Chapter 20 · Security: Privileges, Roles, Profiles, Unified Auditing, VPD, and Encryption

TLS/Native Network Encryption, TDE Wallet/Keystore Concepts, Backup Encryption, and Key Governance

Separate encryption in transit, TDE at rest, and backup/export encryption; inspect 26ai TLS/NNE and wallet state, then engineer keystore/key rotation/backup/restore dependencies without placing real secrets or keys in course files.

Advanced130–150 minutesTLS/NNE/TDE/RMAN encryption governance labTLS 1.3 supported in 26aiTDE wallet setup may require restart; no secrets in filesLast reviewed: August 2026

Learning outcomes

ServiceHub now enforces least privilege, account policy, auditing and row isolation. An attacker who captures database traffic or steals a datafile/backup can still bypass those SQL-layer controls. Oracle separates three encryption planes: network encryption protects bytes in transit, Transparent Data Encryption (TDE) protects database files at rest, and RMAN/Data Pump encryption protects backup/export artifacts. Each has different keys, failure modes and recovery dependencies.

01

Distinguish TLS and Native Network Encryption from TDE and backup/export encryption.

02

Inspect the current session network-security banner and design TLS with 26ai certificate hostname/DN validation.

03

Inspect WALLET_ROOT/TDE_CONFIGURATION/V$ENCRYPTION_WALLET before attempting any keystore changes.

04

Explain united versus isolated PDB keystore concepts, key rotation/backup and the Free limitation on per-PDB keystores/online existing-tablespace conversion.

05

Build a key-governance/restore checklist so encryption cannot make an otherwise valid backup unrecoverable.

Generation-time security baseline and operational boundary

Mandatory examples target Oracle AI Database Free 26ai, reviewed against RU 23.26.3, SQL Developer 26.2, and SQLcl 26.2.1. Free remains limited to 2 foreground CPU cores, 2 GB combined SGA/PGA memory, 12 GB user data, and one installation per logical environment; Oracle provides neither Release Update patches nor Support service requests for Free. The course CDB/PDB baseline is FREE/FREEPDB1. Security administration is performed in the narrowest required container with dedicated administrative roles such as AUDIT_ADMIN or SYSKM where possible, rather than making the application runtime SYSDBA. Current licensing lists Fine-Grained Auditing, Virtual Private Database (VPD), Data Redaction, Transparent Data Encryption (TDE), Oracle Advanced Security, Database Vault, and Privilege Analysis as available in Free. Network encryption through Native Network Encryption (NNE) and Transport Layer Security (TLS) is available across supported licensed editions and is no longer an Oracle Advanced Security feature. No real password, private key, certificate private material, wallet password, recovery secret, or API credential appears in these files.

1. Encryption boundaries solve different threats

Mechanism Protects Does not automatically protect
TLS / Native Network Encryption Oracle Net data in transit Stolen datafiles/backups, privileged SQL access
TDE tablespace/column encryption Database files, temp/redo/undo implications around encrypted data Authorized SELECT results, client traffic by itself
RMAN backup encryption RMAN backup sets Live database files/network traffic
Data Pump dump encryption Logical export file contents RMAN/datafiles/network unless separately configured

2. Prove the current session's network protection instead of assuming it

sql · current connection security banner
SELECT network_service_bannerFROM v$session_connect_infoWHERE sid = SYS_CONTEXT('USERENV','SID')ORDER BY network_service_banner;

Depending on the connection, banners can identify AES encryption/integrity adapters or TLS-related services. A local connection can differ from remote application traffic, so run the check through the same service/protocol path the application uses.

3. Native Network Encryption versus TLS

Native Network Encryption (NNE) is Oracle Net's symmetric encryption/integrity negotiation. Transport Layer Security (TLS) is the industry-standard certificate-based protocol. Both can provide confidentiality/integrity; TLS also supports Public Key Infrastructure (PKI) certificate authentication. Oracle's current security guidance recommends adopting TLS.

text · NNE server-side sqlnet.ora shape
SQLNET.ENCRYPTION_SERVER=REQUIREDSQLNET.ENCRYPTION_TYPES_SERVER=(AES256,AES192,AES128)SQLNET.CRYPTO_CHECKSUM_SERVER=REQUIREDSQLNET.CRYPTO_CHECKSUM_TYPES_SERVER=(SHA512,SHA384,SHA256)

Client/server settings negotiate. If one side says REQUIRED and the peer cannot negotiate an allowed algorithm, the connection fails—which is preferable to silently sending plaintext when encryption is mandatory.

4. 26ai supports TLS 1.3 and strengthens certificate matching

Oracle AI Database 26ai supports TLS 1.3. It also tightens SSL_SERVER_DN_MATCH: strict matching checks both listener and database-server certificates. For partial matching, the connect descriptor HOSTNAME can match the certificate Distinguished Name (DN)/Subject Alternative Name (SAN); the SERVICE_NAME is no longer used for that partial match.

text · client connect-descriptor security shape
(DESCRIPTION=  (ADDRESS=(PROTOCOL=TCPS)           (HOST=servicehub-db.example.com)           (PORT=2484))  (CONNECT_DATA=(SERVICE_NAME=servicehub.example.com))  (SECURITY=    (SSL_SERVER_DN_MATCH=TRUE)  ))

Certificate trust chains, SAN/hostname, listener and server certificate identity must be tested with the exact client/driver. Disabling DN matching merely to make a certificate error disappear weakens server-authentication protection.

5. TDE uses a hierarchy of data keys and TDE master encryption keys

TDE encrypts table/tablespace data using data-encryption keys protected by a TDE master encryption key held in an Oracle software keystore or external key manager. The database therefore needs both encrypted files and usable key material after restore/failover.

sql · non-destructive TDE preflight
SHOW PARAMETER wallet_rootSHOW PARAMETER tde_configurationSELECT  con_id,  wrl_type,  status,  wallet_type,  keystore_mode,  fully_backed_up,  wrl_parameterFROM v$encryption_walletORDER BY con_id;

Oracle warns that querying V$ENCRYPTION_WALLET can itself validate/open some auto-login external-keystore configurations and can emit alert-log warnings if TDE is not configured. Treat the query as operational inspection, not a health probe to run every second.

6. WALLET_ROOT is configuration, not a casual SQL toggle

WALLET_ROOT has no default, is not dynamically modifiable, and is not PDB-modifiable. TDE_CONFIGURATION depends on it. If the Free installation does not already have a TDE keystore, provisioning one is an environment-level change that can require setting WALLET_ROOT in the SPFILE and restarting.

sql · design only — choose a protected OS path; no real secrets in script
-- Example architecture only; do not paste into a shared production host.ALTER SYSTEM SET WALLET_ROOT='/secure/oracle/wallets/FREE'  SCOPE=SPFILE;-- Restart is required because WALLET_ROOT is not dynamically modifiable.ALTER SYSTEM SET TDE_CONFIGURATION='KEYSTORE_CONFIGURATION=FILE'  SCOPE=BOTH;

Use OS ownership/permissions, backup and secret-management controls on the wallet path. The lesson intentionally does not invent a filesystem path or execute a restart.

7. Never hard-code the keystore password

text · SQLcl/SQL*Plus pattern after approved WALLET_ROOT setup
ACCEPT tde_pwd CHAR PROMPT 'TDE keystore password: ' HIDEADMINISTER KEY MANAGEMENT CREATE KEYSTORE  IDENTIFIED BY "&tde_pwd";ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN  IDENTIFIED BY "&tde_pwd";ADMINISTER KEY MANAGEMENT SET ENCRYPTION KEY  IDENTIFIED BY "&tde_pwd"  WITH BACKUP USING 'sh20_initial_key';

The variable is transient; no actual password is present in this course. In automated production, use an approved secret mechanism/external store rather than generating command files containing substituted secrets. Any operation that changes a password-protected wallet should use the documented backup workflow.

8. Free TDE boundary: included, but not every enterprise operation

The current licensing matrix includes Oracle Advanced Security and TDE columns/tablespaces in Free. It specifically notes that the online method to encrypt/rekey/decrypt an existing tablespace is not supported in Free. It also marks Keystore for Each Pluggable Database unavailable in Free, so do not teach isolated per-PDB keystores as the mandatory Free architecture.

On EE/EE-ES, TDE and Data Redaction require the separately licensed Oracle Advanced Security option. In 26ai, AES256 with XTS is the default modern TDE tablespace encryption behavior for relevant new encryption operations.

9. Optional encrypted-column proof when the keystore is already open

sql · run only when V$ENCRYPTION_WALLET shows a usable/open key
BEGIN  EXECUTE IMMEDIATE 'DROP TABLE sh20_tde_case PURGE';EXCEPTION WHEN OTHERS THEN  IF SQLCODE != -942 THEN RAISE; END IF;END;/CREATE TABLE sh20_tde_case (  customer_id NUMBER PRIMARY KEY,  email_addr  VARCHAR2(120)    ENCRYPT USING 'AES256' NO SALT);INSERT INTO sh20_tde_caseVALUES(1,'customer@example.invalid');COMMIT;SELECT table_name,column_name,encryption_alg,saltFROM user_encrypted_columnsWHERE table_name='SH20_TDE_CASE';DROP TABLE sh20_tde_case PURGE;

TDE is transparent to authorized SQL: a permitted SELECT still returns plaintext to the session. Network encryption and least privilege are still required.

10. RMAN backup encryption adds a separate recoverability dependency

RMAN supports transparent keystore-based, password-based and dual-mode backup encryption. Transparent mode is preferred for routine same-database operations when the key infrastructure is available. If the wallet/keys are lost, an intact encrypted backup can become unrecoverable.

text · transparent RMAN path — only after TDE keystore/key setup
SHOW ENCRYPTION ALGORITHM;CONFIGURE ENCRYPTION FOR DATABASE ON;CONFIGURE ENCRYPTION ALGORITHM TO 'AES256';BACKUP AS BACKUPSET  CURRENT CONTROLFILE  TAG 'SH20_ENCRYPTED_CF';

26ai uses modern AES-XTS algorithms for new RMAN encrypted backups when COMPATIBLE >= 23.0.0; older encrypted backups remain restorable according to supported algorithms. RMAN backup encryption to disk is part of Advanced Security: included in Free but extra-cost on EE/EE-ES.

11. Data Pump encryption is a logical-export protection, not TDE

Data Pump can encrypt dump-file content using password, transparent or dual modes where the deployed edition/feature is supported. Its encryption password is independent from a TDE column's encryption key. A Data Pump file is also not an RMAN backup and does not provide media recovery.

Tool/edition check

The current licensing manual includes Data Pump Export File encryption in Oracle Advanced Security and marks Advanced Security included in Free, while Data Pump utility documentation retains edition-specific restrictions for ENCRYPTION_PASSWORD modes. Verify the exact 26ai Free binary/tool mode before making encrypted Data Pump a mandatory workflow; this chapter keeps RMAN/TDE as the executable Free encryption path.

12. Key backup, separation and recovery drill

The keystore is part of the backup set even when it is not physically stored inside the RMAN piece. Protect it as an independent recovery artifact.

text · password-protected keystore backup shape
ACCEPT tde_pwd CHAR PROMPT 'TDE keystore password: ' HIDEADMINISTER KEY MANAGEMENT BACKUP KEYSTORE  USING 'sh20_pre_rotation'  IDENTIFIED BY "&tde_pwd";
  • Keep the password-protected keystore backup in a separate failure/security domain from encrypted database backups.
  • Do not store an auto-login wallet next to encrypted backup media; possession of both can defeat the intended separation.
  • Record key IDs/rotation dates and FULLY_BACKED_UP state without storing secret material in tickets.
  • Copy required TDE key material correctly to Data Guard/RAC/duplicate/restore environments.
  • Test a Chapter 15 isolated restore assuming the original database host and wallet directory are gone.

13. Deliberately wrong: rotate/delete old TDE keys after “successful backup”

Older tablespace/datafile/backup content can still depend on older master keys. Deleting a wallet/key because a newer key is active can make historical backups or encrypted data unreadable. Rekeying creates a new protection layer; it does not automatically eliminate every dependency on old key material.

Governance rule

Never delete retired key material until recovery/retention policy proves that no retained database copy, backup, standby, archive or legal hold can require it. Test that assertion with restores, not a spreadsheet alone.

14. Production judgment and chapter close

Use TLS for modern heterogeneous client/server encryption and certificate authentication; use NNE where Oracle-native deployment requirements justify it. Use TDE for datafiles at rest, backup encryption for backup media, and authorization/VPD/redaction for what authenticated sessions may see. Maintain keys, trust stores and certificates as first-class infrastructure with rotation, expiry, backup and disaster-recovery ownership.

Current baseline is 26ai RU 23.26.3. TLS 1.3 and stricter listener/server certificate matching are 26ai behavior. WALLET_ROOT is static and may require restart when first configured; no chapter lab raises COMPATIBLE. TDE/Advanced Security is included in Free but extra-cost on EE/EE-ES. Free does not support online conversion of existing tablespaces nor per-PDB isolated keystores. The next chapter builds workload governance on top of these security boundaries using Resource Manager, services and capacity controls.

Check your understanding

  1. Does TLS protect a stolen datafile?
  2. What important SSL_SERVER_DN_MATCH behavior changed in 26ai?
  3. Why can an intact encrypted RMAN backup still be unrecoverable?
  4. Can Free use TDE?
  5. What configuration fact makes first-time WALLET_ROOT setup operationally significant?
Review the answers

No. TLS protects data in transit; TDE/backup encryption protect at-rest artifacts.

Strict matching checks both listener and database-server certificates, and partial matching uses HOSTNAME rather than SERVICE_NAME.

The required keystore/master key or password can be lost; encryption deliberately makes ciphertext unusable without the key.

Yes. TDE/Advanced Security are included in Free, with specific limitations such as no online existing-tablespace encrypt/rekey/decrypt conversion.

WALLET_ROOT is not dynamically modifiable or PDB-modifiable, so introducing/changing it can require SPFILE configuration and an instance restart.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.