Skip to main content
Encrypt test data, and then confirm that the database cannot read it without CryptoHub.
Oracle Database does not encrypt objects that SYS owns (ORA-28336: cannot encrypt SYS owned objects). Create the test objects under a separate user.
In the commands on this page, replace TEST_USER_PASSWORD with a password for the test user, and replace CRYPTOHUB_ENDPOINT_PIN with the CryptoHub endpoint PIN.

Create a test user

In sqlplus / as sysdba, create the test user:

Encrypt a column

1
Connect as the test user, and then create a table with an encrypted column:
The query returns the row with the ssn value in plain text.
2
Connect as SYSDBA, and then confirm that the column is encrypted:
The output shows the SSN column of TDETEST.TDE_TEST. The default algorithm is AES 192 bits key.

Encrypt a tablespace

1
As SYSDBA, create an encrypted tablespace:
The output shows TDE_TBS with ENCRYPTED set to YES.
2
Create a table in the encrypted tablespace:

Confirm that access depends on CryptoHub

Close the HSM key store, and then confirm that the encrypted data is unreadable.
1
As SYSDBA, close the HSM key store:
The HSM key store STATUS is CLOSED.
2
As the test user, try to read the encrypted data:
Both queries fail with ORA-28365: wallet is not open.
3
As SYSDBA, open the HSM key store again:
4
As the test user, read the encrypted data again:
Both queries return their rows in plain text.

Confirm the key store opens after a restart

If you configured auto-login, restart the database, and then confirm that the encrypted data is readable without a manual open:
The HSM key store STATUS is OPEN, and both queries return their rows.
If you did not configure auto-login, the HSM key store STATUS is CLOSED after the restart. Open it with ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN, and then run the queries.

Confirm the master encryption key in CryptoHub

In CryptoHub, find the keys in the Oracle Database TDE service key group. Confirm that a key has a label that starts with ORACLE.TDE.HSM.MK.06 followed by the masterkeyid value that you recorded when you created the master encryption key. CryptoHub adds a numeric suffix to the label.

Remove the test objects

After you finish the verification, remove the test objects:
If any check fails, see Troubleshooting.