From owner-freebsd-questions@FreeBSD.ORG Sat Feb 10 18:16:25 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 752D316A402 for ; Sat, 10 Feb 2007 18:16:25 +0000 (UTC) (envelope-from dghatikachalam@gmail.com) Received: from nz-out-0506.google.com (nz-out-0506.google.com [64.233.162.234]) by mx1.freebsd.org (Postfix) with ESMTP id 35C5A13C428 for ; Sat, 10 Feb 2007 18:16:24 +0000 (UTC) (envelope-from dghatikachalam@gmail.com) Received: by nz-out-0506.google.com with SMTP id o37so1252680nzf for ; Sat, 10 Feb 2007 10:16:24 -0800 (PST) DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=RW5WByTHTYukvcoxtr7ldt3RDEAm0p7ZFVGTNdfDMF7U5oy8oNG3WtOEwgJ1PLi+q/fWh5VJfeEWydkY/stt92PtcXHllkN8eeBpH81T/QbycQ0mmZ2dd+T/9elMnvKI2c43I6+0br9P5naIJkBMb7o/ao6QTu37191lx8AMjIU= Received: by 10.114.202.15 with SMTP id z15mr6458384waf.1171131384288; Sat, 10 Feb 2007 10:16:24 -0800 (PST) Received: by 10.114.211.20 with HTTP; Sat, 10 Feb 2007 10:16:24 -0800 (PST) Message-ID: Date: Sat, 10 Feb 2007 13:16:24 -0500 From: "Dak Ghatikachalam" To: "David Robillard" In-Reply-To: <226ae0c60702061025q12b8e5d7of84bbdef43d3b240@mail.gmail.com> MIME-Version: 1.0 References: <226ae0c60702060602x20e34eb9w715c786dbf6dd34e@mail.gmail.com> <226ae0c60702061025q12b8e5d7of84bbdef43d3b240@mail.gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: FreeBSD Questions Subject: Re: Question:encryption tool. X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 Feb 2007 18:16:25 -0000 On 2/6/07, David Robillard wrote: > > On 2/6/07, Dak Ghatikachalam wrote: > [...snip!...] > > > Thanks a lot , but we are on Oracle9i database, the Oracle secure > backup > > they are talking would be nice on 10G onwards > > Well, not according to the FAQ. Here is what it says: > > -- What Oracle database versions does Oracle Secure Backup support? > Oracle Secure Backup installs with a native integration of Oracle > Database's via Oracle Recovery Manager (RMAN), which supports Oracle9i > forward. > > So if you're running 9i, you should be alrgiht. Here is the exception with Oracle9i I was not able to encrypt the RMAN backups, I tried by best it does not have an option of encryption you will see below I have catalog as 10G database , so I registered itself as target Recovery Manager: Release 10.2.0.3.0 - Production on Tue Feb 6 18:52:34 2007 Copyright (c) 1982, 2005, Oracle. All rights reserved. connected to target database: CAT10GR2 (DBID=845501569) connected to recovery catalog database RMAN> show all; RMAN configuration parameters are: CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default CONFIGURE BACKUP OPTIMIZATION OFF; # default CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default CONFIGURE CONTROLFILE AUTOBACKUP OFF; # default CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default CONFIGURE DEVICE TYPE DISK PARALLELISM 1 BACKUP TYPE TO BACKUPSET; # default CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default CONFIGURE MAXSETSIZE TO UNLIMITED; # default CONFIGURE ENCRYPTION FOR DATABASE OFF; # default CONFIGURE ENCRYPTION ALGORITHM 'AES128'; # default CONFIGURE ARCHIVELOG DELETION POLICY TO NONE; # default CONFIGURE SNAPSHOT CONTROLFILE NAME TO '/u01/app/oracle/product/10.2/dbs/snapcf_cat10gr2.f'; # default RMAN> You can see that encryption for db and alogorithm option there but you will not see in Oracle9i Recovery Manager: Release 9.2.0.7.0 - 64bit Production Copyright (c) 1995, 2002, Oracle Corporation. All rights reserved. connected to target database: RCVCAT (DBID=2859160142) connected to recovery catalog database RMAN> show all; RMAN configuration parameters are: CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default CONFIGURE BACKUP OPTIMIZATION OFF; # default CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default CONFIGURE CONTROLFILE AUTOBACKUP OFF; # default CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default CONFIGURE DEVICE TYPE DISK PARALLELISM 1; # default CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default CONFIGURE MAXSETSIZE TO UNLIMITED; # default CONFIGURE SNAPSHOT CONTROLFILE NAME TO '/u01/app/oracle/product/9.2.0.7/dbs/snapcf_rcvcat.f'; # default my impression about the FAQ on secure-backup what oracle talks about , encryption, archivelog deletion policy is that in simply focuses on 10g database and above. yes i went thru th claims of secure of 9i , but the command of set enryption on identified by "password" or CONFIGURE ENCRYPTION FOR DATABASE on identified by "password" is the command of 10G not sure if that would would work on 9i database even we were to use the secure - backup with 9i. You can get your hands on the FAQ at > http://www.oracle.com/technology/products/secure-backup/pdf/FAQ.pdf > > HTH, > > David > -- > David Robillard > UNIX systems administrator & Oracle DBA > CISSP, RHCE & Sun Certified Security Administrator > Montreal: +1 514 966 0122 >