Oracle AI Database 26ai: Encryption and key management from the start

Why this matters - Executive summary:
 
New Oracle AI database 26ai can be encrypted and have its encryption keys centrally managed from creation, not through a separate migration project later. That's eliminating, not just reducing, complexity: the same dbca command with a few more lines replaces a follow-on project. Ask your team how key management is handled today; if the answer involves a spreadsheet or a wallet file on a server, you have your answer.
_____________________________________________________________________________________________
 
Two weeks ago I talked about "born encrypted" for Oracle Databases 21c and 26ai. Many readers have asked about key management in such a scenario. That makes sense; when all databases are encrypted from the start, proper key management becomes a requirement.
With Oracle, you are in good hands:
This dbca code in Oracle AI database 26ai will encrypt your database while it is being built, and the TDE master keys live in Oracle Key Vault; no TDE wallet, no migration:

dbca -silent -createDatabase  \
... 
  -configureTDE TRUE  \
    -tdeKeystoreConfigType OKV  \
    -okvWalletName ${ORACLE_UNQNAME^^}  \
    -tdeWalletRoot /directory/for/TDE/  \
    -TdeWalletPassword <OKV endpoint password>  \
    -createTDESepsWallet  \
    -encryptTablespaces SYSTEM:true,SYSAUX:true,USERS:true  \
    -tdeWalletLoginType AUTO_LOGIN  \
    -initparams PKCS11_LIBRARY_LOCATION=/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/liborapkcs.so


Let's go through it step-by step.
1.) Before this database can be build, the OKV client needs to be installed; this can be fully scripted. An example script is documented in chapter 2.4.3. of the OKV RESTful Services Administrator's Guide. The OKV client software must be installed into "-TdeWalletRoot"/okv.
2.) The "okv endpoint provision" command needs an extra parameter for 26ai databases: "--arch db26ai"
3.) When you run the OKV client root script, use 
"WALLET_ROOT/okv/bin/root.sh --okv_pkcs11_library_location"
 4.) The extra parameter from 3.) will install the PKCS#11 library into a different directory, which is
/opt/oracle/extapi/64/pkcs11/okv/${OKV_CLUSTER_VERSION}/lib/
The "OKV cluster version" can be extracted with the following command:
export OKV_CLUSTER_VERSION=$(okv cluster info get | jq -r .value.clusterVersion)
This way, each database has it's own individual PKCS#11 library. I will explain in detail what this all means in a later blog.
5.) The okvWalletName is usually the ORACLE_UNQNAME in a RAC environment, and the ORACLE_SID with single instance databases.
6.) dbca does not allow "-TdeWalletLoginType" to be LOCAL_AUTO_OPEN, even though, especially in 26ai, the ties of a LOCAL auto-open wallet to the underlying OS are much stronger than with older DB releases.

After this database has been built, it's encryption status will be similar to:

   PDB_NAME        TBS_NAME        ENC_ALG MODE  ENC_STATUS
   --------------- --------------- ------- ----- ----------
   CDB$ROOT        SYSAUX          AES256  XTS   NORMAL
   CDB$ROOT        SYSTEM          AES256  XTS   NORMAL
   CDB$ROOT        USERS           AES256  XTS   NORMAL
   CDB$ROOT        TEMP            ----    ----  ----
   CDB$ROOT        UNDOTBS1        ----    ----  ----
   CDB$ROOT        UNDOTBS2        ----    ----  ----
   FINPDB26        SYSAUX          AES256  XTS   NORMAL
   FINPDB26        SYSTEM          AES256  XTS   NORMAL
   FINPDB26        USERS           AES256  XTS   NORMAL
   FINPDB26        TEMP            ----    ----  ----
   FINPDB26        UNDOTBS1        ----    ----  ----

   FINPDB26        UNDO_5          ----    ----  ----

and the keystore status will be:

   PDB_NAME  WALLET_TYPE  STATUS                         WRL_TYPE
   --------- ------------ ------------------------------ ---------
   CDB$ROOT  AUTOLOGIN    OPEN_UNKNOWN_MASTER_KEY_STATUS FILE
   CDB$ROOT  OKV          OPEN                           OKV
   FINPDB26  AUTOLOGIN    OPEN_UNKNOWN_MASTER_KEY_STATUS FILE
   FINPDB26  OKV          OPEN                           OKV

In older database releases, the wallet status is displayed as "OPEN_NO_MASTER_KEY".

Also,
the Oracle database has it's own PKCS#11 library:

PKCS11_LIB_PATH
---------------------------------------------------------------
/opt/oracle/extapi/64/pkcs11/okv/21.15.0.0.0/lib/liborapkcs.so

This eliminates 23 manual steps that are documented in chapter 10.3.2. of the 26ai TDE documentation.
__________________________________________________________________________________________
Contact me via email or WhatsApp, I read every message.

Comments

Popular posts from this blog

TDE Healthcheck

Upgrade encrypted databases to 26ai

Encryption and Compression in Exadata: How It Really Works