Skip to main content
Open the HSM key store, and then create the TDE master encryption key. Oracle Database sends the CryptoHub endpoint PIN to the Futurex PKCS #11 library, and the library logs in to CryptoHub as the endpoint identity.
Put the CryptoHub endpoint PIN in double quotes in every IDENTIFIED BY clause. Without double quotes, Oracle Database changes the value to uppercase, and CryptoHub rejects the login.
In the commands on this page, replace CRYPTOHUB_ENDPOINT_PIN with the PIN that you copied from fxpkcs11.cfg.
1
Connect to the database as SYSDBA:
2
Open the HSM key store:
Oracle Database returns keystore altered.
3
Create the TDE master encryption key on CryptoHub:
Oracle Database returns keystore altered.
4
Confirm that the HSM key store is open:
The output shows this row:
5
Record the ID of the master encryption key:
The master encryption key on CryptoHub has a label that starts with ORACLE.TDE.HSM.MK.06 and then this ID. You use the ID to find the key in CryptoHub when you verify the integration.
The HSM key store stays open until you close it or the database stops. Unless you configure auto-login, you must open the HSM key store after every database restart. The next page configures auto-login.
Continue to Configure auto-login for the HSM key store.