Data Guard is set up with a primary node and a standby node. The primary node is set up using the same process as the first Oracle Server node. For details, see the following:
If your Oracle environment is set up with Data Guard for disaster recovery, then you will need to make the keys accessible to any standby VMs as well as the primary. To ensure that the same keys are accessible to the standby nodes, all of the VMs must be connected to the same Key Set on the Cryptographic Security Platform Vault for Databases as well.
Setting up the Entrust Client on the Standby Oracle VMs:
Copy the bundle that you downloaded to the standby node.
Create a directory and extract the bundle.
Copy the modified entrust.conf file from the first Oracle server node and overwrite the config file from the bundle.
Run the setup.sh script using bash as the ROOT user:
bash>
sudo ./setup.sh other entrust.confWhere:
other is the node you are updating.
entrust.conf is the name of the configuration file that you downloaded.
Oracle Server Setup:
Important:
Data Guard mandates that the DB_UNIQUE_NAME for primary and standby servers should be different. Oracle derives the application name (CKA_APPLICATION) from the DB_UNIQUE_NAME, so the application name on standby is also different. The keys created by primary are marked with primary's application name. This causes v$encryption_keys view to return empty list.
The Entrust library and scripts have been designed to look for DB_UNIQUE_NAME of both primary and standby servers. This ensures that the v$encryption_keys view shows the keys correctly.
Set Environment:
The oracle administrator must provide the following parameters to set the context. Note that the database unique name here is orcls which is different from the same on primary.
The script provides the "default" parameter value in the brackets, if you want to use that, then just press enter to accept it.
[oracle@oracle19cn1 ~]$ ./encrypt.sh setenv
Using configuration file: ./entrust.conf
Using environment file: ./oracle.env
ORACLE_BASE (/u01/app/oracle) ?
ORACLE_HOME (/u01/app/oracle/product/19c/db_1) ?
Software Wallet Password (************) ?
Database Unique Name (orcls) ?
Database SID (orcl) ?
Access token file (/opt/oracle/entrust/oracle.conf) ?
Successfully set environment variables for TDE scripts in ./oracle.env
Updated env cache ./oracle.tabInitial setup of standby server:
./encrypt.sh standby setupCheck the status:
./encrypt.sh status