Skip to Main Content
DB Security - TDE key management with Oracle Key Vault

About This Workshop

Youtube Video

About This Workshop
In this hands-on lab, you’ll migrate an Oracle Database 19c encrypted with TDE from a local wallet to centralized key management with Oracle Key Vault (OKV). You’ll upload pre-migration TDE master keys to OKV, then remove them from the encrypting server to align with PCI DSS requirements. You’ll also use tagged keys to associate TDE master keys more easily with PDBs, reducing manual steps and configuration errors. By the end, you’ll have a repeatable workflow for centralizing database encryption keys with auditing and rotation readiness.

Workshop Info

1 hour
  • Encrypt an Oracle Database 19c with TDE
  • Use OKV RESTful services to prepare OKV to provide key management for the encrypted database.
  • Upload the pre-migration TDE keys to OKV (important for PCI compliance)
  • Migrate the encrypted database from local TDE wallet to OKV
  • Perform post-migration steps to implement best practices
  • Familiarity with the Oracle database is preferred, but not necessary.
  • An understanding of Transparent Data Encryption (TDE), preferably having completed the DB Security - ASO lab

Other Workshops you might like