Oracle AI Database 26ai: Encryption and key management from the start
Why this matters - Executive summary:
New Oracle AI database 26ai can be encrypted and have its encryption keys centrally managed
from creation, not through a separate migration project later. That's
eliminating, not just reducing, complexity: the same dbca command with a
few more lines replaces a follow-on project. Ask your team how key
management is handled today; if the answer involves a spreadsheet or a
wallet file on a server, you have your answer.
_____________________________________________________________________________________________
Two weeks ago I talked about "born encrypted" for Oracle Databases 21c and 26ai. Many readers have asked about key management in such a scenario. That makes sense; when all databases are encrypted from the start, proper key management becomes a requirement.
With Oracle, you are in good hands:
This dbca code in Oracle AI database 26ai will encrypt your database while it is being built, and the TDE master keys live in Oracle Key Vault; no TDE wallet, no migration:
dbca -silent -createDatabase \
...
...
-configureTDE TRUE \
-tdeKeystoreConfigType OKV \
-okvWalletName ${ORACLE_UNQNAME^^} \
-tdeWalletRoot /directory/for/TDE/ \
-TdeWalletPassword <OKV endpoint password> \
-createTDESepsWallet \
-encryptTablespaces SYSTEM:true,SYSAUX:true,USERS:true \
-tdeWalletLoginType AUTO_LOGIN \
-initparams PKCS11_LIBRARY_LOCATION=/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/liborapkcs.so
Let's go through it step-by step.
-tdeKeystoreConfigType OKV \
-okvWalletName ${ORACLE_UNQNAME^^} \
-tdeWalletRoot /directory/for/TDE/ \
-TdeWalletPassword <OKV endpoint password> \
-createTDESepsWallet \
-encryptTablespaces SYSTEM:true,SYSAUX:true,USERS:true \
-tdeWalletLoginType AUTO_LOGIN \
-initparams PKCS11_LIBRARY_LOCATION=/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/liborapkcs.so
Let's go through it step-by step.
1.) Before this database can be build, the OKV client needs to be installed; this can be fully scripted. An example script is documented in chapter 2.4.3. of the OKV RESTful Services Administrator's Guide. The OKV client software must be installed into "-TdeWalletRoot"/okv.
2.) The "okv endpoint provision" command needs an extra parameter for 26ai databases: "--arch db26ai"
3.) When you run the OKV client root script, use
"WALLET_ROOT/okv/bin/root.sh --okv_pkcs11_library_location"
4.) The extra parameter from 3.) will install the PKCS#11 library into a different directory, which is
/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/
"WALLET_ROOT/okv/bin/root.sh --okv_pkcs11_library_location"
4.) The extra parameter from 3.) will install the PKCS#11 library into a different directory, which is
/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/
The "OKV cluster version" can be extracted with the following command:
export OKV_CLUSTER_VERSION=$(okv cluster info get | jq -r .value.clusterVersion)
This way, each database has it's own individual PKCS#11 library. I will explain in detail what this all means in a later blog.
export OKV_CLUSTER_VERSION=$(okv cluster info get | jq -r .value.clusterVersion)
This way, each database has it's own individual PKCS#11 library. I will explain in detail what this all means in a later blog.
5.) The okvWalletName is usually the ORACLE_UNQNAME in a RAC environment, and the ORACLE_SID with single instance databases.
6.) dbca does not allow "-TdeWalletLoginType" to be LOCAL_AUTO_OPEN, even though, especially in 26ai, the ties of a LOCAL auto-open wallet to the underlying OS are much stronger than with older DB releases.
After this database has been built, it's encryption status will be similar to:
PDB_NAME TBS_NAME ENC_ALG MODE ENC_STATUS
--------------- --------------- ------- ----- ----------
CDB$ROOT SYSAUX AES256 XTS NORMAL
CDB$ROOT SYSTEM AES256 XTS NORMAL
CDB$ROOT USERS AES256 XTS NORMAL
CDB$ROOT TEMP ---- ---- ----
CDB$ROOT UNDOTBS1 ---- ---- ----
CDB$ROOT UNDOTBS2 ---- ---- ----
FINPDB26 SYSAUX AES256 XTS NORMAL
FINPDB26 SYSTEM AES256 XTS NORMAL
FINPDB26 USERS AES256 XTS NORMAL
FINPDB26 TEMP ---- ---- ----
FINPDB26 UNDOTBS1 ---- ---- ----
FINPDB26 UNDO_5 ---- ---- ----
After this database has been built, it's encryption status will be similar to:
PDB_NAME TBS_NAME ENC_ALG MODE ENC_STATUS
--------------- --------------- ------- ----- ----------
CDB$ROOT SYSAUX AES256 XTS NORMAL
CDB$ROOT SYSTEM AES256 XTS NORMAL
CDB$ROOT USERS AES256 XTS NORMAL
CDB$ROOT TEMP ---- ---- ----
CDB$ROOT UNDOTBS1 ---- ---- ----
CDB$ROOT UNDOTBS2 ---- ---- ----
FINPDB26 SYSAUX AES256 XTS NORMAL
FINPDB26 SYSTEM AES256 XTS NORMAL
FINPDB26 USERS AES256 XTS NORMAL
FINPDB26 TEMP ---- ---- ----
FINPDB26 UNDOTBS1 ---- ---- ----
FINPDB26 UNDO_5 ---- ---- ----
and the keystore status will be:
PDB_NAME WALLET_TYPE STATUS WRL_TYPE
--------- ------------ ------------------------------ ---------
CDB$ROOT AUTOLOGIN OPEN_UNKNOWN_MASTER_KEY_STATUS FILE
CDB$ROOT OKV OPEN OKV
FINPDB26 AUTOLOGIN OPEN_UNKNOWN_MASTER_KEY_STATUS FILE
FINPDB26 OKV OPEN OKV
In older database releases, the wallet status is displayed as "OPEN_NO_MASTER_KEY".
Also, the Oracle database has it's own PKCS#11 library:
PKCS11_LIB_PATH
---------------------------------------------------------------
/opt/oracle/extapi/64/pkcs11/okv/21.15.0.0.0/lib/liborapkcs.so
This eliminates 23 manual steps that are documented in chapter 10.3.2. of the 26ai TDE documentation.
Comments
Post a Comment