If the database is already encrypted with a software keystore, then you need to use the migration process.
Oracle requires both the software keystore and CSP Vault-based wallet are open when transitioning from software wallet to the CSP Vault-based keystore. Because both keystores cannot be opened at the same time, Oracle uses Auto Login Wallet to open both keystores during the migration. This applies to both the Primary as well as Standby servers / clusters.
On the Standby server, stop the Managed Recovery process (redo log apply):
Copy./encrypt.sh standby stop_redo_log_applyMigrate the Primary server to a CSP Vault-based keystore and setup auto login wallet:
Copy./encrypt.sh migrate
./encrypt.sh setup_auto_loginCopy the wallet files from the Primary wallet to the Standby wallet. The WALLET_ROOT can be seen in the output of the command:
Copy./encrypt.sh status
scp $WALLET_ROOT/tde/* oracle@standby:$WALLET_ROOT/tdeResync the standby server:
This command will stop and restart the database as well as restart the Manged Recovery process (redo log apply).
Copy./encrypt.sh standby resyncCheck the status.
Copy./encrypt.sh status