Skip to main content
Install the Futurex PKCS #11 library on the Solaris server, and then place the endpoint configuration where the library finds it. Run the commands on this page as root, unless a step says otherwise.

Extract the endpoint bundle

1
Copy the endpoint ZIP file to the Solaris server, and then extract it to a staging directory:
2
Confirm that the library is the 64-bit SPARC build:
The output contains ELF 64-bit MSB dynamic lib SPARCV9.
3
Confirm that the library finds all of the system libraries that it needs:
Every dependency resolves to a path. For example, libcrypto.so.3 and libssl.so.3 resolve to /lib/64, and libstdc++.so.6 and libgcc_s.so.1 resolve to /usr/lib/64. No line shows file not found.

Install the library for Oracle Database

Oracle Database searches the /opt/oracle/extapi/64/hsm/ directory tree for the HSM PKCS #11 library.
The /opt/oracle/extapi/64/hsm/ directory tree must contain exactly one library file. If Oracle Database finds more than one library, it cannot open the HSM key store. If you upgrade the Futurex PKCS #11 library, remove the directory of the earlier version.
1
Create the library directory. The last part of the path is the library version:
2
Copy the library to the directory, and then give the Oracle software owner access to it:
3
Confirm that the directory tree contains only one file:
The output shows only /opt/oracle/extapi/64/hsm/futurex/6.5/libfxpkcs11.so.

Place the configuration and TLS files

The Futurex PKCS #11 library reads /etc/fxpkcs11.cfg by default. The configuration refers to the TLS files by relative path, so the TLS files must be in the same directory as the configuration.
1
Copy the configuration and the TLS files to /etc:
2
Give the Oracle software owner ownership of the files. The configuration and the PKCS #12 file contain secrets, so only the owner can read them:
3
Open /etc/fxpkcs11.cfg in a text editor, and then set the log file location:
/etc/fxpkcs11.cfg
The Oracle software owner must be able to write to this location.

Test the connection to CryptoHub

1
Copy the test program to a directory that the Oracle software owner can use:
2
As the Oracle software owner, run the configuration test:
The Token Info section shows Label: Futurex and a Serial Number that matches your CryptoHub. The log file shows Established connection to HSM and FxPKCS11 library version 6.5.
If the test fails, see Troubleshooting.

Move the PIN to Oracle Database

The <CRYPTO-OPR-PASS> value in fxpkcs11.cfg is the PIN for the endpoint identity. Oracle Database gives this PIN to the library when it opens the HSM key store, so the configuration file does not need to keep it.
1
Copy the <CRYPTO-OPR-PASS> value from /etc/fxpkcs11.cfg, and then store it in a secure location. This guide calls this value the CryptoHub endpoint PIN.
2
Comment out the <CRYPTO-OPR-PASS> line:
/etc/fxpkcs11.cfg
3
Delete the staging directory:
Continue to Configure Oracle Database for the HSM key store.