Encrypting the Cloud EPM User Password
Describes how to encrypt the Cloud EPM user password for the agent parameter file.
Use the password utility to create an AES-GCM encrypted value for CLOUD_PASSWORD. The returned value begins with {AES2}{GCM}.
To encrypt the Oracle Fusion Cloud Enterprise Performance Management user password:
- At a command prompt, run the password utility and provide the full path to the active
agentparams.inifile:- Windows:
Agent Home\EPMAgent\bin\encryptpassword.bat C:\path\to\agentparams.ini - Linux or UNIX:
Agent Home/EPMAgent/bin/encryptpassword.sh /path/to/agentparams.ini
- Windows:
- Enter the password only when prompted in command line.
Note:
For EPM Automate, passwords are stored in.epwfiles. Although the passwords do not begin with{AES2}{GCM}, they are supported when generated using the current version of EPM Automate. - Copy the returned {AES2}{GCM} encrypted value and paste it in CLOUD_PASSWORD in the active
agentparams.inifile.The utility loads or creates an EPMAgent local key in ${EPM_APP_DATA_HOME}/config/.prefs.key. The key is not stored in agentparams.ini, in the encrypted value, or in epmautomate.jar. No key environment variable or additional startup prompt is required.
On Linux or UNIX, the key file is restricted to the owner. On Windows, the key is protected by DPAPI for the Windows identity that created it. A Windows service must run under that same identity.
Each encryption produces a different encrypted value for the same password. The utility always creates AES-GCM values and cannot create legacy ciphertext.
During the six-month migration period, recognized legacy direct password values continue to work with a warning. Re-encrypt each password with this utility before the migration period ends. After that period, legacy values are rejected.
If a GCM value is altered, malformed, or cannot be authenticated, the agent fails immediately and does not try a legacy algorithm.