When Master Key Is Lost, It Is Not Possible to Recreate New Master Key In HSM
Last updated on OCTOBER 31, 2016
Applies to:Advanced Networking Option - Version 18.104.22.168 to 22.214.171.124 [Release 11.2]
Information in this document applies to any platform.
While trying to regenerate the master key, after a HSM device crash and a subsequent recovery, the following error occurs:
SQL> ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234";
ALTER SYSTEM SET ENCRYPTION WALLET OPEN IDENTIFIED By "oracle1234"
ERROR at line 1:
ORA-28354: wallet already open
The issue can be reproduced at will with the following steps:
1. Configure TDE with HSM
2. Create an encrypted tablespace
3. Rebuild the HSM
4. Drop the encrypted tablespace
5. Try to recreate the master key using the new HSM.
Sign In with your My Oracle Support account
Don't have a My Oracle Support account? Click to get started
My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms