网络编程
TDE_CONFIGURATION参数指定了使用Transparent Data Encryption(TDE)的加密容器的名称。TDE功能使得即使在磁盘上的数据泄露了,该数据也无法被访问。
如何正确设置:
1. 首先,需要创建一个TDE加密容器:
SQL> CREATE CONTAINER tde_container_1 ENCRYPT USING ‘AES256′;
2. 为TDE_CONFIGURATION参数设置TDE加密容器的名称:
SQL> ALTER SYSTEM SET TDE_CONFIGURATION=’tde_container_1’;
3. 最后,需要应用这些更改:
SQL> ALTER SYSTEM SCOPE=SPFILE;
window.name=’TDE_CONFIGURATION’ function footdisplay(footnum,footnote) { var msg = window.open(‘about:blank’, ‘NewWindow’ + footnum, ‘directories=no,height=100,location=no,menubar=no,resizable=yes,’ + ‘scrollbars=yes,status=no,toolbar=no,width=598’); msg.document.open(‘text/html’); msg.document.write(”); msg.document.write(‘
msg.document.write(‘Footnote ‘ + footnum); msg.document.write(”); msg.document.write(”); msg.document.write(‘ <![CDATA[ '); msg.document.write('h1 {text-align: center; font-size: 14pt;}'); msg.document.write('fieldset {border: none;}'); msg.document.write('form {text-align: center;}'); msg.document.write(' ]]\u003e ‘); msg.document.write(‘
‘); msg.document.write(footnote); msg.document.write(‘
The script content on this page is for navigation purposes only and does not alter the content in any way.
TDE_CONFIGURATION is used for per-PDB configuration for Transparent Data Encryption (TDE).
TDE_CONFIGURATION
Before Oracle Database 18c, each PDB stored its separate encryption keys in the CDB’s keystore (united mode). Starting with Oracle Database 18c Cloud environments, a PDB can optionally store its encryption keys in a separate keystore (isolated mode), thus allowing protection by a separate keystore password. This functionality is not available for on-premises environments.
The WALLET_ROOT initialization parameter must be set in order for TDE_CONFIGURATION to take effect.
WALLET_ROOT
Parameter type
String
Syntax
TDE_CONFIGURATION = “{ KEYSTORE_CONFIGURATION = value [; CONTAINER = pdb-name] }”
value ::=
{
FILE |
OKV |
HSM |
FILE|OKV |
FILE|HSM |
OKV|FILE |
HSM|FILE
}
Notes:
The KEYSTORE_CONFIGURATION value is case-insensitive. For example, you can specify FILE or file.
KEYSTORE_CONFIGURATION
FILE
file
FILE|OKV, FILE|HSM, OKV|FILE, and HSM|FILE are values. The vertical bars they contain are not separators in the syntax shown above.
FILE|OKV
FILE|HSM
OKV|FILE
Default value
None
Modifiable
ALTER SYSTEMFoot 1
ALTER SYSTEM
Modifiable in a PDB
Yes
Basic
No
Oracle RAC
The same value must be specified on all instances using the ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=value" SCOPE=BOTH SID='*'; statement.
ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=value" SCOPE=BOTH SID='*';
Footnote 1
In some cases when this parameter is set using ALTER SYSTEM SCOPE=SPFILE, the SHOW PARAMETER TDE_CONFIGURATION statement does not show the correct value. However, the value set for TDE_CONFIGURATION can be derived from information shown in the V$ENCRYPTION_WALLET view.
ALTER SYSTEM SCOPE=SPFILE
SHOW PARAMETER TDE_CONFIGURATION
V$ENCRYPTION_WALLET
The following attributes can be specified:
KEYSTORE_CONFIGURATION attribute. This attribute is required. The value specified with this attribute configures the keystore type for the specified PDB. The following values can be specified for this attribute:
FILE: This value configures a wallet keystore.
OKV: This value configures an Oracle Key Vault (OKV) keystore.
OKV
This value is also used to disable an auto-login OKV configuration and cause any existing cwallet.sso files, containing the credentials to the OKV server as the OKV_PASSWORD client secret, to be ignored.
cwallet.sso
OKV_PASSWORD
HSM: This value configures a Hardware Security Module (HSM) keystore.
HSM
FILE|OKV: This value configures a reverse migration from an OKV to a wallet keystore.
FILE|HSM: This value configures a reverse migration from a HSM to a wallet keystore.
OKV|FILE: This value configures a migration from a wallet to an OKV keystore.
This value is also used in an auto-login OKV configuration, because in this configuration a cwallet.sso file, containing the OKV_PASSWORD client secret, must be used by the Oracle server to obtain the credentials to log in to the OKV server.
HSM|FILE: This value configures a migration from a wallet to a HSM keystore.
This value is also used in an auto-login HSM configuration, because in this configuration a cwallet.sso file, containing the HSM_PASSWORD client secret, must be used by the Oracle server to obtain the credentials to log in to the HSM server.
HSM_PASSWORD
Some of the KEYSTORE_CONFIGURATION attribute values consist of a single word, for example, the FILE, OKV, and HSM values. The other KEYSTORE_CONFIGURATION attribute values consist of two words separated by the “|” character that is a required part of the value’s syntax, for example, the FILE|OKV, FILE|HSM, OKV|FILE, and HSM|FILE values.
In Oracle Database releases prior to Oracle Database 18.1, keystore types were configured in sqlnet.ora using the METHOD attribute of the SQLNET.ENCRYPTION_WALLET_LOCATION parameter.
sqlnet.ora
METHOD
SQLNET.ENCRYPTION_WALLET_LOCATION
CONTAINER attribute: This optional attribute can be used only when setting the parameter in the CDB$ROOT of a CDB. The CONTAINER attribute can be specified only when the CDB$ROOT is in MOUNTED state. With this attribute, you must specify the name of the PDB for which you are setting the parameter. When you specify the CONTAINER attribute, you must use a semicolon “;” as the separation character between the KEYSTORE_CONFIGURATION and CONTAINER attributes.
CONTAINER
CDB$ROOT
MOUNTED
Examples
The following statement configures a wallet keystore for the open PDB from which the statement is issued:
CopyALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=FILE" SCOPE=BOTH SID='*';
The following statement configures an OKV keystore for the PDB in MOUNTED state from which the statement is issued:
CopyALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=OKV" SCOPE=SPFILE SID='*';
The following statement configures a HSM keystore for the ORCLPDB PDB. For this statement to succeed, the parameter must be set in the CDB$ROOT of a CDB when the CDB$ROOT is in MOUNTED state:
ORCLPDB
CopyALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=HSM; CONTAINER=ORCLPDB" SCOPE=MEMORY SID='*';
See Also:
Oracle Database Advanced Security Guide for information about managing keystores and encryption keys in united mode
Oracle Database Advanced Security Guide for information about managing keystores and encryption keys in isolated mode