How to clone encrypted PDBs without "shared keys"
During my time as the TDE and OKV PM, I always struggled to understand where customers get command snippets from that never show up in any MOS note, let alone in the TDE documentation. One of my favorites is "using shared key" when cloning encrypted PDBs. This part of the cloning command isn't documented, and Google doesn't find it either — it remains a mystery where it comes from, but it comes up pretty often. The unintended consequence of using "shared key" when cloning encrypted PDBs is that all clones from that source database end up with the SAME TDE master key. Nobody wants that. When an (encrypted) PDB is cloned, that clone is (per definition) 100% identical, and that includes the TDE master key. If you've paid attention to the TDE documentation, you'll have noticed it's recommended to tag a key, for example "FINPDB 2026-08-17 21:06:36Z" (tags are only supported by the TDE wallet and Oracle Key Vault). If that's the key of...