Index

A  B  C  D  E  F  G  H  I  J  K  L  M  N  O  P  R  S  T  U  V  W 

A

access control configuration, 2.3
access control options, 2.3.1
access grants, 2.3.2
access settings
endpoint groups, 6.6.3
removing from virtual wallets, 7.6.4
accounts
users, 5.1
Actions menu, 3.5.1
administration
Oracle Key Vault, 2.5.1
administrative roles
overview, 2.5.3
alerts
about, 10.2
configuring, 10.2
configuring in Alerts menu, 10.2.2
viewing, 10.2, 10.5.1
archiving
credential files, 9.3.1
JKS and JCEKS keystores, 9.2.1
Audit Manager role
functions, 2.5.3
auditing
about, 10.3.1
Audit Manager role, 2.5.3
deleting audit records, 10.3.2
exporting audit records, 10.3.2
managing, 10.3
auto-login wallets
creating for accessing Oracle Key Vault credentials, 8.3.2

B

backing up and restoring data, 4.2
with Oracle Key Vault, 1.4.6
backup destinations
creating a remote backup destination, 4.2.2.2
editing, 4.2.2.3
LOCAL, 4.2.2.1
backup scheduling, 4.2.3
about, 4.2.3.1
deleting, 4.2.3.4
process, 4.2.3.1.1
schedule state, 4.2.3.1.2
types, 4.2.3.1.3
backup time
setting, 4.2.3.2
backups
and high availability, 4.2.3.5
and high availability failover, 4.2.3.5
and high availability switchover, 4.2.3.5
destinations, 4.2.2, 4.2.2.1
editing, 4.2.3.3
protecting with recovery passphrase, 4.2.3.6
scheduling, 4.2.3.2
types, 4.2.3.1.3
benefits
centralizing key lifecyle management, 1.2
centralizing key storage, 1.2
fighting security threats, 1.2

C

centralized storage
Java keystores, 2.2.1
Oracle wallet files, 2.2.1
changepwd command (okvutil), 8.6.6
changing passwords, 5.7.1
changing recovery passphrase, 10.6.4
configuration files
endpoint configuration file, 8.5
configuring
alerts, 10.2
configuring high availability, 4.1
creating a user group, 5.9.1
creating users, 5.2
credential files
about archiving and downloading, 9.3.1
best practices for archiving and downloading, 9.3.4
downloading, 9.3.3
storage, 2.2.3
uploading, 9.3.2
use case, 2.2.3

D

dashboard, 10.5
data
backing up, 4.2
restoring, 4.2
deactivating keys, 7.4.3.2
default wallet, 2.1
deleting audit records, 10.3.2
deleting user groups, 5.9.5
deleting users, 5.8
deployment architecture
Oracle Key Vault, 2.4
deployments
credential files, archiving and downloading, 9.3.1
Java keystores, archiving and downloading, 9.1.1
JKS and JCEKS keystores, archiving and downloading, 9.2.1
Oracle wallets, archiving and downloading, 9.1.1
TDE direction connection for TDE wallets, 9.4.1
DNS (Domain Name Service)
setting, 10.6.2.1
download command (okvutil), 8.6.5, 9.1.3

E

emergency system recovery, 2.5.4, 10.6.3
enabling SSH Access, 10.6.2.2
endpoint access to wallets, 6.5.1
endpoint administrators
about, 2.6
endpoint database requirements, 3.1.5
endpoint groups
about creating, 6.6.1.1
about removing, 6.6.5.1, 6.6.5.1
creating, 6.6.1.2
modifying, 6.6.2
removing, 6.6.5.2
removing a member from, 6.6.4
endpoint membership
adding, 6.4.3
endpoint platform, 3.1.4
endpoint self-enrollment, about, 6.3.1
endpoints
about, 8.1
about managing, 6.1
adding access to virtual wallet, 6.5.1
adding details
about, 6.4.1
adding to an endpoint group, 6.4.3
adding using administrator-initiated enrollment, 6.3.3
adding using self-enrollment, 6.3.4
administrators for, 6.1
configuration file, 8.5
deleting, 6.3.5.2
about, 6.3.5.1
procedure, 6.3.5.2
downloading software to endpointdownloading endpoint software to endpoint, 8.3.1
enrolling and provisioning, 8.3.1
enrollment, 6.3.1
about, 8.2
administrator initiated, about, 6.3.1
types of enrollment, 6.3.1
enrollment process
about, 8.2
enrollment status, 6.3.2
how Java home is determined during installation, 8.3.3
installing Key Vault client, 8.3.2
modifying details, 6.4.2
okvutil utility for provisioning, 8.6.1
Oracle Enterprise Manager, 8.1
password, changing, 8.6.6
provisioning, 8.2
about, 8.2
reenrolling, 6.3.5.1, 6.3.5.2
about, 6.3.5.1
procedure, 6.3.5.2
removing access to virtual wallet, 6.5.2
searching for, 6.2
TDE endpoint management, 8.4
See also endpoint groups
enrolling endpoints
administrator initiated
about, 6.3.1
process, 8.2
self-initiated
about, 6.3.1
status, 6.3.2
Error
Object is Unstorable in Container error, 8.6.5
exporting audit records, 10.3.2

F

failover
and backup, 4.2.3.5
restoring high availability, 4.1.4

G

general maintenance, 10.1
general steps for using Oracle Key Vault, 1.6
granting access to objects or users, 2.3.2
granting roles, 5.3

H

high availability
and Active Data Guard, 1.4.5
and backup, 4.2.3.5
and restore, 4.2.4.4
clusters, 4.1.3
configuring, 4.1, 4.1.2
failover and backup, 4.2.3.5
switchover, backup, 4.2.3.5
unconfiguring, 4.1.5
with Oracle Key Vault, 1.4.5

I

installation passphrase, 3.2
entering, 3.2.1
interfaces, 1.5

J

Java keystores
downloading, 8.6.5, 9.2.3
uploading, 8.6.4, 9.2.2
JAVA_HOME environment variable
how determined during client installation, 8.3.3
JKS and JCEKS keystores
archiving
about, 9.2.1
best practices, 9.2.4
procedure, 9.2.2
downloading
best practices, 9.2.4
procedure, 9.2.3

K

Kerberos keytabs
downloading, 8.6.5
Key Administrator role
functions, 2.5.3
key lifecycle management, 1.4.2
key management, 1.1
key rotation, 2.2.2
keys
changing state of, 7.4.3.1
deactivating, 7.4.3.2
finding for Key Vault, 8.6.3
revoking, 7.4.3.3
KMIP Protocol, 1.4.8

L

liborapkcs.so file
about, 8.3.2
copying to endpoint, 8.3.2
list command (okvutil), 8.6.3
LOCAL
backup destinations, 4.2.2.1
log file locations, A.1

M

managed content
viewing, 10.5.1
management console, 3.3
about, 1.5
logging in to, 3.4
management of Oracle Key Vault, 10.1
management report
accessing, 10.4.2
managing users, 5.1
modifying a user group, 5.9.2

N

network address
setting, 10.6.2.1
network services
setting, 10.6.2

O

OASIS Key Management Interoperability Protocol (KMIP)
Oracle Key Vault implementation of, 1.4.8
okvclient.ora file
about, 8.5
location, 8.3.3
okvutil utility
about, 1.5
changepwd command, 8.6.6
download command, 8.6.5
list command, 8.6.3
syntax, 8.6.2
upload command, 8.6.4
used to manage endpoints, 8.6.1
options for access control, 2.3.1
Oracle Active Data Guard
migrating Oracle wallets, 9.7.4
TDE direct connections, 9.7.3
uploading Oracle wallets to Oracle Key Vault, 9.7.1
Oracle Enterprise Manager
endpoints, 8.1
TDE integration with Oracle Key Vault, 8.1
Oracle Key Vault
about, 1.1
administering, 10.6
benefits, 1.2
endpoint database requirements, 3.1.5
endpoint platform, 3.1.4
general steps for using, 1.6
installing, 3.2
other Oracle Database product support, 9.4.2
standards and protocols, 1.4.8
system requirements, 3.1.2
who should use, 1.3
Oracle Key Vault client software
auto-login wallet, 8.3.2
installing, 8.3.2
password-protected wallet, 8.3.2
setting credentials for accessing, 8.3.2
Oracle Key Vault configurations, 10.6.2
Oracle Key Vault endpoint utility
about, 1.5
See okvutil utility
Oracle Key Vault interfaces, 1.5
Oracle Key Vault keys
finding, 8.6.3
Oracle Key Vault management console, 3.3
about, 1.5
logging in to, 3.4
Oracle Key Vault restore, 4.2.4
Oracle Key Vault status
viewing, 10.5, 10.6.1
Oracle Key Vault use cases, 2.2
Oracle Real Application Clusters
archiving Oracle wallets, 9.5
Oracle wallets
archiving
about, 9.1.1
best practices, 9.1.4
archiving in Oracle Real Application Clusters environment, 9.5
downloading, 9.1.3
best practices, 9.1.4
restoring from Key Vault wallets, 9.4.4.3
uploading, 9.1.2

P

password-protected wallets
creating for accessing Oracle Key Vault credentials, 8.3.2
passwords
changing, 5.7.1
changing endpoint password, 8.6.6
Payment Card Industry Data Security Standard (PCI DSS), 1.4.2
power off, 10.6.2
power on, 10.6.2
provisioning endpoints
about, 8.2

R

reboot, 10.6.2
recovery passphrase
changing, 10.6.4
maintaining correct passphrase, 2.5.4
protecting the backup, 4.2.3.6
reenrolling
endpoints
about, 6.3.5.1
reenrolling endpoints
procedure, 6.3.5.2
rekey operation, 2.2.2, 9.1.4, 9.7.1
reports
viewing, 10.4
restore, 4.2.4
restore process, 4.2.4.2
about, 4.2.4.1
and high availability, 4.2.4.4
restoring Key Vault steps, 4.2.4.3
system state after, 4.2.4.5
restoring a system, 4.2.4.3
restoring high availability after a failover, 4.1.4
revoking keys, 7.4.3.3
revoking roles, 5.3
roles, 2.5.3
granting or revoking, 5.3
users without, 2.5, 5.1
rotation of encryption key, 9.1.4

S

scheduled backups, 4.2.3.2
deleting, 4.2.3.4
editing, 4.2.3.3
Search bars, 3.5.2
searches
how to perform searches in Oracle Key Vault, 3.5
searching for endpoints, 6.2
searching for items
all items section, 7.4.1
security objects
adding details, 7.4.2.1
advanced attributes of, 7.4.2.3
basic attributes of, 7.4.2.2
changing state of, 7.4.3.1
deactivating keys, 7.4.3.2
downloading to different types, 8.6.5
modifying details of, 7.4.2.1
revoking keys, 7.4.3.3
viewing details of, 7.4.2.1
separation of duties, 2.5.2
setting access to wallet, 6.6.3
SSH key files
downloading from Key Vault to a wallet, 8.6.5
switching primary and secondary nodes, 4.1.3
syslog configuration
setting, 10.6.2.1
System Administrator role
functions, 2.5.3
system recovery, 2.5.4
system requirements, 3.1.2
system state
after restore, 4.2.4.5
system time
setting, 10.6.2.1

T

TDE direct connections
about, 9.4.1
configuration for database with existing TDE data, 9.4.4.1
configuration for database with no TDE data, 9.4.3
use case, 2.2.2
TDE intetegration with Oracle Key Vault
Oracle Enterprise Manager, 8.1
TDE master keys
centralized management, 2.2.2
template, Glossary
Transparent Data Encryption
endpoint management, 8.4
troubleshooting
finding log files, A.1
upgrade errors, A.5
uploading Java keystores, A.2
uploading keystores with same file name but different contents, A.4
uploading the same Oracle wallet multiple times, A.3
types of backups, 4.2.3.1.3

U

upgrades
error handling, A.5
upload command (okvutil), 8.6.4
uploading
Oracle wallets, 9.1.1
use cases, 2.2
user details page, 5.5
user group membership
adding, 5.6.1
managing, 5.6, 5.6.2
removing, 5.6.1
user groups
adding a user, 5.9.3
creating, 5.9.1
deleting, 5.9.5
modifying, 5.9.2
removing a user, 5.9.4
virtual wallet access, 5.9
users
accounts, 5.1
adding access to virtual wallets, 7.6.2.1
creating, 5.2
deleting, 5.8
list, 5.4
managing, 5.1
removing access to virtual wallets, 7.6.2.2
users without roles, 2.5, 5.1, 5.7.1

V

viewing
alerts status, 10.5.1
managed content status, 10.5.1
virtual wallets
about, 7.1
about creating, 7.3.1
access for user groups, 5.9
adding access for individual user, 7.6.2.1
adding endpoint access to, 6.5.1
adding items, 7.5
creating, 7.3.2
deleting, 7.7
endpoint details, 6.4.1
granting access to, 7.6.1
removing access settings from, 7.6.4
removing endpoint access to, 6.5.2
removing individual access to, 7.6.2.2
removing items, 7.5
restoring Oracle wallets from, 9.4.4.3
viewing, 7.2

W

wallets
downloading from Key Vault to a wallet, 8.6.5
uploading contents to Key Vault server, 8.6.4
See also Oracle wallets, virtual wallets
Web Access, SSH Access, SNMP Access, 10.6.2