> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create the TDE master encryption key

> Open the Oracle Database HSM key store with the CryptoHub endpoint PIN and create the TDE master encryption key on CryptoHub.

Open the HSM key store, and then create the TDE master encryption key. Oracle Database sends the CryptoHub endpoint PIN to the Futurex PKCS #11 library, and the library logs in to CryptoHub as the endpoint identity.

<Warning>
  Put the CryptoHub endpoint PIN in **double quotes** in every `IDENTIFIED BY` clause. Without double quotes, Oracle Database changes the value to uppercase, and CryptoHub rejects the login.
</Warning>

In the commands on this page, replace `CRYPTOHUB_ENDPOINT_PIN` with the PIN that you copied from `fxpkcs11.cfg`.

<Steps>
  <Step>
    Connect to the database as `SYSDBA`:

    ```shell wrap theme={null}
    sqlplus / as sysdba
    ```
  </Step>

  <Step>
    Open the HSM key store:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "CRYPTOHUB_ENDPOINT_PIN";
    ```

    <Check>
      Oracle Database returns `keystore altered.`
    </Check>
  </Step>

  <Step>
    Create the TDE master encryption key on CryptoHub:

    ```sql wrap theme={null}
    ADMINISTER KEY MANAGEMENT SET KEY IDENTIFIED BY "CRYPTOHUB_ENDPOINT_PIN" WITH BACKUP;
    ```

    <Check>
      Oracle Database returns `keystore altered.`
    </Check>
  </Step>

  <Step>
    Confirm that the HSM key store is open:

    ```sql wrap theme={null}
    SELECT WRL_TYPE, STATUS, WALLET_TYPE FROM v$encryption_wallet;
    ```

    <Check>
      The output shows this row:

      ```text theme={null}
      WRL_TYPE             STATUS                         WALLET_TYPE
      -------------------- ------------------------------ --------------------
      HSM                  OPEN                           HSM
      ```
    </Check>
  </Step>

  <Step>
    Record the ID of the master encryption key:

    ```sql wrap theme={null}
    SELECT masterkeyid FROM v$database_key_info;
    ```

    The master encryption key on CryptoHub has a label that starts with `ORACLE.TDE.HSM.MK.06` and then this ID. You use the ID to find the key in CryptoHub when you [verify the integration](./verify-integration#confirm-the-master-encryption-key-in-cryptohub).
  </Step>
</Steps>

<Note>
  The HSM key store stays open until you close it or the database stops. Unless you configure auto-login, you must open the HSM key store after every database restart. The next page configures auto-login.
</Note>

Continue to [Configure auto-login for the HSM key store](./configure-auto-login).
