Configuring Transport Layer Security Encryption
You can configure Oracle Database 19c to use Transport Layer Security (TLS) to protect data in transit and authenticate endpoints.
-
TLS Features in Oracle Database
Learn how TLS certificates, wallets, system certificate stores, one-way TLS, mutual TLS, DN matching, and the TLS handshake flow work in Oracle Database 19c. -
Why TLS Modernization Matters
Modernizing TLS in Oracle Database 19c reduces exposure to legacy protocol and cipher choices, prepares the environment for TLS 1.3, and establishes the foundation for post-quantum key exchange. -
Switching the Cryptographic Provider for Oracle Database 19c
Switch an Oracle Database 19c environment from the legacy cryptographic provider to the next-generation provider. -
Migrate from Oracle Database 19c TLS 1.2 to Oracle Database 19.32 with TLS 1.3
Migrate an Oracle Database 19c environment from TLS 1.2 to TLS 1.3. -
Configuring TLS for the Oracle Database and Client
Follow the detailed procedures for one-way TLS without a client wallet, one-way TLS with a client wallet, and mutual TLS with a client certificate wallet. -
Configuring TLS 1.3
Configure TLS protocol versions and cipher suites for the active cryptographic provider. -
Configuring Post-Quantum Cryptography
Configure ML-KEM and hybrid key exchange for TLS 1.3 after enabling the next-generation cryptographic provider. -
FIPS and Certified Cryptography
Configure the fips.ora parameter model and understand the distinction between FIPS 140-2 and FIPS 140-3 modes. -
Advanced and Optional Configurations
Use optional controls for wallet location, certificate selection, protocol and cipher policy, weak-cipher compatibility, and certificate revocation. -
TLS and Other Oracle Products
Configure TLS consistently across Oracle Database products and deployment patterns. -
Troubleshooting the Transport Layer Security Configuration
Diagnose common TLS wallet, protocol, cipher suite, certificate, and provider issues.