The following procedure applies when the target database is non-multitenant, and you are already using a software wallet with TDE encryption. If your target database is multitenant, see Migrating from Software Keystore to CSP Vault .

Entrust strongly recommends you back up your software wallet as an independent operation before attempting migration to KeyControl. Keep the backup folder in a safe place separated from the associated database files. Only users with authorization should be able to access the backup folder.

Repeat the following procedure for each database software wallet from which you want to migrate. Each independent database instance can use its own Entrust key protection method or credential if required.

Once an Entrust key protection method has been activated for a particular database instance, then you must continue to use that same credential for any further keys you want to protect for that instance.

Use the WALLET_ROOT and TDE_CONFIGURATION parameters. The WALLET_ROOT parameter should have already been set for Oracle keystore use.

In the following steps, use the orcl.conf file to utilize the access credentials for the Cryptographic Security Platform Vault for Databases: 

  1. Prepare for key migration by running the following SQL script:

    Copy
    CONNECT sysdba@DB
    ALTER SYSTEM SET TDE_CONFIGURATION = "KEYSTORE_CONFIGURATION=HSM|FILE" SCOPE=BOTH SID='*';
  2. Migrate from the keystore to Cryptographic Security Platform Vault:

    Copy
    CONNECT sysdba@DB
    ALTER SYSTEM SET ENCRYPTION KEY IDENTIFIED BY "file:/opt/oracle/entrust/orcl.conf" MIGRATE USING <keystorepassphrase>;

    The cloud key is created.

  3. Return to the Oracle Server in the SQL database and run the select CON_ID,WRL_TYPE,STATUS from V$ENCRYPTION_WALLET; command.

    For example: 

    Copy
    SQL> select CON_ID,WRL_TYPE,STATUS from V$ENCRYPTION_WALLET;

      CON_ID WRL_TYPE STATUS
    ---------- -------------------- ------------------------------
      0 HSM OPEN