Posts

Showing posts from July, 2026

Oracle AI Database 26ai: Born encrypted

Why this matters - Executive summary: New Oracle AI database 26ai can be encrypted the moment they're created, not "later" when all stars align. That closes a real exposure window regulators and auditors specifically look for, with far less engineering effort than the manual approach. If your team is building new databases and isn't already doing this by default, that's a gap worth closing now.  ____________________________________________________________________________________________ TDE has come a long way; from the humble beginnings of TDE column encryption in Oracle Database 10gR2 in July 2005 to automated and mandatory encryption for all Oracle databases that are controlled by OCI. Starting with Oracle database 21c, DBCA (Database Configuration Assistant) can create encrypt ed (primary and standby) databases; this is do cumented here  for 21c and here  for 26ai (did you notice that TDE in 26ai has its own documentation book, separated from Data Redaction?) ...

The TDE Academy

Did you miss the "TDE Academy"? A long time ago, I published three videos on YouTube that go through a complete upgrade of encrypted PDBs from 12.1.0.2, 12.2.0.1 and 18c databases to 19c. At one point, they were made private. Here are the links: Upgrade encrypted PDBs to 19c from 18c: https://youtu.be/onIQ3CDsjik 12.2.0.1.: https://youtu.be/oJipexiHBXk 12.1.0.2.: https://youtu.be/ql6352lmi24 You can also find those links in chapter 7.8.3.4. of the 19c Advanced Security Guide. Happy upgrading !!  __________________________________________________________________________________________ Contact me via email or WhatsApp , I read every message.

Encryption and Compression in Exadata: How It Really Works

After a great vacation, I'm finally back with a new blog post. This one is about two weeks later than my usual Thursday schedule, but I hope you'll find it worth the wait. Today's topic is a question that comes up surprisingly often: how do compression and Transparent Data Encryption (TDE) actually work in Oracle Exadata? The answer is actually quite simple - with one important exception. Everything described here applies equally to Oracle Exadata and all of its deployment models, including ExaDB-C@C, ADB-C@C, ADB-D, and ExaDB-D, whether deployed on-premises, in OCI, or in supported third-party clouds. The Normal Data Path The fundamental rule is simple: Compression always happens before encryption. This has to be the case because encrypted data is essentially random and therefore cannot be compressed efficiently. Oracle's implementation of TDE tablespace encryption is fully compatible with Oracle compression technologies, including Exadata Hybrid Columnar Compression ...