TLS Overview and Configuration

Transport Layer Security (TLS) is used for end-to-end communication encryption.

TLS between a Recovery Appliance and client databases involves the use of certificates that authenticate and encrypt communication.

Certificates describe the server, who it belongs to, its connection string, etc. and is issued and signed by a trusted authority. Customers may choose third-party vendors or Oracle internal CA certificate authority.

For development and testing purpose, some customers choose to use self-signed certificate, which could be created by RACLI command.

For TLS, both types of certificates are required.

This chapter provides general information on obtaining the certificates from a security website, as well as alternatively information on generating the certificates manually with RACLI commands. RACLI (racli create certificate) is a wrapper for openssl operations.

Whether obtained or generated, the created certificate is imported to the Recovery Appliance wallet using racli add certificate so that they are available for the network. Then, finally the

racli alter network establishes the needed encryption mode.

If replication is managed by RACLI, running racli alter network to disable or enable TLS on the downstream Recovery Appliance automatically imports the downstream Recovery Appliance’s certificate into the upstream Recovery Appliance, updates the upstream Recovery Appliance’s tnsnames.ora, and restarts the replication server. Thus, the manual steps mentioned in TLS Replication are no longer required. This is true for bidirectional replication as well.

If replication is not managed by RACLI, and the user runs racli alter network, then the manual steps described in TLS Replication are required.