Migrate Encryption Keys
This topic provides the details and procedure to migrate encryption keys between different encryption methods.
Before you begin, review the following:
- Migration requires the credentials for the encryption key, which must already be present on the external keystore.
- Key migration works seamlessly in a Data Guard environment.
- You cannot migrate keys if other databases in the same VM Cluster are already using different encryption methods, such as an external keystore or Oracle Key Vault (OKV).
Procedure
Perform the following steps in the Console.
-
On the Data Infrastructures list page, select the Data Infrastructure that you want to work with. If you need help finding the list page or the Data Infrastructure, see List Data Infrastructures.
- On the Data Infrastructure details page, select the VM Cluster tab to view the list of all VM Clusters.
- On the VM Clusters tab, select the VM Cluster that you want to work with.
-
On the VM Cluster details page, select the Databases tab to view the list of all databases.
-
On the Databases tab, select the Database that you want to work with.
-
On the Database details page, select the Database information tab to view details.
-
On the Database information tab, in the Encryption section, select Migrate key.
-
In the Migate key panel, provide the following details.
- Select encryption type: Select the encryption type. You can select Oracle Key Vault or External Keystore.
- Select Save changes.