Backing Up Oracle TDE on an Encrypted Database
-
If Oracle is not running, login as sysdba and run the startup.
Copysu - oracle
sqlplus / as sysdba
sql> startup; -
If the database is running in NOARCHIVELOG mode, change it to ARCHIVELOG mode.
Copysql> shutdown immediate;
sql> startup mount;
sql> alter database archivelog;
sql> alter database open; -
Exit the sqlplus session and connect to the rman session.
Copyrman target / -
List any existing backup files.
Copyrman> list backup; -
If there are any backup files, optionally delete them.
Copyrman> delete backup; -
Display the default configuration for rman.
Copyrman> show all; -
Set the backup and configuration file location and the file name format of the backup files. If the path doesn't exist, create it using the following:
mkdir -p /u02/backup/ORCL/Copyrman> CONFIGURE CHANNEL DEVICE TYPE DISK FORMAT '/u02/backup/ORCL/ORCL_BKP_%U';
rman> CONFIGURE controlfile autobackup on; -
Create the backup with archive logs.
Copyrman> BACKUP DATABASE PLUS ARCHIVELOG; -
Create the init file using the pfile.
Copycd $ORACLE_HOME/dbs/
sqlplus / as sysdba
sql> create pfile from spfile; -
After the backup is completed, identify the encryption key using the following query as sysdba on the source machine.
Copysqlplus / as sysdba
startup;
select KEY_ID,KEY_USE from V$ENCRYPTION_KEYS;Search for the section called "Current database master encryption key/s in use".