Supported hardware
- CryptoHub,
7.3.0.xor later.
Supported Oracle Database versions
19c,21c, and26ai.
This integration was validated end to end with Oracle AI Database 26ai Free Release 23.26.3.0.0 and the CryptoHub Client Library PKCS #11 1.0.0.
Supported operating systems
- Linux Server (Rocky Linux 8 for this example; GUI not required):
- Windows 10 or later
Required access
- An account on the CryptoHub with administrator privileges to deploy new services.
- Local administrator access on the computer where Oracle Database is installed.
Client library and runtime
- The CryptoHub Client Library PKCS #11 module (
libcryptohub-pkcs11.so) ships inside the endpoint download; you do not obtain or install a separate package. - Select the endpoint Platform for the operating system and runtime libraries of the Oracle process that loads the module, which can differ from the host OS when Oracle runs in a container (for example, Oracle Linux 8 / OpenSSL 1.1 inside a container on an Ubuntu/OpenSSL 3 host).
Network and firewall
- Allow outbound TCP port 443 (CryptoHub REST API over TLS) from the computer running Oracle Database to the CryptoHub, specified by FQDN (for example,
cryptohub.example.com) or CIDR (for example,203.0.113.0/24).
Other
- Oracle Database
- Installation Guide for Oracle Database:
- Oracle Guide to securing data with Oracle TDE (general concepts and how to enable TDE):
- Oracle Guide to use HSM with TDE:
This guide assumes that you are running the server, have root permissions, and have already installed the Oracle database with the necessary configurations to support TDE.

