When Master Key Is Lost, It Is Not Possible to Recreate New Master Key In HSM (Doc ID 1314417.1)

Last updated on OCTOBER 31, 2016

Applies to:

Advanced Networking Option - Version 11.2.0.1 to 11.2.0.2 [Release 11.2]
Information in this document applies to any platform.

Symptoms

While trying to regenerate the master key, after a HSM device crash and a subsequent recovery,  the following error occurs: 


SQL> ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234";
ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234"
*
ERROR at line 1:
ORA-28354: wallet already open




The issue can be reproduced at will with the following steps:

1. Configure TDE with HSM
2. Create an encrypted tablespace
3. Rebuild the HSM
4. Drop the encrypted tablespace
5. Try to recreate the master key using the new HSM.


Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms