Oracle Wallet Manager (OWM)
Survived, partially.
✓ certified by the mortician
In life
Oracle Wallet Manager is the graphical Java tool for creating and maintaining Oracle wallets, the PKCS#12 containers that hold TLS certificates, private keys and, in many deployments, the Transparent Data Encryption keystore and secure external password store entries.
Migrations care because wallets hold material the migration itself depends on: the TDE master key needed to read encrypted tablespaces during export, and the certificates used for TLS connections from migration tooling. Moving key management to Azure Key Vault starts with an inventory of wallets, and scripts that invoked the GUI must be rewritten around command-line tools.
Oracle's 21c Upgrade Guide deprecates Oracle Wallet Manager (notice dated May 2021), and the 26ai guide desupports it (notice dated April 2023), recommending the orapki command-line tool instead.
Cause of departure
Desupported in Oracle Database 26ai after deprecation in 21c. Oracle names orapki command-line tool as the successor.
Obituary
Oracle Wallet Manager, born before 11.2, maintained PKCS#12 wallets containing TDE master keys, TLS certificates, and stored credentials. It served these security duties with the quiet gravity expected of a wallet.
Deprecated in 21c and desupported in 26ai, it leaves Oracle work to the orapki command-line tool. Azure offers no wallet file to migrate; keys are instead generated or imported into Key Vault.
It is survived by Azure Key Vault for customer-managed TDE keys, where it lives on partly. The server identity needs key permissions, while managed certificates, Key Vault secrets, or Microsoft Entra authentication assume its other responsibilities.
Survived by
Azure Key Vault (customer-managed TDE keys) partial effort M
Oracle Wallet Manager maintained PKCS#12 wallets holding TDE master keys, TLS certificates and stored credentials. For TDE the Azure equivalent is customer-managed TDE with the protector in Key Vault or Managed HSM, accessed by the server's managed identity; the wallet's other roles (server TLS certificates, client credential store) are handled by the platform's managed certificates and by Key Vault secrets or Microsoft Entra authentication in the application. There is no wallet file to migrate; keys are generated or imported into Key Vault.
- Create a Key Vault with soft-delete and purge protection; import or generate the TDE protector key.
- Grant the logical server or managed instance identity get, wrapKey and unwrapKey.
- Switch the server to customer-managed TDE and enable automatic rotation.
- Replace wallet-based client credentials (mkstore) with Entra managed identities or Key Vault secrets.
Complications
Notices of correction
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 21c) · Upgrade Guide 21c, F17069-48, Feb 2026 · read 2026-09-26
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 26ai) · Upgrade Guide 26ai, G43570-12, updated Jul 2026 · read 2026-09-26
- microsoft Customer-managed transparent data encryption (TDE) with Azure Key Vault · page updated 2026-09-15 · read 2026-09-26