Skip to main content

Using Password Protected RMAN Backups


References-

1.    Creating Duplicate database in RMAN using password-mode encrypted backups (Doc ID 464832.1)




Objective –

1.    RMAN backups on NAS are at risk and can be copied easily on intranet.

2.    They can be restored, and critical information can be fetched easily.

3.    Encryption of these backups is need of the hour.

4.    Need to find a simple yet reliable solution to solve this security breach.




Security risk



















Proposed Solution –


RMAN backups are now password protected and we are safe even if backup files are stolen. This feature of Oracle will stop hackers restore our backup files and will ask for a password before restoring onto any other server.

























Real-time sample Use-case

Complete level-0 backup taken on Friday as highlighted – post estimation for s3 storage




















When trying to restore onto a different server(Stage in our case).


















After setting password, restore was successful.






















Enabling password protection

Change configuration parameter as follows and set password accordingly before starting backup –

Now when restoring, provide same password with set decryption configuration parameter.

This needs to be done outside run block.






Comments

Popular posts from this blog

Logfile locations in EBS r12.1 and EBS r12.2

Startup/shutdown Apps tier services are started and stopped frequently and we must know logfiles when troubleshooting startup/shutdown issues. $INST_TOP/logs/appl/admin/log $INST_TOP/logs/appl/admin/log Apache OHS being part of opmn in r12.1 has continued in r12.2. Logfile locations for troubleshooting have been changed $INST_TOP/logs/ora/10.1.3/Apache/error_log[timestamp] $INST_TOP/logs/ora/10.1.3/opmn/HTTP_Server~1.log $IAS_ORACLE_HOME/instances/*/diagnostics/logs/OHS/*/*log*   OPMN Logfile locations for r12.1 and r12.2 have been changed $INST_TOP/logs/ora/10.1.3/opmn/opmn* $IAS_ORACLE_HOME/instances/*/diagnostics/logs/OPMN/opmn/* Oacore oacore in r12.1 is oc4j component and part of 10gAS. However, in r12.2, oacore is now a managed server for weblogic server $LOG_HOME/ora/10.1.3/j2ee/oacore/oacore*/ $LOG_HOME/ora/10.1.3/j2ee/oacore/oacore*/ $LOG_HOME/ora/10.1.3/opmn/oacore*/oacor...
Defragment workflow related tables in r12   References- 1.     How to Reorganize Workflow Tables? (Doc ID 388672.1) 2.     EBS Workflow (WF) Analyzer (Doc ID 1369938.1) Points to Remember –     Some workflow tables are associated to queues so that it is necessary to use the advance queuing instructions to reorganize them. For tables other than queue tables, please refer to different notes created by RDBMS team to reorganize tables. This activity depends on the RDBMS version.       Defragment tables in workflow r12 Verify tables are not associated to queues – SQL> select queue_table from dba_queue_tables   2   where queue_table like '%WF%'; QUEUE_TABLE ------------------------------ WF_CONTROL WF_DEFERRED WF_DEFERRED_TABLE_M WF_ERROR WF_IN WF_INBOUND_TABLE WF_JAVA_DEFERRED WF_JAVA_ERROR WF_JMS_IN WF_JMS_JMS_OUT WF_JMS_OUT WF_NOTIFICATION_IN WF...

Oracle EBS r12 migration to Solaris SPARC ** issues and solutions

Let me share a list of issues I faced when migrating a single node Oracle ebs r12.1.3 environment from Linux x86_64 to multinode Solaris SPARC machines. I have already shared ppt that was point of discussion before migration. Oracle ebs db platform migration Please note that below is set of issues and respective solutions while migration. I have not covered steps for migration in this post. I would also like to share list of references from metalink that were very handy during complete migration process. ·          Export/import process for 12.0 or 12.1 using 11gR1 or 11gR2 (Doc ID 741818.1) -           This document will be primarily used for database migration. ·          Application Tier Platform Migration with Oracle E-Business Suite Release 12 (Doc ID 438086.1) -           Apps tier will b...