Skip to main content
This guide configures Oracle Database 19c Transparent Data Encryption (TDE) on Oracle Solaris 11.4 SPARC to use CryptoHub as its hardware key store. Oracle TDE reaches CryptoHub through the Futurex PKCS #11 library (FXPKCS11) 6.5 for Solaris SPARC. This guide applies to the following combination: For Oracle Database TDE on Linux or Windows, see Oracle Database TDE.

What you’ll build

  • A CryptoHub Oracle Database TDE service and a client endpoint for the database server.
  • The Futurex PKCS #11 library installed in the location where Oracle Database finds hardware security module (HSM) libraries.
  • An Oracle database that uses CryptoHub as its HSM key store. The TDE master encryption key is created on CryptoHub and does not leave it.
  • An auto-login configuration that opens the HSM key store when the database starts, without an operator.
  • An encrypted column and an encrypted tablespace that prove the database encrypts data with the CryptoHub key.

How it works

Oracle TDE uses a two-tier key model:
  • TDE master encryption key: CryptoHub creates and stores this key. Oracle Database gives it a label that starts with ORACLE.TDE.HSM.MK.
  • Table and tablespace keys: Oracle Database creates these keys and stores them in the database, encrypted by the master encryption key.
When Oracle Database needs a table or tablespace key, it sends the encrypted key to CryptoHub through PKCS #11. CryptoHub decrypts it with the master encryption key and returns the result. The master encryption key never leaves CryptoHub. If the HSM key store is closed, or CryptoHub cannot be reached, Oracle Database cannot read encrypted data. The integration follows these steps:
  1. Deploy the Oracle Database TDE service in CryptoHub and create a client endpoint for the database server.
  2. Install the Futurex PKCS #11 library and the endpoint configuration on the Solaris server.
  3. Point Oracle Database at the HSM key store.
  4. Open the HSM key store and create the TDE master encryption key on CryptoHub.
  5. Configure auto-login so the key store opens when the database starts.
  6. Encrypt data and verify that access depends on CryptoHub.

Why this integration uses PKCS #11

Oracle Database connects to an HSM key store through a PKCS #11 library that the HSM vendor supplies. Oracle Database loads the library from a fixed directory, /opt/oracle/extapi/64/hsm/. The Futurex PKCS #11 library connects to the CryptoHub Host API over mutual TLS, and it uses the credentials in the endpoint bundle. You do not add any CryptoHub connection details to Oracle Database. The Futurex PKCS #11 library build must match the platform. Oracle Database 19c on Solaris SPARC is a 64-bit SPARC V9 process, so it can load only the 64-bit SPARC build of the library. Linux and Windows builds do not work on this platform.

Integration workflow

  1. Review the prerequisites.
  2. Prepare CryptoHub.
  3. Install and configure Futurex PKCS #11.
  4. Configure Oracle Database for the HSM key store.
  5. Create the TDE master encryption key.
  6. Configure auto-login for the HSM key store.
  7. Verify the integration.
  8. Troubleshoot the integration.