0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

PDBでTDEの設定をする(19c 19.29)

0
Posted at

はじめに

ここでは、改めてCDBの統合モードによるTDEにより PDBのユーザデータ格納用表領域を暗号化する簡易的な手順を示します。前述のPDBクローンが使用するインフラリソースを追求した記事の補足解説ものになります。
関連情報はこちらです。
PDBクローンが使用するインフラリソース(TDEあり)
マニュアル : ウォレットベースの透過的データ暗号化のクイックスタート設定ガイド

環境と手順について

環境は Oracle Database 19c (19.29) for Linuxを使用しました。
Wallet 用のディレクトリを準備します。(/u01/app/oracle/admin/orcl19c/wallet)

[oracle@node1 orcl19c]$ ls -l
合計 28
drwxr-x--- 4 oracle oinstall 24576  1月 14 11:15 adump
drwxr-x--- 4 oracle oinstall   100  1月 13 16:43 dpdump
drwxr-x--- 2 oracle oinstall    36  1月 13 16:42 pfile
drwx------ 2 oracle oinstall     6  1月 14 11:17 wallet ⇦
drwxr-x--- 2 oracle oinstall    44  1月 13 16:10 xdb_wallet

初期化パラメータ WALLET_ROOT と TABLESPACE_ENCRYPTION をセットする

alter system set WALLET_ROOT = '/u01/app/oracle/admin/orcl19c/wallet' scope = spfile; 
alter system set TABLESPACE_ENCRYPTION = AUTO_ENABLE scope = spfile;

(インスタンスの再起動)

alter system set TDE_CONFIGURATION = "KEYSTORE_CONFIGURATION=FILE" scope = both;
administer key management CREATE KEYSTORE identified by Welcome123##;
administer key management CREATE LOCAL AUTO_LOGIN KEYSTORE from keystore identified by Welcome123##;
ADMINISTER KEY MANAGEMENT SET KEYSTORE open IDENTIFIED BY Welcome123## CONTAINER=all;
administer key management SET KEY force keystore identified by Welcome123## with backup container = all;

作成したディレクトリに暗号化キーが生成されます。

[oracle@node1tde]$ pwd
/u01/app/oracle/admin/orcl19c/wallet/tde
[oracle@node1 tde]$ ls -la
合計 20
drwxr-x--- 2 oracle oinstall   80  1月 14 13:00 .
drwx------ 3 oracle oinstall   17  1月 14 12:59 ..
-rw------- 1 oracle oinstall 5526  1月 14 13:00 cwallet.sso
-rw------- 1 oracle oinstall 5465  1月 14 13:00 ewallet.p12
-rw------- 1 oracle oinstall 2553  1月 14 13:00 ewallet_2026011404001866.p12

確認します。

SQL>SELECT CON_ID, STATUS, WRL_PARAMETER FROM V$ENCRYPTION_WALLE
    CON_ID STATUS                         WRL_PARAMETER
---------- ------------------------------ ------------------------------------------------
         1 OPEN                           /u01/app/oracle/admin/orcl19c/wallet/tde/
         2 OPEN
         3 OPEN

既存のPDBに存在するUSERS表領域をオンラインで暗号化してみます。

SQL> alter tablespace USERS encryption ONLINE encrypt;
表領域が変更されました。
 
SQL> select c.name as PDB_NAME, t.name as TBS_NAME, e.ENCRYPTIONALG as ALG, e.STATUS from v$tablespace t, v$encrypted_tablespaces e, v$containers c where e.ts# = t.ts# and e.con_id = t.con_id and e.con_id = c.con_id order by e.con_id, t.name;
 
PDB_NAME                                 TBS_NAME                       ALG     STATUS
---------------------------------------- ------------------------------ ------- ----------
PDB                                      USERS                          AES128  NORMAL

最後に

OCIなどの環境ではTDE前提であるため、あまりTDEを手動で実装する機会は無いかも知れませんが、オンプレミスの検証環境に必要なため作業メモとして残します。

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?