Does TDE (Transperent Data Encryption) allows DBA to see the Encryption key?
If so, is there a way to avoid it so that only the designated application user can have access to and can manage encryption key?
we are considering tablespace encryption and this was sited as the major drawback of Oracle TDE. I'm not sure but it's hard to believe that Oracle would make a security tool which can not protect data from DBA's. Appreciate input from Encryption experts.
Thanks
Dinesh