Skip to main content
Oracle Database 19c uses two initialization parameters to find its key store:
  • WALLET_ROOT sets the directory for key store files. Oracle Database needs this directory even when the master encryption key is on an HSM. You also use it for the auto-login key store later in this guide.
  • TDE_CONFIGURATION sets the key store type. The value KEYSTORE_CONFIGURATION=HSM tells Oracle Database to use the PKCS #11 library.
These parameters replace the ENCRYPTION_WALLET_LOCATION setting in sqlnet.ora. If sqlnet.ora has an ENCRYPTION_WALLET_LOCATION entry, remove it.
This guide configures a database that does not use TDE yet. If the database already has TDE master encryption keys in a software key store or in a different HSM, you must migrate those keys. A new master encryption key on CryptoHub cannot decrypt data that an earlier master encryption key protects. For the migration steps, see [Managing the Keystore and the Master Encryption Key](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key store-and-tde-master-encryption-key.html) in the Oracle documentation.

Create the wallet directory

As the Oracle software owner, create the wallet directory:

Set the initialization parameters

1
Connect to the database as SYSDBA:
2
Set WALLET_ROOT. This parameter is static, so Oracle Database applies it at the next startup:
3
Restart the database:
4
Set TDE_CONFIGURATION to use the HSM key store. This parameter is dynamic, so it does not need a restart:
5
Confirm the parameter values:
The output shows these values:
Continue to Create the TDE master encryption key.