Skip to main content
Confirm that your environment meets these requirements.

Supported versions

  • CryptoHub 7.0.3.x.
  • Oracle Database 19c Enterprise Edition, installed as a non-container database (non-CDB).
  • Oracle Solaris 11.4 SPARC, 64-bit kernel.
  • Futurex PKCS #11 library 6.5 for Solaris 11.4 SPARC.
This guide uses a non-CDB database. In a multitenant (CDB) database, you run the key store commands from CDB$ROOT with the CONTAINER = ALL clause, and you open the key store and set a master encryption key for each pluggable database. For those steps, see the Oracle Database Advanced Security Guide.

Oracle Solaris server

Prepare a Solaris server that has:
  • Oracle Database 19c installed, with a database created and open.
  • OpenSSL 3 libraries in /lib/64. Oracle Solaris 11.4 includes them.
  • The GCC runtime libraries libstdc++.so.6 and libgcc_s.so.1 in /usr/lib/64.
The Futurex PKCS #11 library links to these system libraries. The installation page includes a check that confirms the library finds all of them.

Required access

  • Two CryptoHub administrator identities for dual-control service deployment.
  • Root access, or sudo, on the Solaris server, to install the library and the configuration files.
  • The Oracle software owner account (oracle in this guide), and SYSDBA access to the database.

Network and firewall

Allow outbound TCP port 2001 (the CryptoHub Host API port) from the Solaris server to CryptoHub. Use the CryptoHub FQDN, for example cryptohub.example.com.
TLS inspection or an SSL proxy can break the mutual TLS handshake. Exempt the CryptoHub FQDN from TLS inspection.
Confirm connectivity from the Solaris server:
The command must print the subject and issuer of the CryptoHub server certificate.

Environment used in this guide

This guide uses the following values. Replace them with the values for your environment.

Oracle documentation

Continue to Prepare CryptoHub.