When Master Key Is Lost, It Is Not Possible to Recreate New Master Key In HSM
(Doc ID 1314417.1)
Last updated on APRIL 09, 2018
Applies to:Advanced Networking Option - Version 22.214.171.124 to 126.96.36.199 [Release 11.2]
Information in this document applies to any platform.
While trying to regenerate the master key, after a HSM device crash and a subsequent recovery, the following error occurs:
SQL> ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234";
ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234"
ERROR at line 1:
ORA-28354: wallet already open
The issue can be reproduced at will with the following steps:
1. Configure TDE with HSM
2. Create an encrypted tablespace
3. Rebuild the HSM
4. Drop the encrypted tablespace
5. Try to recreate the master key using the new HSM.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!