The following procedure applies when the target database is multitenant, and you are already using a software wallet with TDE encryption. If your target database is non-multitenant, see Migrating from Software Wallet to CSP Vault.
Repeat the following procedure for each software keystore from which you want to migrate. Each container database (CDB) can use its own Entrust key protection method (credential) if required. However, once a Entrust key protection method has been activated for a particular database instance (CDB), then you must continue to use that same credential for any further keys you want to protect for that instance.
Use the WALLET_ROOT and TDE_CONFIGURATION parameters.
In the following steps, use the orcl.conf file to utilize the access credentials for the Cryptographic Security Platform Vault for Databases.
Back up your software keystore before attempting key migration to Cryptographic Security Platform Vault:
CopyCONNECT sysdba@CDB<n>
ADMINISTER KEY MANAGEMENT BACKUP KEYSTORE USING '<PreMigrationBackupString>' IDENTIFIED BY
"<keystorepassphrase>";Prepare for key migration by running the following SQL script:
CopyCONNECT sysdba@CDB1ROOT
ALTER SYSTEM SET TDE_CONFIGURATION = "KEYSTORE_CONFIGURATION=HSM|FILE" SCOPE=BOTH SID='*';Migrate from the keystore to Cryptographic Security Platform Vault:
CopyCONNECT sysdba@CDB1ROOT
ALTER SESSION SET CONTAINER = CDB$ROOT;
SHOW con_name;
--Open all the PDBs.
ALTER PLUGGABLE DATABASE ALL OPEN;
ADMINISTER KEY MANAGEMENT SET ENCRYPTION KEY IDENTIFIED BY "file:/opt/oracle/entrust/orcl.conf" MIGRATE
USING <keystore-passphrase> WITH BACKUP;For Oracle 21c Database, you must open PDB$SEED with read write permissions to successfully bounce the database after migrating from the keystore to Cryptographic Security Platform Vault:
CopyCONNECT sysdba@CDB1ROOT
ALTER SESSION SET CONTAINER = CDB$ROOT;
SHOW con_name;
--Open all the PDBs.
ALTER PLUGGABLE DATABASE ALL OPEN;
-- open PDB$SEED with read write perm show pdbs;
alter pluggable database pdb$seed close;
alter pluggable database pdb$seed open read write;
show pdbs;
ADMINISTER KEY MANAGEMENT SET ENCRYPTION KEY IDENTIFIED BY "file:/opt/oracle/entrust/orcl.conf" MIGRATE
USING <keystore-passphrase> WITH BACKUP;Return to the Oracle Server in the SQL database and run the
select CON_ID,WRL_TYPE,STATUS from V$ENCRYPTION_WALLET;command.For example:
CopySQL> select CON_ID,WRL_TYPE,STATUS from V$ENCRYPTION_WALLET;
CON_ID WRL_TYPE STATUS
---------- -------------------- ------------------------------
1 HSM OPEN
2 HSM OPEN
3 HSM OPEN
4 HSM OPEN