Oracle Database does not encrypt objects that
SYS owns (ORA-28336: cannot encrypt SYS owned objects). Create the test objects under a separate user.TEST_USER_PASSWORD with a password for the test user, and replace CRYPTOHUB_ENDPOINT_PIN with the CryptoHub endpoint PIN.
Create a test user
Insqlplus / as sysdba, create the test user:
Encrypt a column
1
Connect as the test user, and then create a table with an encrypted column:
The query returns the row with the
ssn value in plain text.2
Connect as
SYSDBA, and then confirm that the column is encrypted:The output shows the
SSN column of TDETEST.TDE_TEST. The default algorithm is AES 192 bits key.Encrypt a tablespace
1
As
SYSDBA, create an encrypted tablespace:The output shows
TDE_TBS with ENCRYPTED set to YES.2
Create a table in the encrypted tablespace:
Confirm that access depends on CryptoHub
Close the HSM key store, and then confirm that the encrypted data is unreadable.1
As
SYSDBA, close the HSM key store:The HSM key store
STATUS is CLOSED.2
As the test user, try to read the encrypted data:
Both queries fail with
ORA-28365: wallet is not open.3
As
SYSDBA, open the HSM key store again:4
As the test user, read the encrypted data again:
Both queries return their rows in plain text.
Confirm the key store opens after a restart
If you configured auto-login, restart the database, and then confirm that the encrypted data is readable without a manual open:The HSM key store
STATUS is OPEN, and both queries return their rows.STATUS is CLOSED after the restart. Open it with ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN, and then run the queries.
Confirm the master encryption key in CryptoHub
In CryptoHub, find the keys in the Oracle Database TDE service key group. Confirm that a key has a label that starts withORACLE.TDE.HSM.MK.06 followed by the masterkeyid value that you recorded when you created the master encryption key. CryptoHub adds a numeric suffix to the label.

