> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Before you start

> Review the CryptoHub, Oracle Solaris SPARC, Oracle Database 19c, access, and network requirements for Oracle TDE with CryptoHub.

Confirm that your environment meets these requirements.

## Supported versions

* CryptoHub `7.0.3.x`.
* Oracle Database 19c Enterprise Edition, installed as a non-container database (non-CDB).
* Oracle Solaris 11.4 SPARC, 64-bit kernel.
* Futurex PKCS #11 library 6.5 for Solaris 11.4 SPARC.

<Note>
  This guide uses a non-CDB database. In a multitenant (CDB) database, you run the key store commands from `CDB$ROOT` with the `CONTAINER = ALL` clause, and you open the key store and set a master encryption key for each pluggable database. For those steps, see the Oracle Database Advanced Security Guide.
</Note>

## Oracle Solaris server

Prepare a Solaris server that has:

* Oracle Database 19c installed, with a database created and open.
* OpenSSL 3 libraries in `/lib/64`. Oracle Solaris 11.4 includes them.
* The GCC runtime libraries `libstdc++.so.6` and `libgcc_s.so.1` in `/usr/lib/64`.

The Futurex PKCS #11 library links to these system libraries. The installation page includes a check that confirms the library finds all of them.

## Required access

* Two CryptoHub administrator identities for dual-control service deployment.
* Root access, or `sudo`, on the Solaris server, to install the library and the configuration files.
* The Oracle software owner account (`oracle` in this guide), and `SYSDBA` access to the database.

## Network and firewall

Allow outbound TCP port **2001** (the CryptoHub Host API port) from the Solaris server to CryptoHub. Use the CryptoHub FQDN, for example `cryptohub.example.com`.

<Warning>
  TLS inspection or an SSL proxy can break the mutual TLS handshake. Exempt the CryptoHub FQDN from TLS inspection.
</Warning>

Confirm connectivity from the Solaris server:

```shell wrap theme={null}
echo | openssl s_client -connect cryptohub.example.com:2001 2>/dev/null | openssl x509 -noout -subject -issuer
```

The command must print the subject and issuer of the CryptoHub server certificate.

## Environment used in this guide

This guide uses the following values. Replace them with the values for your environment.

| Item | Value |
| - | - |
| `ORACLE_BASE` | `/u01/app/oracle` |
| `ORACLE_HOME` | `/u01/app/oracle/product/19.0.0/db_1` |
| `ORACLE_SID` | `ORCL` |
| Oracle software owner | `oracle`, primary group `oinstall` |
| TDE wallet root | `/u01/app/oracle/admin/ORCL/wallet` |

## Oracle documentation

* [Oracle Database 19c Installation Guide for Oracle Solaris](https://docs.oracle.com/en/database/oracle/oracle-database/19/ssdbi/index.html)
* [Oracle Database 19c Advanced Security Guide: Configuring Transparent Data Encryption](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/configuring-transparent-data-encryption.html)

Continue to [Prepare CryptoHub](./prepare-cryptohub).
