ORACLE/WALLETS/tde/    | AUTOLOGIN   | OPENNOMASTERKEY
  HSM      |                             | HSM         | OPEN
  ```
</Check>

## Validate if TDE is active

<Steps>
  <Step>
    Connect to the Oracle database, and make sure that the database instance is running.

    ```shell expandable lines wrap title="Shell" theme={null}
    $ sqlplus / as sysdba
    ```

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> STARTUP;
    ```
  </Step>

  <Step>
    Switch to a preferred PDB container

    ```mysql title="SQL" expandable lines wrap theme={null}
      SQL> ALTER SESSION SET CONTAINER = <PDB_CONTAINER>;
    ```
  </Step>

  <Step>
    Check if the PDB container has a HSM keystore set up:

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> SELECT WRL_TYPE, STATUS, WALLET_TYPE FROM V$ENCRYPTION_WALLET;
    ```

    <Note>
      Important

      Each PDB must have its own keystore opened and a TDE master key generated. This process should be performed only after the CDB’s keystore has been opened and its TDE master key created. Repeat the steps from the previous page for every PDB requiring TDE encryption.
    </Note>
  </Step>

  <Step>
    Create a test user

    ```mysql title="SQL" expandable lines wrap theme={null}
      SQL> CREATE USER test_user IDENTIFIED BY "<USER_PASSWORD>";
    ```

    Grant basic privileges to the user

    ```sql title="SQL" expandable lines wrap theme={null}
      SQL> GRANT CONNECT, RESOURCE TO test_user;
    ```

    Grant quota unlimited to the user

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> ALTER USER test_user QUOTA UNLIMITED ON USERS;
    ```
  </Step>

  <Step>
    In a separate terminal, connect to the newly created user

    ```shell expandable lines wrap title="Shell" theme={null}
    sqlplus test_user/<USER_PASSWORD>@<HOSTNAME>:<PORT>/<PDB_NAME>
    ```

    <Note>
      Important

      To check which hostname and port the PDB is connected to, check the `listener.ora` or `tnsnames.ora` files

      ```shell expandable lines wrap title="Shell" theme={null}
      cat $ORACLEHOME/network/admin/listener.ora
      cat $ORACLEHOME/network/admin/tnsnames.ora
      ```
    </Note>
  </Step>

  <Step>
    Create a table

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> CREATE TABLE CUSTOMERS (ID NUMBER(5), NAME VARCHAR2(42), CREDIT_LIMIT NUMBER(10));
    ```
  </Step>

  <Step>
    Insert test data into the table

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> INSERT INTO CUSTOMERS VALUES (1, 'Test User', 1000);
    SQL> INSERT INTO CUSTOMERS VALUES (2, 'Test User 2', 2000);
    ```
  </Step>

  <Step>
    Encrypt a column using the TDE key on CryptoHub

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> ALTER TABLE CUSTOMERS MODIFY (CREDIT_LIMIT ENCRYPT);
    ```
  </Step>

  <Step>
    Check if the column is encrypted

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> SELECT TABLE_NAME, COLUMN_NAME, ENCRYPTION_ALG
    FROM USER_ENCRYPTED_COLUMNS
    WHERE TABLE_NAME = 'CUSTOMERS';
    ```

    <Check>
      A successful output will look similar to the output below

      ```none expandable lines wrap title="None" theme={null}
      TABLENAME	     COLUMNNAME	ENCRYPTIONALG
      --------------- --------------- -----------------------------
      CUSTOMERS	     CREDITLIMIT	AES 192 bits key
      ```
    </Check>
  </Step>
</Steps>

## Test if TDE is active

<Steps>
  <Step>
    In the terminal that is logged in as the newly created user, run the following command to see the data in the `CREDIT_LIMIT` column in the table

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> SELECT CREDIT_LIMIT FROM CUSTOMERS;
    ```

    <Check>
      Output should look similar to

      ```none expandable lines wrap title="None" theme={null}
      CREDIT_LIMIT
      ------------
      	1000
      	2000
      ```
    </Check>
  </Step>

  <Step>
    In another terminal that is logged in as SYS, close the PDB wallet.

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> ADMINISTER KEY MANAGEMENT SET KEYSTORE CLOSE IDENTIFIED BY "CryptoHub_Identity_Password";
    ```
  </Step>

  <Step>
    In the terminal that is logged in as the newly created user, try to view the data in the `CREDIT_LIMIT` column

    ```sql expandable lines wrap title="Sql" theme={null}
    SQL> SELECT CREDIT_LIMIT FROM CUSTOMERS;
    ```

    <Check>
      A successful TDE output will look similar to below

      ```none expandable lines wrap title="None" theme={null}
      ERROR at line 1:
      ORA-28365: wallet is not open
      ```
    </Check>
  </Step>
</Steps>
