Should 'root' user of OS have privileges of MyDiamo encryption/decryption?

You don't need to.

The only thing you need is 'root' authority for DB server.

There's nothing to do with root user of OS for encryption and decryption.

