# Attach two encrypted database failed

**URL:** <https://discuss.zetetic.net/t/attach-two-encrypted-database-failed/4450>\
**Category:** Issues\
**Created:** [June 5, 2020, 12:18pm UTC](https://discuss.zetetic.net/t/attach-two-encrypted-database-failed/4450 "2020-06-05T12:18:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pearzl](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/pearzl/32/1386_2.png) [@pearzl](https://discuss.zetetic.net/u/pearzl)\
**Post date:** [June 5, 2020, 12:18pm UTC](https://discuss.zetetic.net/t/attach-two-encrypted-database-failed/4450/1 "2020-06-05T12:18:56Z")

</div>

I met a problem while attaching two encrypted database whose key are same.

Following steps can reproduce the issue.

```auto
localhost:2h zhangli.pear$ sqlcipher T/test_attach_cipher1.db 
SQLCipher version 3.30.1 2019-10-10 20:19:45
Enter ".help" for usage hints.
sqlite> pragma key='123';
ok
sqlite> .tables
c1
sqlite> ATTACH DATABASE 'T/test_attach_cipher2.db' AS c;
Error: file is not a database
sqlite> .exit

```

The most weird is that if `.table` query is ignored before attach, the problem will disappear.

```auto
localhost:2h zhangli.pear$ sqlcipher T/test_attach_cipher1.db 
SQLCipher version 3.30.1 2019-10-10 20:19:45
Enter ".help" for usage hints.
sqlite> pragma key='123';
ok
sqlite> ATTACH DATABASE 'T/test_attach_cipher2.db' AS c;
sqlite> .tables
c.c2 c1  
sqlite> .exit

```

I can’t figure it out, hope someone can help me.  
Thanks

---

<div class="post-metadata">

**Author:** ![developernotes](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/developernotes/32/1309_2.png) [@developernotes](https://discuss.zetetic.net/u/developernotes)\
**Post date:** [June 5, 2020, 2:16pm UTC](https://discuss.zetetic.net/t/attach-two-encrypted-database-failed/4450/2 "2020-06-05T14:16:26Z")

</div>

Hi @pearzl

In your first scenario, while the password is the same between the two databases, they each have a different database salt. Per the [implementation notes](https://www.zetetic.net/sqlcipher/sqlcipher-api/#notes-attach), when you do not specify a `KEY` parameter in the attach statement, the raw key and database salt are copied over during attach. When you invoke `.tables`, the encryption key is derived to produce a result from the first database. A separate context is created when you attach a database, and the keyspec (representation of your encryption key and database salt) is copied over from the main database to the attached database. Because each database has a unique salt, it is unable to decrypt the content in the second database.

In the second scenario, because the encryption key has not yet be derived at the point when you perform the attach operation, each context will derive their encryption key independently. This will allow each database to decrypt their content.

You can address this issue by using the `KEY` specifier when [attaching a database](https://www.zetetic.net/sqlcipher/sqlcipher-api/#attach).
