[oracle@ip-172-31-30-29 ~]$ aws rds add-option-to-option-group \
    --option-group-name TEST-RDS-ORA-OPTION \
    --options "OptionName=NATIVE_NETWORK_ENCRYPTION,OptionSettings=[{Name=SQLNET.ENCRYPTION_SERVER,Value=REQUIRED}]" \
    --apply-immediately
    
aws rds add-option-to-option-group \
    --option-group-name TEST-RDS-ORA-OPTION \
    --options "OptionName=NATIVE_NETWORK_ENCRYPTION,OptionSettings=[{Name=SQLNET.ENCRYPTION_SERVER,Value=REQUIRED}]" \
    --apply-immediately
    

{
    "OptionGroup": {
        "OptionGroupName": "test-rds-ora-option",
        "OptionGroupDescription": "TEST-RDS-ORA-OPTION",
        "EngineName": "oracle-se2",
        "MajorEngineVersion": "19",
        "Options": [
            {
                "OptionName": "NATIVE_NETWORK_ENCRYPTION",
                "OptionDescription": "Native Network Encryption",
                "Persistent": false,
                "Permanent": false,
                "OptionSettings": [
                    {
                        "Name": "SQLNET.ENCRYPTION_SERVER",
                        "Value": "REQUIRED",
                        "DefaultValue": "REQUESTED",
                        "Description": "Specifies the desired encryption behavior",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
                        "IsModifiable": true,
                        "IsCollection": false
                    },
                    {
                        "Name": "SQLNET.ENCRYPTION_TYPES_CLIENT",
                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 ",
                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 0,DES40",
:...skipping...
{
    "OptionGroup": {
        "OptionGroupName": "test-rds-ora-option",
        "OptionGroupDescription": "TEST-RDS-ORA-OPTION",
        "EngineName": "oracle-se2",
        "MajorEngineVersion": "19",
        "Options": [
            {
                "OptionName": "NATIVE_NETWORK_ENCRYPTION",
                "OptionDescription": "Native Network Encryption",
                "Persistent": false,
                "Permanent": false,
                "OptionSettings": [
                    {
                        "Name": "SQLNET.ENCRYPTION_SERVER",
                        "Value": "REQUIRED",
                        "DefaultValue": "REQUESTED",
                        "Description": "Specifies the desired encryption behavior",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
                        "IsModifiable": true,
                        "IsCollection": false
                    },
                    {
                        "Name": "SQLNET.ENCRYPTION_TYPES_CLIENT",
                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 ",
                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 0,DES40",
                        "Description": "Specifies list of encryption algorithms in order of intended use",
:...skipping...
{
    "OptionGroup": {
        "OptionGroupName": "test-rds-ora-option",
        "OptionGroupDescription": "TEST-RDS-ORA-OPTION",
        "EngineName": "oracle-se2",
        "MajorEngineVersion": "19",
        "Options": [
            {
                "OptionName": "NATIVE_NETWORK_ENCRYPTION",
                "OptionDescription": "Native Network Encryption",
                "Persistent": false,
                "Permanent": false,
                "OptionSettings": [
                    {
                        "Name": "SQLNET.ENCRYPTION_SERVER",
                        "Value": "REQUIRED",
                        "DefaultValue": "REQUESTED",
                        "Description": "Specifies the desired encryption behavior",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
                        "IsModifiable": true,
                        "IsCollection": false
                    },
                    {
                        "Name": "SQLNET.ENCRYPTION_TYPES_CLIENT",
                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 ",
                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 0,DES40",
                        "Description": "Specifies list of encryption algorithms in order of intended use",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_ 40,DES40",
                        "IsModifiable": true,
                        "IsCollection": true
                    },
                    {
                        "Name": "SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER",
:...skipping...
{
    "OptionGroup": {
        "OptionGroupName": "test-rds-ora-option",
        "OptionGroupDescription": "TEST-RDS-ORA-OPTION",
        "EngineName": "oracle-se2",
        "MajorEngineVersion": "19",
        "Options": [
            {
                "OptionName": "NATIVE_NETWORK_ENCRYPTION",
                "OptionDescription": "Native Network Encryption",
                "Persistent": false,
                "Permanent": false,
                "OptionSettings": [
                    {
                        "Name": "SQLNET.ENCRYPTION_SERVER",
                        "Value": "REQUIRED",
                        "DefaultValue": "REQUESTED",
                        "Description": "Specifies the desired encryption behavior",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
                        "IsModifiable": true,
                        "IsCollection": false
                    },
                    {
                        "Name": "SQLNET.ENCRYPTION_TYPES_CLIENT",
                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 ",
                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 0,DES40",
                        "Description": "Specifies list of encryption algorithms in order of intended use",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_ 40,DES40",
                        "IsModifiable": true,
                        "IsCollection": true
                    },
                    {
                        "Name": "SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER",
                        "Value": "SHA512,SHA384,SHA256,SHA1,MD5",
                        "DefaultValue": "SHA512,SHA384,SHA256,SHA1,MD5",
                        "Description": "Specifies list of checksumming algorithms in order of intended use",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "SHA256,SHA384,SHA512,SHA1,MD5",
                        "IsModifiable": true,
:...skipping...
{
    "OptionGroup": {
        "OptionGroupName": "test-rds-ora-option",
        "OptionGroupDescription": "TEST-RDS-ORA-OPTION",
        "EngineName": "oracle-se2",
        "MajorEngineVersion": "19",
        "Options": [
            {
                "OptionName": "NATIVE_NETWORK_ENCRYPTION",
                "OptionDescription": "Native Network Encryption",
                "Persistent": false,
                "Permanent": false,
                "OptionSettings": [
                    {
                        "Name": "SQLNET.ENCRYPTION_SERVER",
                        "Value": "REQUIRED",
                        "DefaultValue": "REQUESTED",
                        "Description": "Specifies the desired encryption behavior",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
                        "IsModifiable": true,
                        "IsCollection": false
                    },
                    {
                        "Name": "SQLNET.ENCRYPTION_TYPES_CLIENT",
                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 ",
                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 0,DES40",
                        "Description": "Specifies list of encryption algorithms in order of intended use",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_ 40,DES40",
                        "IsModifiable": true,
                        "IsCollection": true
                    },
                    {
                        "Name": "SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER",
                        "Value": "SHA512,SHA384,SHA256,SHA1,MD5",
                        "DefaultValue": "SHA512,SHA384,SHA256,SHA1,MD5",
                        "Description": "Specifies list of checksumming algorithms in order of intended use",
                        "ApplyType": "STATIC",
                        "DataType": "STRING",
                        "AllowedValues": "SHA256,SHA384,SHA512,SHA1,MD5",
                        "IsModifiable": true,
                        "IsCollection": true
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.CRYPTO_CHECKSUM_SERVER",
: ESCESCOOBB                        "Value": "REQUESTED",
: ESCESCOOBB                        "DefaultValue": "REQUESTED",
: ESCESCOOBB                        "Description": "Specifies the desired data integrity behavior",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": false
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.ENCRYPTION_CLIENT",
: ESCESCOOBB                        "Value": "REQUESTED",
: ESCESCOOBB                        "DefaultValue": "REQUESTED",
: ESCESCOOBB                        "Description": "Specifies the desired encryption behavior",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": false
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.ALLOW_WEAK_CRYPTO",
: ESCESCOOBB                        "Value": "TRUE",
: ESCESCOOBB                        "DefaultValue": "TRUE",
: ESCESCOOBB                        "Description": "Allow use of weak encryption and checksumming algorithms.",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "TRUE,FALSE",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": false
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT",
: ESCESCOOBB                        "Value": "SHA512,SHA384,SHA256",
: ESCESCOOBB                        "DefaultValue": "SHA512,SHA384,SHA256",
: ESCESCOOBB                        "Description": "Specifies list of checksumming algorithms in order of intended use",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "SHA256,SHA384,SHA512,SHA1,MD5",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": true
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.ALLOW_WEAK_CRYPTO_CLIENTS",
: ESCESCOOBB                        "Value": "TRUE",
: ESCESCOOBB                        "DefaultValue": "TRUE",
: ESCESCOOBB                        "Description": "Block clients that have not been patched with July 2021 PSU from conne : ESCESCOOBBcting to the database.",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "TRUE,FALSE",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": false
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.ENCRYPTION_TYPES_SERVER",
: ESCESCOOBB                        "Value": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_40,DES40 : ESCESCOOBB",
: ESCESCOOBB                        "DefaultValue": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_4 : ESCESCOOBB0,DES40",
: ESCESCOOBB                        "Description": "Specifies list of encryption algorithms in order of intended use",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "RC4_256,AES256,AES192,3DES168,RC4_128,AES128,3DES112,RC4_56,DES,RC4_ : ESCESCOOBB40,DES40",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": true
: ESCESCOOBB                    },
: ESCESCOOBB                    {
: ESCESCOOBB                        "Name": "SQLNET.CRYPTO_CHECKSUM_CLIENT",
: ESCESCOOBB                        "Value": "REQUESTED",
: ESCESCOOBB                        "DefaultValue": "REQUESTED",
: ESCESCOOBB                        "Description": "Specifies the desired data integrity behavior",
: ESCESCOOBB                        "ApplyType": "STATIC",
: ESCESCOOBB                        "DataType": "STRING",
: ESCESCOOBB                        "AllowedValues": "ACCEPTED,REJECTED,REQUESTED,REQUIRED",
: ESCESCOOBB                        "IsModifiable": true,
: ESCESCOOBB                        "IsCollection": false
: ESCESCOOBB                    }
: ESCESCOOBB                ],
: ESCESCOOBB                "DBSecurityGroupMemberships": [],
: ESCESCOOBB                "VpcSecurityGroupMemberships": []
: ESCESCOOBB            }
: ESCESCOOBB        ],
: ESCESCOOBB        "AllowsVpcAndNonVpcInstanceMemberships": false,
: ESCESCOOBB        "OptionGroupArn": "arn:aws:rds:ap-southeast-2:010526254989:og:test-rds-ora-option"
: ESCESCOOBB    }
: ESCESCOOBB}
: ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END) ESCESCOOBB(END)(END)[oracle@ip-172-31-30-29 ~]$ 
