1. Login to MariaDB using the following command: mariadb

    Note: If you want to log in using a specific user, use the following command:  mariadb -u <user_name> -p

  2. Install the Entrust encryption plugin.

    Copy
    INSTALL SONAME 'entrust_key_management';
  3. Encrypting the tables.

    To encrypt the new table, you have to provide the following options while creating the table: 

    Option

    Description

    ENCRYPTED=YES

    This option is used to encrypt the table.

    ENCRYPTION_KEY_ID=1

    This option is used to provide the master key ID.

    If you include ENCRYPTED=YES and do not include the encryption key ID, then MariaDB will use ENCRYPTION_KEY_ID=1 as the default.

    For example:

    Copy
    CREATE TABLE table1 (i int) ENGINE=InnoDB ENCRYPTED=YES ENCRYPTION_KEY_ID=1;

    To encrypt an existing table, use ALTER TABLE and provide the following options: 

    Option

    Description

    ENCRYPTED=YES

    This option is used to encrypt the table.

    ENCRYPTION_KEY_ID=1

    This option is used to provide the master key ID.

    If you include ENCRYPTED=YES and do not include the encryption key ID, then MariaDB will use ENCRYPTION_KEY_ID=1 as the default.

    For example:

    Copy
    ALTER TABLE table2 ENCRYPTED=YES ENCRYPTION_KEY_ID=2;
  4. Retrieve encryption details.

    To retrieve encryption details such as the key ID, and key version, run the following query: 

    Copy
    SELECT * FROM information_schema.innodb_tablespaces_encryption G;

Note: We recommend that you run the shutdown command (SHUTDOWN;) before you exit MariaDB to ensure that your encrypted tables are synchronized correctly. The shutdown command forces MariaDB to write the encrypted data to disk.