What is Oracle Wallet and how to configure Wallet || TDE - Why do we need Wallet? - Oracle Security

  Рет қаралды 35,227

Vismo Technologies

Vismo Technologies

Күн бұрын

Пікірлер: 91
@gen32hp
@gen32hp Жыл бұрын
Excellent video and beautiful execution
@guruinibm
@guruinibm 3 жыл бұрын
Excellent Video ... I have to thank you for explaining clearly with simple terms to make us understand better. A big thank you 🙏
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Glad it was helpful!
@stavros1337
@stavros1337 2 ай бұрын
Thank you Mallik
@madhusudhan8815
@madhusudhan8815 4 жыл бұрын
Superb video and very crisp explanation... Thank you for your effort ..!
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thank you Madhu, Keep watching my channel
@mohammadislam3134
@mohammadislam3134 2 жыл бұрын
It's very fruitful and useful. Thanks 👍
@sandeeepkumarmishra1747
@sandeeepkumarmishra1747 4 жыл бұрын
Please share the slides, And the things which may help better are +What is the difference between mkstore and orapki? +What would be the step to add a second user ? +What changes needed for RAC,DG and GG I am suggesting to add these sections into the lecture. Thank you for this one, it helped me a lot.
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
+What is the difference between mkstore and orapki? >>> orapki to create wallet >>> mkstore to store the DB user name and password to wllet +What would be the step to add a second user ? >>> same mkstore you can user and add N number of users +What changes needed for RAC,DG and GG >>> I will make more video on this, pls staandby
@sandeeepkumarmishra1747
@sandeeepkumarmishra1747 4 жыл бұрын
@@VismoTechnologies docs.oracle.com/middleware/1213/wls/JDBCA/oraclewallet.htm#JDBCA599 mkstore -wrl -create So I guess we can also create wallet via mkstore On adding the second user, I guess one may need a second entry in the TNS file for the same database, with a different alias. If wallet files can't be copied and used then what is the significance/difference between "auto_login" and "auto_login_local"
@CBwhite2
@CBwhite2 3 жыл бұрын
Thank You.. Very detailed video.
@techpetla3901
@techpetla3901 4 жыл бұрын
Nice presentation.
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thank you!
@boyaswathi1328
@boyaswathi1328 Жыл бұрын
Thank you so much for this video
@DipsaDishNDiaries
@DipsaDishNDiaries 3 жыл бұрын
Thank you for your effort ..!
@dannyabraham2347
@dannyabraham2347 3 жыл бұрын
Hi, Thanks, very good presentation but centered on the Server side. What about the remote clients? Can U pls provide any link for a detailed TODO how to connect clients and distribute the wallet?
@tauseefmohmmed5447
@tauseefmohmmed5447 4 жыл бұрын
Thanks sir it is very informative video..
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thanks. Keep Watching my videos
@soundarm7649
@soundarm7649 4 жыл бұрын
Easy to understand as always. Tde set up video can you upload please
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Sure I will do more and more videos on TDE in upcoming days.
@mohamedsaleem7706
@mohamedsaleem7706 4 жыл бұрын
Excellent
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thanks
@nagababutalasila5023
@nagababutalasila5023 2 жыл бұрын
Nice video and can you please make video to connect from client machine without password.
@v8tornado
@v8tornado 3 жыл бұрын
Fantastic video. After creating the oracle wallet, can you explain how to connect from nodejs to the oracle wallet?
@rominmaharjan2392
@rominmaharjan2392 3 жыл бұрын
great video!!!
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Thank you!!
@BHARARHROYAL
@BHARARHROYAL 4 жыл бұрын
Nice video.
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thank you.
@guruinibm
@guruinibm 3 жыл бұрын
Nice video .. will you take a session for SSL wallet and TCPS port please ...
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Yes, soon I will take session on SSL and TSL
@HachtoAdventour
@HachtoAdventour 9 ай бұрын
Hey mallik what if the password get expired for mallik .. then how will you update? Do you need to recreate it
@VinayBMV
@VinayBMV 4 жыл бұрын
Which editor you are using, because I'm new to this
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
I did not get your question
@jamsher731
@jamsher731 3 жыл бұрын
Its putty only background color is changed
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
You can do your own customisation, like colour, fonts and font size etc
@aambaksh4924
@aambaksh4924 2 жыл бұрын
Plz make vedio on tls encryption also
@VijayKumar-py6fw
@VijayKumar-py6fw 3 жыл бұрын
Please let me know How to check wallet is disable at binary level?
@ulisesgtzr
@ulisesgtzr 3 жыл бұрын
Hello Mallik, the DB admin create a DB wallet on our company, when i try to make a insert in java (preparestatment) give me error, about lost connection, but if i make a select in java its works, did you have any idea why? error java.sql.SQLRecoverableException: Closed Connection PreparedStatement insertStatement = (OraclePreparedStatement)connection.prepareStatement(sqlE1); this Select works try (Statement statement = connection.createStatement()) { try (ResultSet resultSet = statement .executeQuery("select * from global_name")) { any idea?
@vasu041
@vasu041 3 жыл бұрын
Hi, i installed oracle 11g express edition and i donot have orapki installed on my linux machine. What is the process to insall orapki ?
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Express edition will not comes with orapki, This is light wait installation will not be having much feature. you have to go with PE/EE/SE edition installation
@kushagramishra3486
@kushagramishra3486 2 жыл бұрын
Can we have username/password for two different users in same ewallet file? if yes....when we connect to db with sqlplus /@DBDEV which user to get connected how will that be decided ?
@VismoTechnologies
@VismoTechnologies 2 жыл бұрын
Att with defferent tns alias for different users
@umashankar327
@umashankar327 4 жыл бұрын
How to do column an ts level encryption?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
We have column and tablespace level encryption using TDE. I will cover it in my next lecture.
@udays2
@udays2 4 жыл бұрын
Thank you..
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
You're welcome
@meghanakanagala2088
@meghanakanagala2088 3 жыл бұрын
Thanks for the explanation. At 15.27, if we store 2 or more than 2 credentials using mkstore cmd and try to login using 'sqlplus/@DEVDB'.....which user credentials will it consider? How does it make the difference?
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
mkstore -wrl /oracle/wallet -createCredential DEVDB mallik mallik mkstore -wrl /oracle/wallet -createCredential DEVDB1 mallik1 mallik1 mkstore -wrl /oracle/wallet -createCredential DEVDB2 mallik2 mallik2 mkstore -wrl /oracle/wallet -createCredential DEVDB3 mallik3 mallik3 sqlplus /@DEVDB sqlplus /@DEVDB1 sqlplus /@DEVDB2 sqlplus /@DEVDB3 All DEVDB, DEVDB1, DEVDB2 and DEVDB3 should point to DEVDB in you tnsnames.ora
@aa33366
@aa33366 4 жыл бұрын
ora-28632: master key not found. have you seen this error? this shows up when I try to select a table having encrypted column
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
This ORA-28632 occurs in many scenario -- when you are doing export/import -- When when I delete my wallet and try to re-create it -- invalid or incorrect wallet and many other scenario. You have to address based on the scenario and issue
@aa33366
@aa33366 4 жыл бұрын
@@VismoTechnologies Thanks for the reply. We have an 11g Oracle DB. DBA upgraded it to Oracle 12. As, 11g had encrypted tables, most probably, dba didn't export the keys properly to 12. That is why we are getting the error. I checked the forums. I think Oracle 12 is not recoverable. Do you have any steps to fix this issue? may create a separate DB instance for a proper upgrade of Oracle 11g to Oracle 12 so that master key problems do not arise?
@moonlight-kh6uz
@moonlight-kh6uz 4 жыл бұрын
Does Wallet offer all capabilities offered by Entrust/PKI?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Yes Wallet offers all those capabilities
@moonlight-kh6uz
@moonlight-kh6uz 4 жыл бұрын
@@VismoTechnologies Does it mean that Wallet can -create certificate -check the status of certificate revocation If so, can you provide the link attesting to that?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
@@moonlight-kh6uz Please refer the below Oracle document docs.oracle.com/cd/B14099_19/core.1012/b13995/wallets.htm 15.3 Interoperability with X.509 Certificates Oracle Wallet Manager functionality supports users who already have certificates provisioned. If you do not use Oracle Wallet Manager to create certificates, you can use it to manage and store certificates created previously. For more details on how to create certificate and manage certificate, I will launch new video in next 1 or 2 weeks with detailed explanation
@moonlight-kh6uz
@moonlight-kh6uz 4 жыл бұрын
@@VismoTechnologies on the link you provided, Walett cqn only generate CSR in PKCS#10 format and cannot fulfill the request i.e. you have to wait for CA to send you the to import into the walett. Creation of the certificate is not the function of the Walett (that's why Entrust/PKI is called Entrust Authority i.e. it creates certificates)
@sandeeepkumarmishra1747
@sandeeepkumarmishra1747 4 жыл бұрын
While creating wallet password is used While encrypting the wallet another password is used What is the difference between these two? Can I copy the wallet files to another machine and use them? If so is there a way to prevent it?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
While creating wallet password is used >>> Wallet password While encrypting the wallet another password is used >>> You can set you mater key and also to change your wallet password you can use this What is the difference between these two? >>> You can set you mater key and also to change your wallet password you can use this Can I copy the wallet files to another machine and use them? If so is there a way to prevent it? >>> You can not use these wallets on the other servers provided if you restore/clone the same database in that server
@mahmoodalnabhani7979
@mahmoodalnabhani7979 3 жыл бұрын
Thanks mallik, I follow you from Oman 🇴🇲, awesome 👏, where i can get the script to research and develop in oracle
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Script has been already share on our telegram group @mallik034 If you have not joined request you to join our telegram group @mallik034
@muthukumarn1
@muthukumarn1 3 жыл бұрын
@@VismoTechnologies Kindly share the wallet configuration in cdb and pdb link vedios
@bharathkumar-ds8cd
@bharathkumar-ds8cd 4 жыл бұрын
I am eagerly waiting to your demo datawallet lab session. 😯🙄
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Sure I will upload all the video shortly
@Brothers2Bonding
@Brothers2Bonding 4 жыл бұрын
Hi Mallik If we are using "mkstore" command will prompt for wallet password . Suppose if I forgot wallet password then ?
@Brothers2Bonding
@Brothers2Bonding 4 жыл бұрын
Also forgot encryption key password also . Please suggest how to resolve
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
If you forgot the wallet password then you can not restore it back. Its very critical, You have to keep password secure.
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Same thing with encryption keys as well If you forgot encryption keys then you can not restore it back. Its very critical, You have to keep password secure.
@OODevelopers
@OODevelopers 3 жыл бұрын
If I have wallet the sso and pl2 files, how to get database username from oracle wallet in to java datasource or some properties file in java
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
What is the requirements here. Why do you want to extract database name from wallet?
@OODevelopers
@OODevelopers 3 жыл бұрын
@@VismoTechnologies that's for logging. But I got to know how to do that. Thanks
@KidsstorybyAvi
@KidsstorybyAvi 4 жыл бұрын
Nice video , kindly share OKV confihuration in 12c rac database
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
I will do in sometime in future days.
@syedrahman8602
@syedrahman8602 4 жыл бұрын
Could you please create one more demo for Oracle 12c?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
I am planning to cover all the topics but it will take sometimes. Definitely I will do a session on 12c and its new features
@yakathare
@yakathare 4 жыл бұрын
Hi Malli, I have been watching your videos. And they are very useful. Can share how to standby and primary for oracle 11g and 12c for ASM file system
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Sure, please stay tuned, I will try to upload as soon as possible. I am getting lots requests for other topics as well. I am trying to cover all the topics as requested.
@anwarnaim8889
@anwarnaim8889 4 жыл бұрын
Can you post the complete transcript of the video - thanks
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Sure Anwar
@mukidkhan952
@mukidkhan952 4 жыл бұрын
Sir if there are number of user who add there key in wallet than how they connect via single command sqlplus /@DEVDB
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
You can not add more user to wallet and for the you need to go with Key Management that is advanced concept than this wallet but there is a way you can add more users like below. mkstore -wrl /oracle/wallet -createCredential DEVDB mallik mallik mkstore -wrl /oracle/wallet -createCredential DEVDB1 mallik1 mallik1 mkstore -wrl /oracle/wallet -createCredential DEVDB2 mallik2 mallik2 mkstore -wrl /oracle/wallet -createCredential DEVDB3 mallik3 mallik3 sqlplus /@DEVDB sqlplus /@DEVDB1 sqlplus /@DEVDB2 sqlplus /@DEVDB3 All DEVDB, DEVDB1, DEVDB2 and DEVDB3 should point to DEVDB in you tnsnames.ora
@ArunJayapal
@ArunJayapal 4 жыл бұрын
I have created a wallet credential for a user (e.g. userabc) . Assume the db instance here is FOODB. When trying os auth with spl plus as follows: sqlplus /@FOODB i get error: ORA-01017: invalid username/password; logon denied What is the solution for this?
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
How you created and how you added user and what is your tns entry Can you share all these pls?
@ArunJayapal
@ArunJayapal 4 жыл бұрын
@@VismoTechnologies Thanks for responding. I connected as sysdba and created user as follows: SQL> alter session set "_ORACLE_SCRIPT"=true; SQL> CREATE USER fred identified by flintstone; SQL> GRANT CONNECT, RESOURCE, DBA to fred; After that I created the wallet as per instructions in the videos. No problems there. Next created the wallet profile for fred: $ mkstore -wrl $ORACLE_BASE/admin/$ORACLE_SID/wallet -createCredential $ORACLE_SID fred flintstone No issues here. Next tried to login (with fred): $ sqlplus /@$ORACLE_SID This gave the logon error mentioned in the previous thread. Where can I find the tns entry?
@rihamchowdhury4020
@rihamchowdhury4020 3 жыл бұрын
need that slide
@VismoTechnologies
@VismoTechnologies 3 жыл бұрын
Its shared on our Telegram group. U can join our Telegram group @mallik034
@sankaradeful
@sankaradeful 2 жыл бұрын
If someone read your script and found command sqlplus /@DEVDB then he can use same command to connect DB with your userid and password. It means he can also login with your credentials to DB.. it is also security problem... correct?
@patela21
@patela21 3 жыл бұрын
Nice instructions, just want to correct something though. this setting should be in place with sqlnet.ora: SQLNET.WALLET_OVERRIDE = TRUE otherwise, no matter how many times I create or delete the user I'd like to use to access the database via wallet, its not working. After I embedded above config in sqlnet.ora, reloaded the listener, I'm able to connect to the database via wallet.
@umashankar327
@umashankar327 4 жыл бұрын
Excellent
@VismoTechnologies
@VismoTechnologies 4 жыл бұрын
Thanks
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 66 МЛН
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 51 МЛН
Oracle Tutorial - How to configure wallet manager step by step
11:31
OCP TECHNOLOGY
Рет қаралды 36 М.
002 - What is VIP & What is SCAN in Oracle RAC? || Real Application Cluster
32:27
Authenticate Oracle Database users with MS Active Directory
23:00
Oracle Database Product Management
Рет қаралды 11 М.
Oracle 19c Transparent Data Encryption TDE with Wallet
1:12:44
Oracle ASM Administration
1:13:46
DBA Genesis
Рет қаралды 128 М.
What is Oracle TDE (Transparent Data Encryption)
4:55
Cloud Alchemy Academy
Рет қаралды 4,2 М.