> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Oracle Database for the HSM key store

> Set the WALLET_ROOT and TDE_CONFIGURATION initialization parameters so Oracle Database 19c uses CryptoHub as its HSM key store.

Oracle Database 19c uses two initialization parameters to find its key store:

* `WALLET_ROOT` sets the directory for key store files. Oracle Database needs this directory even when the master encryption key is on an HSM. You also use it for the auto-login key store later in this guide.
* `TDE_CONFIGURATION` sets the key store type. The value `KEYSTORE_CONFIGURATION=HSM` tells Oracle Database to use the PKCS #11 library.

These parameters replace the `ENCRYPTION_WALLET_LOCATION` setting in `sqlnet.ora`. If `sqlnet.ora` has an `ENCRYPTION_WALLET_LOCATION` entry, remove it.

<Warning>
  This guide configures a database that does not use TDE yet. If the database already has TDE master encryption keys in a software key store or in a different HSM, you must migrate those keys. A new master encryption key on CryptoHub cannot decrypt data that an earlier master encryption key protects. For the migration steps, see \[Managing the Keystore and the Master Encryption Key]\([https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key) store-and-tde-master-encryption-key.html) in the Oracle documentation.
</Warning>

## Create the wallet directory

As the Oracle software owner, create the wallet directory:

```shell wrap theme={null}
su - oracle
mkdir -p /u01/app/oracle/admin/ORCL/wallet
chmod 700 /u01/app/oracle/admin/ORCL/wallet
```

## Set the initialization parameters

<Steps>
  <Step>
    Connect to the database as `SYSDBA`:

    ```shell wrap theme={null}
    export ORACLE_HOME=/u01/app/oracle/product/19.0.0/db_1
    export ORACLE_SID=ORCL
    export PATH=$ORACLE_HOME/bin:$PATH
    sqlplus / as sysdba
    ```
  </Step>

  <Step>
    Set `WALLET_ROOT`. This parameter is static, so Oracle Database applies it at the next startup:

    ```sql wrap theme={null}
    ALTER SYSTEM SET WALLET_ROOT='/u01/app/oracle/admin/ORCL/wallet' SCOPE=SPFILE;
    ```
  </Step>

  <Step>
    Restart the database:

    ```sql wrap theme={null}
    SHUTDOWN IMMEDIATE;
    STARTUP;
    ```
  </Step>

  <Step>
    Set `TDE_CONFIGURATION` to use the HSM key store. This parameter is dynamic, so it does not need a restart:

    ```sql wrap theme={null}
    ALTER SYSTEM SET TDE_CONFIGURATION="KEYSTORE_CONFIGURATION=HSM" SCOPE=BOTH;
    ```
  </Step>

  <Step>
    Confirm the parameter values:

    ```sql wrap theme={null}
    SELECT name, value FROM v$parameter WHERE name IN ('wallet_root', 'tde_configuration');
    ```

    <Check>
      The output shows these values:

      ```text theme={null}
      NAME                 VALUE
      -------------------- --------------------------------------------------
      wallet_root          /u01/app/oracle/admin/ORCL/wallet
      tde_configuration    KEYSTORE_CONFIGURATION=HSM
      ```
    </Check>
  </Step>
</Steps>

Continue to [Create the TDE master encryption key](./create-the-tde-master-encryption-key).
