Oracle Database 19c Release Update 19.32 introduces a new cryptographic provider with support for TLS 1.3, post-quantum cryptography, and FIPS 140-3 mode. Organizations can now strengthen cryptographic security while continuing to run Oracle Database 19c and modernize at a pace that fits their application, compliance, and upgrade plans.
Release Update 19.32 brings capabilities also available in Oracle AI Database 26ai to Oracle Database 19c, helping organizations:
- Strengthen database connections with TLS 1.3
- Reduce future quantum decryption risks for sensitive data
- Support regulated environments with FIPS 140-3 mode
Strengthen database connections with TLS 1.3
TLS 1.3 provides a modern foundation for protecting network traffic between Oracle Database clients and servers. It removes older algorithm choices, streamlines protocol negotiation, and supports evolving enterprise security requirements.
Large organizations rarely have a uniform client environment. A single database estate may support packaged applications, custom applications, administrative tools, integration platforms, batch processes, and older connection libraries using TLS 1.2. These clients are unlikely to become TLS 1.3-ready at the same time, making migration flexibility especially important for Oracle Database 19c customers.
Applying Release Update 19.32 does not change server or client behavior by default, and the existing cryptographic provider remains in use. When organizations enable the new provider, it supports both TLS 1.3 and TLS 1.2, allowing newer clients to use TLS 1.3 while existing Oracle Database 19c clients can continue using TLS 1.2. This enables a phased migration without requiring every application and client to upgrade at the same time.
Prepare for future quantum decryption risk
One of the most immediate quantum-related concerns is commonly described as “harvest now, decrypt later.” An attacker could capture encrypted network traffic today and retain it in the hope that future quantum computers will make it possible to decrypt that traffic.
This risk is especially relevant when database traffic contains information that must remain confidential for many years, including personally identifiable information, health records, financial information, government data, and intellectual property.
To help address this risk, the new cryptographic provider in Oracle Database 19.32 supports ML-KEM, a post-quantum key-encapsulation mechanism standardized by the National Institute of Standards and Technology (NIST). It also supports hybrid key establishment, which combines ML-KEM with established cryptographic methods for key exchange.
Plan the transition to FIPS 140-3 mode
FIPS 140-3 mode is particularly important for government agencies, government contractors, and regulated organizations whose security programs must account for federal standards, procurement requirements, or accreditation processes.
The new cryptographic provider in Oracle Database 19.32 supports non-FIPS, FIPS 140-2, and FIPS 140-3 modes, allowing organizations to select the operating mode that aligns with their requirements.
Because some algorithms available in other modes are not supported in FIPS 140-3 mode, organizations should review the Oracle documentation, inventory existing cryptographic dependencies, and validate application and client compatibility before enabling it.
Take a phased approach to cryptographic modernization
Cryptographic modernization is not a single configuration change. It requires coordination across databases, clients, applications, network infrastructure, and compliance programs.
Release Update 19.32 gives Oracle Database 19c customers a phased path forward.
Organizations can begin testing the new cryptographic provider, identify applications that are ready for TLS 1.3, prioritize traffic that requires protection against future quantum decryption, and prepare regulated environments for FIPS 140-3 requirements.
This approach allows enterprises to strengthen cryptographic security now while aligning the transition with their broader application and database modernization plans.
Please watch this space for a technical note that describes these capabilities in depth.
Learn more:
