Database TDE MCP Server for CipherTrust CAKM Integration - Provides tools for managing Transparent Data Encryption (TDE) operations across SQL Server and Oracle databases with integration to Thales CipherTrust Application Key Management (CAKM) and CDSP
Server has 9 tools with generally adequate schemas and descriptions, but several critical gaps limit production readiness. Tool descriptions are reasonably detailed (avg ~180 chars), but many lack explicit error handling guidance, recovery paths, and security warnings. Parameter descriptions are present but inconsistent in detail. No input validation examples or constraint documentation visible in code. Output schemas are mentioned in docstrings but not formally documented in responses. The codebase shows basic structure but lacks comprehensive parameter validation, idempotent operation guarantees, and actionable error messages. Several tools expose security-sensitive operations (encryption, key rotation) without confirmation patterns or dry-run options.
List all configured database connections. Returns: JSON string containing list of database connections with their basic information.
Manage Oracle TDE configuration parameters. --- **Operations:** - `get`: Retrieves current TDE configuration parameters. - `set`: Sets TDE-related parameters like wallet_root. - `verify`: Verifies the TDE setup and provides recommendations. ---
Manage Oracle Master Encryption Keys (generate, rotate, list). Operations: generate, rotate, list - Generates Master Encryption Keys (MEK) for Oracle - Rotates existing keys with backup creation - Lists key information and status
Encrypt or decrypt Oracle tablespaces and manage encryption status. This tool provides comprehensive tablespace encryption management for Oracle databases, supporting both online and offline encryption methods with container-aware operations.
Comprehensive Oracle wallet management operations. --- **Operations:** - `open`: Opens the wallet, making keys available. - `close`: Closes the wallet. - `status`: Provides detailed status of the wallet (FILE and HSM). - `backup`: Backs up the wallet files. - `merge`: Merges two wallets. - `autologin`: Manages the auto-login (SSO) wallet (requires autologin_operation sub-parameter). ---
CRITICAL: No input validation or constraint enforcement visible in code. Parameters like 'operation' accept free-form strings without enum validation. LLMs can pass invalid operations (e.g. 'decrypt_all', 'rotate_fast') that fail at runtime instead of being caught upfront.
CRITICAL: Sensitive credentials (ciphertrust_username, ciphertrust_password) exposed as tool parameters. These will appear in MCP call logs, agent traces, and prompt history. Must use server-side secret injection via environment variables or vault.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Manage SQL Server External Key Manager (EKM) objects. This tool handles the lifecycle of EKM providers, the credentials used to access them, and the server logins that are mapped to those credentials.
Encrypt or decrypt one or more SQL Server databases. This tool manages the encryption state of SQL Server databases. The 'encrypt' operation is idempotent and will automatically handle the creation of the necessary TDE infrastructure (keys, logins, credentials). --- **Operations:** - `encrypt`: Encrypts the specified databases. Skips any that are already encrypted. - `decrypt`: Decrypts the specified databases. **Database Targeting (`database_names`):** - A single database name: "MyDatabase" - A comma-separated list: "DB1,DB2,DB3" - All user databases: "all databases" (for encryption) - All encrypted databases: "all encrypted databases" (for decryption) ---
Manage the lifecycle of SQL Server cryptographic keys used for TDE. This tool handles Asymmetric keys (Master Keys) stored in an EKM provider and the Database Encryption Keys (DEKs) that they protect. --- **Operations:** - `create`: Creates a new Asymmetric Key in the EKM and registers it in SQL Server. - `list`: Lists all Asymmetric and Symmetric keys, indicating if they are in use. - `drop`: Drops a key from SQL Server. Can optionally remove it from the EKM. - `drop_unused`: Drops all keys that are not actively encrypting a database. - `rotate_master`: Rotates the Asymmetric Key for a specific database. - `rotate_dek`: Rotates the Database Encryption Key for a specific database. ---
Oracle TDE deployment operations for complete database encryption setup. OPERATION TYPES & WHEN TO USE THEM: 1. "setup_hsm_only" - HSM-only TDE setup (NO auto-login) - Use when: Setting up TDE with HSM only, skip auto-login creation - Creates: HSM keystore only - Requires: NO software_wallet_password needed - Result: Manual wallet opening required after database restart 2. "setup_hsm_with_autologin" - Complete TDE setup with HSM + auto-login - Use when: Setting up TDE with both HSM and auto-login wallet - Creates: HSM keystore + software wallet + auto-login keystore - Requires: software_wallet_password (for software wallet creation) - Result: Database can start without manual wallet opening 3. "add_autologin" - Add auto-login to existing TDE database - Use when: Database already has TDE, want to add auto-login capability - Creates: Software wallet + auto-login keystore for existing HSM setup - Requires: software_wallet_password (for new software wallet) - Result: Existing HSM TDE + new auto-login capability 4. "migrate_software_to_hsm" - Migrate software wallet to HSM - Use when: Database has software-based TDE, want to move to HSM - Migrates: Existing software wallet keys to HSM - Requires: software_wallet_password (for existing software wallet) - Result: HSM-based TDE (preserves auto-login if it existed) 5. "get_tde_status" - Check current TDE status and configuration - Use when: Want to see current wallet status and TDE configuration
HIGH: Irreversible operations (encrypt databases, rotate keys, migrate to HSM) lack confirmation or dry-run patterns. An agent mistakenly invoking 'oracle_tde_deployment' with 'setup_hsm_only' could permanently alter production database encryption without reversibility.
HIGH: Error responses in code (e.g. 'Missing required arguments for encryption') do not guide LLM recovery. Should include: what went wrong, which params are required, what to do next. Raw JSON error returns force LLMs to infer corrective action.
HIGH: Output schemas not formally documented. Code returns JSON but does not specify field names, types, or structure in parameter definitions. LLMs cannot reliably chain outputs to downstream tool inputs.
MEDIUM: Parameter descriptions lack constraint details. E.g. 'key_size' shows '(e.g., "2048")' but no validation rules (min, max, allowed values). 'operation' lists options in prose ('encrypt or decrypt') instead of enum constraint. LLMs may infer wrong values from examples.
MEDIUM: Tool naming uses 'manage_*' prefix (e.g. 'manage_sql_encryption', 'manage_oracle_wallet'), which is overly generic and conflates multiple concerns (create, list, update, delete). Better: split into 'encrypt_database', 'decrypt_database', 'list_encryption_keys', 'rotate_encryption_key'.
MEDIUM: No permission checks visible. Tools do not verify calling user/agent has authority to encrypt production databases or rotate HSM keys. Missing scope declarations (e.g. 'requires: write:encryption, write:keys').
MEDIUM: No pagination or result limiting on 'list_database_connections' or multi-database operations. Returning 1000+ database names as a flat JSON list wastes tokens and risks context window overflow.
MEDIUM: 'oracle_tde_deployment' tool mixes multiple operations (setup_hsm_only, setup_hsm_with_autologin, add_autologin, migrate_software_to_hsm, get_tde_status) in one tool with complex conditional logic. Should be split into separate tools (deploy_tde_hsm, deploy_tde_with_autologin, migrate_wallet_to_hsm, check_tde_status) for clarity and composability.