Chapter 20 · Security: Privileges, Roles, Profiles, Unified Auditing, VPD, and Encryption
TLS/Native Network Encryption, TDE Wallet/Keystore Concepts, Backup Encryption, and Key Governance
Separate encryption in transit, TDE at rest, and backup/export encryption; inspect 26ai TLS/NNE and wallet state, then engineer keystore/key rotation/backup/restore dependencies without placing real secrets or keys in course files.
Learning outcomes
ServiceHub now enforces least privilege, account policy, auditing and row isolation. An attacker who captures database traffic or steals a datafile/backup can still bypass those SQL-layer controls. Oracle separates three encryption planes: network encryption protects bytes in transit, Transparent Data Encryption (TDE) protects database files at rest, and RMAN/Data Pump encryption protects backup/export artifacts. Each has different keys, failure modes and recovery dependencies.
Distinguish TLS and Native Network Encryption from TDE and backup/export encryption.
Inspect the current session network-security banner and design TLS with 26ai certificate hostname/DN validation.
Inspect WALLET_ROOT/TDE_CONFIGURATION/V$ENCRYPTION_WALLET before attempting any keystore changes.
Explain united versus isolated PDB keystore concepts, key rotation/backup and the Free limitation on per-PDB keystores/online existing-tablespace conversion.
Build a key-governance/restore checklist so encryption cannot make an otherwise valid backup unrecoverable.
Mandatory examples target Oracle AI Database Free 26ai, reviewed against RU 23.26.3, SQL Developer 26.2, and SQLcl 26.2.1. Free remains limited to 2 foreground CPU cores, 2 GB combined SGA/PGA memory, 12 GB user data, and one installation per logical environment; Oracle provides neither Release Update patches nor Support service requests for Free. The course CDB/PDB baseline is FREE/FREEPDB1. Security administration is performed in the narrowest required container with dedicated administrative roles such as AUDIT_ADMIN or SYSKM where possible, rather than making the application runtime SYSDBA. Current licensing lists Fine-Grained Auditing, Virtual Private Database (VPD), Data Redaction, Transparent Data Encryption (TDE), Oracle Advanced Security, Database Vault, and Privilege Analysis as available in Free. Network encryption through Native Network Encryption (NNE) and Transport Layer Security (TLS) is available across supported licensed editions and is no longer an Oracle Advanced Security feature. No real password, private key, certificate private material, wallet password, recovery secret, or API credential appears in these files.
1. Encryption boundaries solve different threats
| Mechanism | Protects | Does not automatically protect |
|---|---|---|
| TLS / Native Network Encryption | Oracle Net data in transit | Stolen datafiles/backups, privileged SQL access |
| TDE tablespace/column encryption | Database files, temp/redo/undo implications around encrypted data | Authorized SELECT results, client traffic by itself |
| RMAN backup encryption | RMAN backup sets | Live database files/network traffic |
| Data Pump dump encryption | Logical export file contents | RMAN/datafiles/network unless separately configured |
2. Prove the current session's network protection instead of assuming it
SELECT network_service_bannerFROM v$session_connect_infoWHERE sid = SYS_CONTEXT('USERENV','SID')ORDER BY network_service_banner;
Depending on the connection, banners can identify AES encryption/integrity adapters or TLS-related services. A local connection can differ from remote application traffic, so run the check through the same service/protocol path the application uses.
3. Native Network Encryption versus TLS
Native Network Encryption (NNE) is Oracle Net's symmetric encryption/integrity negotiation. Transport Layer Security (TLS) is the industry-standard certificate-based protocol. Both can provide confidentiality/integrity; TLS also supports Public Key Infrastructure (PKI) certificate authentication. Oracle's current security guidance recommends adopting TLS.
SQLNET.ENCRYPTION_SERVER=REQUIREDSQLNET.ENCRYPTION_TYPES_SERVER=(AES256,AES192,AES128)SQLNET.CRYPTO_CHECKSUM_SERVER=REQUIREDSQLNET.CRYPTO_CHECKSUM_TYPES_SERVER=(SHA512,SHA384,SHA256)
Client/server settings negotiate. If one side says
REQUIRED and the peer cannot negotiate an allowed
algorithm, the connection fails—which is preferable to silently
sending plaintext when encryption is mandatory.
4. 26ai supports TLS 1.3 and strengthens certificate matching
Oracle AI Database 26ai supports TLS 1.3. It
also tightens SSL_SERVER_DN_MATCH: strict matching
checks both listener and database-server certificates. For
partial matching, the connect descriptor
HOSTNAME can match the certificate Distinguished
Name (DN)/Subject Alternative Name (SAN); the
SERVICE_NAME is no longer used for that partial
match.
(DESCRIPTION= (ADDRESS=(PROTOCOL=TCPS) (HOST=servicehub-db.example.com) (PORT=2484)) (CONNECT_DATA=(SERVICE_NAME=servicehub.example.com)) (SECURITY= (SSL_SERVER_DN_MATCH=TRUE) ))
Certificate trust chains, SAN/hostname, listener and server certificate identity must be tested with the exact client/driver. Disabling DN matching merely to make a certificate error disappear weakens server-authentication protection.
5. TDE uses a hierarchy of data keys and TDE master encryption keys
TDE encrypts table/tablespace data using data-encryption keys protected by a TDE master encryption key held in an Oracle software keystore or external key manager. The database therefore needs both encrypted files and usable key material after restore/failover.
SHOW PARAMETER wallet_rootSHOW PARAMETER tde_configurationSELECT con_id, wrl_type, status, wallet_type, keystore_mode, fully_backed_up, wrl_parameterFROM v$encryption_walletORDER BY con_id;
Oracle warns that querying V$ENCRYPTION_WALLET can
itself validate/open some auto-login external-keystore
configurations and can emit alert-log warnings if TDE is not
configured. Treat the query as operational inspection, not a
health probe to run every second.
6. WALLET_ROOT is configuration, not a casual SQL toggle
WALLET_ROOT has no default, is not dynamically
modifiable, and is not PDB-modifiable.
TDE_CONFIGURATION depends on it. If the Free
installation does not already have a TDE keystore, provisioning
one is an environment-level change that can require setting
WALLET_ROOT in the SPFILE and restarting.
-- Example architecture only; do not paste into a shared production host.ALTER SYSTEM SET WALLET_ROOT='/secure/oracle/wallets/FREE' SCOPE=SPFILE;-- Restart is required because WALLET_ROOT is not dynamically modifiable.ALTER SYSTEM SET TDE_CONFIGURATION='KEYSTORE_CONFIGURATION=FILE' SCOPE=BOTH;
Use OS ownership/permissions, backup and secret-management controls on the wallet path. The lesson intentionally does not invent a filesystem path or execute a restart.
7. Never hard-code the keystore password
ACCEPT tde_pwd CHAR PROMPT 'TDE keystore password: ' HIDEADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY "&tde_pwd";ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "&tde_pwd";ADMINISTER KEY MANAGEMENT SET ENCRYPTION KEY IDENTIFIED BY "&tde_pwd" WITH BACKUP USING 'sh20_initial_key';
The variable is transient; no actual password is present in this course. In automated production, use an approved secret mechanism/external store rather than generating command files containing substituted secrets. Any operation that changes a password-protected wallet should use the documented backup workflow.
8. Free TDE boundary: included, but not every enterprise operation
The current licensing matrix includes Oracle Advanced Security and TDE columns/tablespaces in Free. It specifically notes that the online method to encrypt/rekey/decrypt an existing tablespace is not supported in Free. It also marks Keystore for Each Pluggable Database unavailable in Free, so do not teach isolated per-PDB keystores as the mandatory Free architecture.
On EE/EE-ES, TDE and Data Redaction require the separately licensed Oracle Advanced Security option. In 26ai, AES256 with XTS is the default modern TDE tablespace encryption behavior for relevant new encryption operations.
9. Optional encrypted-column proof when the keystore is already open
BEGIN EXECUTE IMMEDIATE 'DROP TABLE sh20_tde_case PURGE';EXCEPTION WHEN OTHERS THEN IF SQLCODE != -942 THEN RAISE; END IF;END;/CREATE TABLE sh20_tde_case ( customer_id NUMBER PRIMARY KEY, email_addr VARCHAR2(120) ENCRYPT USING 'AES256' NO SALT);INSERT INTO sh20_tde_caseVALUES(1,'customer@example.invalid');COMMIT;SELECT table_name,column_name,encryption_alg,saltFROM user_encrypted_columnsWHERE table_name='SH20_TDE_CASE';DROP TABLE sh20_tde_case PURGE;
TDE is transparent to authorized SQL: a permitted SELECT still returns plaintext to the session. Network encryption and least privilege are still required.
10. RMAN backup encryption adds a separate recoverability dependency
RMAN supports transparent keystore-based, password-based and dual-mode backup encryption. Transparent mode is preferred for routine same-database operations when the key infrastructure is available. If the wallet/keys are lost, an intact encrypted backup can become unrecoverable.
SHOW ENCRYPTION ALGORITHM;CONFIGURE ENCRYPTION FOR DATABASE ON;CONFIGURE ENCRYPTION ALGORITHM TO 'AES256';BACKUP AS BACKUPSET CURRENT CONTROLFILE TAG 'SH20_ENCRYPTED_CF';
26ai uses modern AES-XTS algorithms for new RMAN encrypted
backups when COMPATIBLE >= 23.0.0; older
encrypted backups remain restorable according to supported
algorithms. RMAN backup encryption to disk is part of Advanced
Security: included in Free but extra-cost on EE/EE-ES.
11. Data Pump encryption is a logical-export protection, not TDE
Data Pump can encrypt dump-file content using password, transparent or dual modes where the deployed edition/feature is supported. Its encryption password is independent from a TDE column's encryption key. A Data Pump file is also not an RMAN backup and does not provide media recovery.
The current licensing manual includes Data Pump Export File encryption in Oracle Advanced Security and marks Advanced Security included in Free, while Data Pump utility documentation retains edition-specific restrictions for ENCRYPTION_PASSWORD modes. Verify the exact 26ai Free binary/tool mode before making encrypted Data Pump a mandatory workflow; this chapter keeps RMAN/TDE as the executable Free encryption path.
12. Key backup, separation and recovery drill
The keystore is part of the backup set even when it is not physically stored inside the RMAN piece. Protect it as an independent recovery artifact.
ACCEPT tde_pwd CHAR PROMPT 'TDE keystore password: ' HIDEADMINISTER KEY MANAGEMENT BACKUP KEYSTORE USING 'sh20_pre_rotation' IDENTIFIED BY "&tde_pwd";
- Keep the password-protected keystore backup in a separate failure/security domain from encrypted database backups.
- Do not store an auto-login wallet next to encrypted backup media; possession of both can defeat the intended separation.
-
Record key IDs/rotation dates and
FULLY_BACKED_UPstate without storing secret material in tickets. - Copy required TDE key material correctly to Data Guard/RAC/duplicate/restore environments.
- Test a Chapter 15 isolated restore assuming the original database host and wallet directory are gone.
13. Deliberately wrong: rotate/delete old TDE keys after “successful backup”
Older tablespace/datafile/backup content can still depend on older master keys. Deleting a wallet/key because a newer key is active can make historical backups or encrypted data unreadable. Rekeying creates a new protection layer; it does not automatically eliminate every dependency on old key material.
Never delete retired key material until recovery/retention policy proves that no retained database copy, backup, standby, archive or legal hold can require it. Test that assertion with restores, not a spreadsheet alone.
14. Production judgment and chapter close
Use TLS for modern heterogeneous client/server encryption and certificate authentication; use NNE where Oracle-native deployment requirements justify it. Use TDE for datafiles at rest, backup encryption for backup media, and authorization/VPD/redaction for what authenticated sessions may see. Maintain keys, trust stores and certificates as first-class infrastructure with rotation, expiry, backup and disaster-recovery ownership.
Current baseline is 26ai RU 23.26.3. TLS 1.3 and stricter
listener/server certificate matching are 26ai behavior.
WALLET_ROOT is static and may require restart when
first configured; no chapter lab raises COMPATIBLE.
TDE/Advanced Security is included in Free but extra-cost on
EE/EE-ES. Free does not support online conversion of existing
tablespaces nor per-PDB isolated keystores. The next chapter
builds workload governance on top of these security boundaries
using Resource Manager, services and capacity controls.
Check your understanding
- Does TLS protect a stolen datafile?
- What important SSL_SERVER_DN_MATCH behavior changed in 26ai?
- Why can an intact encrypted RMAN backup still be unrecoverable?
- Can Free use TDE?
- What configuration fact makes first-time WALLET_ROOT setup operationally significant?
Review the answers
No. TLS protects data in transit; TDE/backup encryption protect at-rest artifacts.
Strict matching checks both listener and database-server certificates, and partial matching uses HOSTNAME rather than SERVICE_NAME.
The required keystore/master key or password can be lost; encryption deliberately makes ciphertext unusable without the key.
Yes. TDE/Advanced Security are included in Free, with specific limitations such as no online existing-tablespace encrypt/rekey/decrypt conversion.
WALLET_ROOT is not dynamically modifiable or PDB-modifiable, so introducing/changing it can require SPFILE configuration and an instance restart.
Authoritative references
- Securing Data for Database Connections — TLS versus native network encryption
- Configuring Transport Layer Security Encryption — certificate/DN matching
- Transparent Data Encryption Guide — keystore/key/tablespace encryption
- WALLET_ROOT — static wallet-root parameter
- Licensing Information — Advanced Security/TDE/Redaction/network-encryption boundaries