Skip to Main Content

Database Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Is it possible to use a centralized keystore for multiple db servers?

wylieinnormanAug 21 2018 — edited Aug 22 2018

Our enterprise is starting to move towards using TDE to encrypt tablespaces as we upgrade existing application databases to 18c.  I have been asked to find out if it is possible to use a centralized keystore for all the (test/dev/prod) dbs in the enterprise.  We are on RHEL.

I realize this is far from the optimal implementation and in fact opens us up to catastrophic results should the single keystore be corrupted, but management wants to know if it is POSSIBLE.

In addition, they have decided we will NOT keep the keystore on ASM.

I have reviewed the "Best Practices" document and the security portion of the 18c documentation. Any other advice/direction is appreciated.

Wylie

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Sep 19 2018
Added on Aug 21 2018
6 comments
557 views