WALLET_ROOTsets the directory for key store files. Oracle Database needs this directory even when the master encryption key is on an HSM. You also use it for the auto-login key store later in this guide.TDE_CONFIGURATIONsets the key store type. The valueKEYSTORE_CONFIGURATION=HSMtells Oracle Database to use the PKCS #11 library.
ENCRYPTION_WALLET_LOCATION setting in sqlnet.ora. If sqlnet.ora has an ENCRYPTION_WALLET_LOCATION entry, remove it.
Create the wallet directory
As the Oracle software owner, create the wallet directory:Set the initialization parameters
1
Connect to the database as
SYSDBA:2
Set
WALLET_ROOT. This parameter is static, so Oracle Database applies it at the next startup:3
Restart the database:
4
Set
TDE_CONFIGURATION to use the HSM key store. This parameter is dynamic, so it does not need a restart:5
Confirm the parameter values:
The output shows these values:

