Controlling TDE Keys
To learn more about the service administrator role, see Oracle Cloud User Roles and Privileges.
-
Transportation Key: The public key that the you download from Oracle Cloud
-
TDE Master Encryption Key: The key that you generate on your premises
-
Encrypted Key File: The file which stores the encrypted TDE Master Encryption Key with the Transportation Key
-
Download Oracle public key and use it to encrypt your own TDE master encryption key.
-
Upload your new TDE master encrypted key.
-
Reset your key: You can replace the given key with your own TDE master encryption key. You must use OpenSSL to generate your own key for replacing the existing master encryption key.
-
Revoke your key: Delete your TDE master encryption key and shut down the system.
-
Restore your key: Restore your key and the system after the revoke operation. You can restore the system only if you provide the exact key that was revoked.
Topics: