> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure auto-login for the HSM key store

> Store the CryptoHub endpoint PIN in an Oracle auto-login software key store so the HSM key store opens automatically when the database starts.

By default, the HSM key store is closed after each database restart, and an administrator must open it. Until the key store is open, the database cannot read encrypted data.

Auto-login removes this manual step. Oracle Database stores the CryptoHub endpoint PIN as a secret in a small software key store. At startup, Oracle Database reads the PIN from the software key store and opens the HSM key store. The master encryption key stays on CryptoHub. The software key store holds only the PIN.

<Warning>
  Anyone who can read the auto-login key store file (`cwallet.sso`) can open the HSM key store on this server. Keep the wallet directory owned by the Oracle software owner with mode `700`, and include the file in your host security controls. If your security policy requires a person to open the key store, skip this page and open the key store manually after each restart.
</Warning>

In the commands on this page:

* Replace `CRYPTOHUB_ENDPOINT_PIN` with the CryptoHub endpoint PIN.
* Replace `SOFTWARE_KEYSTORE_PASSWORD` with a new password for the software key store. Store this password securely.

## Create the software key store directory

Oracle Database looks for the software key store in the `tde` subdirectory of `WALLET_ROOT`. As the Oracle software owner, create the directory:

```shell wrap theme={null}
mkdir -p /u01/app/oracle/admin/ORCL/wallet/tde
chmod 700 /u01/app/oracle/admin/ORCL/wallet/tde
```

## Store the PIN in an auto-login key store

Run these steps in `sqlplus / as sysdba`.

<Steps>
  <Step>
    Set the key store type to a software key store, so that the next commands create and open the software key store:

    ```sql wrap theme={null}
    ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=FILE" SCOPE=BOTH;
    ```
  </Step>

  <Step>
    Create the software key store:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT CREATE KEYSTORE IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD";
    ```

    <Check>
      Oracle Database returns `keystore altered.`, and the file `ewallet.p12` appears in `/u01/app/oracle/admin/ORCL/wallet/tde`.
    </Check>
  </Step>

  <Step>
    Open the software key store:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD";
    ```

    <Note>
      The software key store must be open before you add the secret. If it is closed, the next step fails with `ORA-28417: password-based keystore is not open`.
    </Note>
  </Step>

  <Step>
    Add the CryptoHub endpoint PIN as the HSM password secret. `HSM_PASSWORD` is the client name that Oracle Database reads for the HSM key store PIN. Put both values in single quotes:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT ADD SECRET 'CRYPTOHUB_ENDPOINT_PIN' FOR CLIENT 'HSM_PASSWORD' IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD" WITH BACKUP;
    ```
  </Step>

  <Step>
    Create the auto-login key store from the software key store:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT CREATE AUTO_LOGIN KEYSTORE FROM KEYSTORE IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD";
    ```

    <Check>
      The file `cwallet.sso` appears in `/u01/app/oracle/admin/ORCL/wallet/tde`.
    </Check>
  </Step>

  <Step>
    Set the key store type to use the HSM key store with the software key store:

    ```sql wrap theme={null}
    ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=HSM|FILE" SCOPE=BOTH;
    ```
  </Step>

  <Step>
    Restart the database:

    ```sql wrap theme={null}
    SHUTDOWN IMMEDIATE;
    STARTUP;
    ```
  </Step>

  <Step>
    Confirm that both key stores opened without a manual command:

    ```sql wrap theme={null}
    SELECT WRL_TYPE, WRL_PARAMETER, STATUS, WALLET_TYPE FROM v$encryption_wallet;
    ```

    <Check>
      The output shows these rows. The software key store has no master key because the master encryption key is on CryptoHub, so `OPEN_NO_MASTER_KEY` is the expected status for the `FILE` row.

      ```text theme={null}
      WRL_TYPE  WRL_PARAMETER                               STATUS              WALLET_TYPE
      --------  ------------------------------------------  ------------------  -----------
      FILE      /u01/app/oracle/admin/ORCL/wallet/tde/      OPEN_NO_MASTER_KEY  AUTOLOGIN
      HSM                                                   OPEN                HSM
      ```
    </Check>
  </Step>
</Steps>

Continue to [Verify the integration](./verify-integration).
