To restore the backup on an alternate Oracle Server VM, you will need to perform the same setup process as you did to prepare a secondary node. For more information, see Scripted Installation and Configuration for Oracle TDE.
Note: If the Oracle server node is already connected to the CSP Vault for Databases, you can skip the setup steps.
Copy the bundle file to the Oracle server node where you want to restore the database.
Create a directory and extract the bundle.
Copy the modified entrust.conf from the first Oracle server node and overwrite the configuration file from the bundle.
Run the setup.sh script using bash as the ROOT user.
Copysudo ./setup.sh other entrust.confNote: Because this is an additional node, the value of the node parameter must be 'other'.
Retrieve the access token for accessing the backup key.
The Oracle server node where you want to restore can now access keys in the Key Set to which it is connected. However, the backup might have been taken with a key in a different Key Set. To ensure that you have the correct key, you will need to retrieve the master key ID of the key which is associated with the backup. It can be seen in the output of command "./encrypt.sh status" on Oracle server node where the backup was taken
Run the following script on the Oracle server node where the backup was taken.
Copy./encrypt.sh statusThe output displays the master key ID.
Run the following script to get the access token for accessing the appropriate Key Set.
Copy./get_token.sh <Master key ID>This command prints the path of the access token file you will need to open the keystore for accessing the keys. For example:
Copy$ get_token.sh 0684299E32808C4F5ABF40262B20AF86D7
...
Key with Key ID 0684299E32808C4F5ABF40262B20AF86D7 found in KeySet named poc_keyset
...
...
Successfully created access token file "/opt/oracle/entrust/poc_keyset.conf"
Set the environment variables. In this example, the access token file is located at /opt/oracle/entrust/poc_keyset.conf.
Copy[oracle@oracle19cn1 ~]$ ./encrypt.sh setenv
Using configuration file: ./entrust.conf
Using environment file: ./oracle.env
ORACLE_BASE (/u01/app/oracle) ?
ORACLE_HOME (/u01/app/oracle/product/19c/db_1) ?
Software Wallet Password (************) ?
Database Unique Name (orcl) ?
Database SID (orcl) ?
Access token file (/opt/oracle/entrust/oracle.conf) ? /opt/oracle/entrust/poc_keyset.conf
Successfully set environment variables for TDE scripts in ./oracle.env
Updated env cache ./oracle.tabCopy the backup and control file from the source server to the same location on the destination server.
Copy the
initorcl.oraandorapworclfiles to the destination server at $ORACLE_HOME/dbs.Note: If you are using Oracle RAC, the file is called
orapw, notorapworcl.The following files need to be copied into the locations on the destination server:
File
Location
init<SID>.ora
For example, initorcl.ora$ORACLE_HOME/dbs
orapw<SID> or orapw (RAC)
$ORACLE_HOME/dbs
Control files, for example:
c-1730471087-20250602-00
/u02/oracle/oradata/ORCL/control01.ctl
/u02/oracle/FRA/ORCL/control02.ctl
grep control $ORACLE_HOME/dbs/init<SID>.ora
Redo log files, for example:
/u02/oracle/oradata/ORCL/redo0*
SQL> SELECT GROUP#, STATUS, MEMBER FROM V$LOGFILE;
Backup files
Backup directory. For example:
/u02/backup/ORCL
Autobackup files for controlfile
For example:
/u01/app/oracle/oradata/fra/ORCLP/autobackup
Delete any older backup files on the destination server.
Copyrman target /
rman> list backup;
rman> delete backup;If you have another database with the same name, you will need to delete that database using the dbca command.
Create a dummy entry in /etc/oratab file in the format $ORACLE_SID:$ORACLE_HOME:<N|Y>
Where $ORACLE_SID is the system identifier, $ORACLE_HOME is the home directory of the database, and Y/N indicates whether or not to start the database after reboot or startup. For example:
Copyorcl:/u01/app/oracle/product/19c/db_1:NOptionally run the following command to get information on the control file path and learn where the control file will be restored.
Copycat $ORACLE_HOME/dbs/initorcl.ora | grep control
# it will display output in this format
*.control_files='/u02/oracle/oradata/ORCL/control01.ctl','/u02/oracle/FRA/ORCL/control02.ctl'Ensure that the path exists for both files. Create them if needed.
Copymkdir -p /u02/oracle/oradata/ORCL/
mkdir -p /u02/oracle/FRA/ORCL/Create the audit dump directory in each node of the RAC cluster.
Copymkdir -p $ORACLE_BASE/admin/$ORACLE_SID/adumpStartup the database in nomount mode.
Copycd $ORACLE_HOME/dbs/
sqlplus / as sysdba
sql> startup nomount pfile=$ORACLE_HOME/dbs/initorcl.oraConnect to rman and restore the control file. If you do not know the control file location, run "list backup;" on the source server.
Copyrman target /
rman> restore controlfile from '/u02/oracle/oradata/ORCL/control01.ctl';
OR
rman> restore controlfile from autobackup;Start the database in nomount mode.
Copyrman> alter database mount;Crosscheck the backup.
Copyrman> crosscheck backup;Optionally catalog the old control file.
Copyrman> catalog start with '/u02/backup/ORCL/' noprompt;Restore the database.
Copyrman> restore database ;
rman> ALTER DATABASE FLASHBACK OFF;Exit rman.
Open the wallet.
Copy./encrypt.sh open_hsm_keystoreWhen the wallet is open, start rman and finish the recovery process.
Copyrman target /
rman> recover database ;Note: If you see a media recovery error, you can safely ignore it.
If you see a failure, open the database with resetlogs.
Copyalter database open resetlogs;If no failures are seen, open the database normally.
Copyalter database open;Ensure the database mode is set to Read, Write.
Copyselect name, open_mode from v$database;Add the database to the cluster and add the RAC instances.
Copysrvctl add database -d orcl -o $ORACLE_HOME
srvctl add instance -d orcl -i orcl1 -n oracle19cn1
srvctl add instance -d orcl -i orcl2 -n oracle19cn2
srvctl config database -d orcl -aIf required, set the key ID in sqlpls using the following:
CopyADMINISTER KEY MANAGEMENT USE KEY '0684299E32808C4F5ABF40262B20AF86D7' IDENTIFIED BY "file:/opt/oracle/entrust/orcl.conf";Crosscheck any other encrypted table data or tables in the encrypted table space using select query by login as the Key Management (syskm) user.