To restore the backup on an alternate Oracle Server VM, you will need to perform the same setup process as you did to prepare a secondary node. For more information, see Scripted Installation and Configuration for Oracle TDE.

Note: If the Oracle server node is already connected to the CSP Vault for Databases, you can skip the setup steps.

  1. Copy the bundle file to the Oracle server node where you want to restore the database.

  2. Create a directory and extract the bundle.

  3. Copy the modified entrust.conf from the first Oracle server node and overwrite the configuration file from the bundle.

  4. Run the setup.sh script using bash as the ROOT user.

    Copy
    sudo ./setup.sh other entrust.conf

    Note: Because this is an additional node, the value of the node parameter must be 'other'.

  5. Retrieve the access token for accessing the backup key.

    The Oracle server node where you want to restore can now access keys in the Key Set to which it is connected. However, the backup might have been taken with a key in a different Key Set. To ensure that you have the correct key, you will need to retrieve the master key ID of the key which is associated with the backup. It can be seen in the output of command "./encrypt.sh status" on Oracle server node where the backup was taken

    1. Run the following script on the Oracle server node where the backup was taken.

      Copy
      ./encrypt.sh status

      The output displays the master key ID.

    2. Run the following script to get the access token for accessing the appropriate Key Set.

      Copy
      ./get_token.sh <Master key ID>

      This command prints the path of the access token file you will need to open the keystore for accessing the keys. For example: 

      Copy
      $ get_token.sh 0684299E32808C4F5ABF40262B20AF86D7
      ...
      Key with Key ID 0684299E32808C4F5ABF40262B20AF86D7 found in KeySet named poc_keyset
      ...
      ...
      Successfully created access token file "/opt/oracle/entrust/poc_keyset.conf" 
  6. Set the environment variables. In this example, the access token file is located at /opt/oracle/entrust/poc_keyset.conf.

    Copy
    [oracle@oracle19cn1 ~]$ ./encrypt.sh setenv


    Using configuration file: ./entrust.conf
    Using environment file: ./oracle.env

    ORACLE_BASE (/u01/app/oracle) ?
    ORACLE_HOME (/u01/app/oracle/product/19c/db_1) ?
    Software Wallet Password (************) ?
    Database Unique Name (orcl) ?
    Database SID (orcl) ?

    Access token file (/opt/oracle/entrust/oracle.conf) ? /opt/oracle/entrust/poc_keyset.conf

    Successfully set environment variables for TDE scripts in ./oracle.env
    Updated env cache ./oracle.tab
  7. Copy the backup and control file from the source server to the same location on the destination server.

  8. Copy the initorcl.ora and orapworcl files to the destination server at $ORACLE_HOME/dbs.

    Note: If you are using Oracle RAC, the file is called orapw, not orapworcl.

    The following files need to be copied into the locations on the destination server: 

    File

    Location

    init<SID>.ora
    For example, initorcl.ora

    $ORACLE_HOME/dbs

    orapw<SID> or orapw (RAC)

    $ORACLE_HOME/dbs

    Control files, for example: 

    c-1730471087-20250602-00

    /u02/oracle/oradata/ORCL/control01.ctl

    /u02/oracle/FRA/ORCL/control02.ctl

    grep control $ORACLE_HOME/dbs/init<SID>.ora

    Redo log files, for example: 

    /u02/oracle/oradata/ORCL/redo0*

    SQL> SELECT GROUP#, STATUS, MEMBER FROM V$LOGFILE;

    Backup files

    Backup directory. For example: 

    /u02/backup/ORCL

    Autobackup files for controlfile

    For example: 

    /u01/app/oracle/oradata/fra/ORCLP/autobackup

  9. Delete any older backup files on the destination server.

    Copy
    rman target /

    rman> list backup;
    rman> delete backup; 

    If you have another database with the same name, you will need to delete that database using the dbca command.

  10. Create a dummy entry in /etc/oratab file in the format $ORACLE_SID:$ORACLE_HOME:<N|Y>

    Where $ORACLE_SID is the system identifier, $ORACLE_HOME is the home directory of the database, and Y/N indicates whether or not to start the database after reboot or startup. For example: 

    Copy
    orcl:/u01/app/oracle/product/19c/db_1:N
  11. Optionally run the following command to get information on the control file path and learn where the control file will be restored.

    Copy
    cat $ORACLE_HOME/dbs/initorcl.ora | grep control

    # it will display output in this format
    *.control_files='/u02/oracle/oradata/ORCL/control01.ctl','/u02/oracle/FRA/ORCL/control02.ctl'
  12. Ensure that the path exists for both files. Create them if needed.

    Copy
    mkdir -p /u02/oracle/oradata/ORCL/
    mkdir -p /u02/oracle/FRA/ORCL/
  13. Create the audit dump directory in each node of the RAC cluster.

    Copy
    mkdir -p $ORACLE_BASE/admin/$ORACLE_SID/adump
  14. Startup the database in nomount mode.

    Copy
    cd $ORACLE_HOME/dbs/
    sqlplus / as sysdba

    sql> startup nomount pfile=$ORACLE_HOME/dbs/initorcl.ora
  15. Connect to rman and restore the control file. If you do not know the control file location, run "list backup;" on the source server.

    Copy
    rman target /
    rman> restore controlfile from '/u02/oracle/oradata/ORCL/control01.ctl';
    OR
    rman> restore controlfile from autobackup;
  16. Start the database in nomount mode.

    Copy
    rman> alter database mount;
  17. Crosscheck the backup.

    Copy
    rman> crosscheck backup;
  18. Optionally catalog the old control file.

    Copy
    rman> catalog start with '/u02/backup/ORCL/' noprompt;
  19. Restore the database.

    Copy
    rman> restore database ;
    rman> ALTER DATABASE FLASHBACK OFF;
  20. Exit rman.

  21. Open the wallet.

    Copy
    ./encrypt.sh open_hsm_keystore
  22. When the wallet is open, start rman and finish the recovery process.

    Copy
    rman target /
    rman> recover database ;

    Note: If you see a media recovery error, you can safely ignore it.

  23. If you see a failure, open the database with resetlogs.

    Copy
    alter database open resetlogs;
  24. If no failures are seen, open the database normally.

    Copy
    alter database open;
  25. Ensure the database mode is set to Read, Write.

    Copy
    select name, open_mode from v$database;
  26. Add the database to the cluster and add the RAC instances.

    Copy
    srvctl add database -d orcl -o $ORACLE_HOME
    srvctl add instance -d orcl -i orcl1 -n oracle19cn1
    srvctl add instance -d orcl -i orcl2 -n oracle19cn2
    srvctl config database -d orcl -a
  27. If required, set the key ID in sqlpls using the following: 

    Copy
    ADMINISTER KEY MANAGEMENT USE KEY '0684299E32808C4F5ABF40262B20AF86D7' IDENTIFIED BY "file:/opt/oracle/entrust/orcl.conf";
  28. Crosscheck any other encrypted table data or tables in the encrypted table space using select query by login as the Key Management (syskm) user.