- Replace
CRYPTOHUB_ENDPOINT_PINwith the CryptoHub endpoint PIN. - Replace
SOFTWARE_KEYSTORE_PASSWORDwith a new password for the software key store. Store this password securely.
Create the software key store directory
Oracle Database looks for the software key store in thetde subdirectory of WALLET_ROOT. As the Oracle software owner, create the directory:
Store the PIN in an auto-login key store
Run these steps insqlplus / as sysdba.
1
Set the key store type to a software key store, so that the next commands create and open the software key store:
2
Create the software key store:
Oracle Database returns
keystore altered., and the file ewallet.p12 appears in /u01/app/oracle/admin/ORCL/wallet/tde.3
Open the software key store:
The software key store must be open before you add the secret. If it is closed, the next step fails with
ORA-28417: password-based keystore is not open.4
Add the CryptoHub endpoint PIN as the HSM password secret.
HSM_PASSWORD is the client name that Oracle Database reads for the HSM key store PIN. Put both values in single quotes:5
Create the auto-login key store from the software key store:
The file
cwallet.sso appears in /u01/app/oracle/admin/ORCL/wallet/tde.6
Set the key store type to use the HSM key store with the software key store:
7
Restart the database:
8
Confirm that both key stores opened without a manual command:
The output shows these rows. The software key store has no master key because the master encryption key is on CryptoHub, so
OPEN_NO_MASTER_KEY is the expected status for the FILE row.
