TDE - Lost Password

From: David Barbour <david.barbour1_at_gmail.com>
Date: Fri, 2 Jun 2017 14:30:21 -0500
Message-ID: <CAFH+ifeqW6cq1Dy6fQMCotNmYVXV8jcrmE2sQhpwSi0Dxjz14A_at_mail.gmail.com>



Oracle 12.1.0.2 EE 2-Node RAC
RHEL 6.7 A production database I have to duplicate has 4 tablespaces that were created a while back to test TDE. It was never fully implemented, the data in the tables in these tablespaces are copies of real data but aren't accessed by the application or used at all.

The password for the keystore has been lost. It's auto_login on ASM:

WRL_TYPE             WRL_PARAMETER        STATUS
WALLET_TYPE          WALLET_OR FULLY_BAC     CON_ID
-------------------- -------------------- ------------------------------
-------------------- --------- --------- ----------
ASM                  +ACTIVE/ORCL/wallet/ OPEN
AUTOLOGIN            SINGLE    NO                 0

Since we don't have the password, can I create a new auto_login keystore for which the password will be retained, export or merge the contents (which shouldn't require a password) into the new keystore, close the old keystore which again should not require a password, change the sqlnet.ora to point to the new keystore and breathe a sigh of relief?

There are some enhancement to Key Administration in 12.2, but with 12.1 is my only choice to move to an unencrypted state to copy the tables to an unencrypted tablespace?

--
http://www.freelists.org/webpage/oracle-l
Received on Fri Jun 02 2017 - 21:30:21 CEST

Original text of this message