> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare CryptoHub

> Deploy the Oracle Database TDE service in CryptoHub 7.0.3.x and download a client endpoint bundle for the Oracle Solaris SPARC server.

Prepare the CryptoHub side of the integration: deploy the Oracle Database TDE service, and then create a client endpoint for the Solaris server.

## Deploy the Oracle Database TDE service

<Steps>
  <Step>
    Log in to CryptoHub under dual control with your administrator identities.
  </Step>

  <Step>
    Locate **Oracle Database TDE** in the service store, and then select **Deploy**.
  </Step>

  <Step>
    On **Service Setup**:

    * Enter a unique **Service Name**, or keep the default.
    * Keep the default **Service Category**.

    Select **Next**.
  </Step>

  <Step>
    On **Access Control**, confirm the authorized resources. The role you logged in with has access to the service by default. Add any other role that must administer this service, and then select **Next**.
  </Step>

  <Step>
    On **Service Info**, keep the default authentication mechanism, and then select **Deploy**.

    <Check>
      The Oracle Database TDE service appears under **Deployed Services**.
    </Check>
  </Step>
</Steps>

## Create a client endpoint

An endpoint represents the Solaris server. The endpoint bundle holds the credentials and the TLS files that the Futurex PKCS #11 library uses to authenticate to CryptoHub.

<Steps>
  <Step>
    Open the deployed Oracle Database TDE service, and then select **Endpoints**.
  </Step>

  <Step>
    Under **Manage Endpoints**, select **Add New**.
  </Step>

  <Step>
    Configure the endpoint:

    * Enter a unique **Endpoint Identifier**, or leave it empty for auto-generation.
    * Keep the auto-populated **CryptoHub Hostname**.
    * Set **Platform** to the Oracle Solaris 11.4 SPARC platform.

    Select **Add Endpoint**.
  </Step>

  <Step>
    Save the downloaded endpoint ZIP file.

    <Check>
      The endpoint ZIP file contains the files in the following table.
    </Check>
  </Step>
</Steps>

| File | Description |
| - | - |
| `libfxpkcs11.so` | The Futurex PKCS #11 library for Solaris SPARC. |
| `configTest` | Tests the configuration and the connection to CryptoHub. |
| `PKCS11Manager` | Tests PKCS #11 operations, such as log in and random number generation. |
| `fxpkcs11.cfg` | The library configuration. It contains the CryptoHub address, the endpoint identity, and the TLS settings. |
| `client.p12` | The client TLS certificate and private key, in an encrypted PKCS #12 file. |
| `client-cert.pem` | The client TLS certificate. |
| `ca-chain.pem` | The CA certificate bundle. |
| `CryptoHub NUMBER.cer` | The CryptoHub CA certificate that issued the client TLS certificate. `NUMBER` is the CryptoHub serial number. |
| `Futurex Test Root CA (ECC).cer` | The root CA certificate for the CryptoHub server TLS certificate. The name depends on your CryptoHub TLS configuration. |

<Warning>
  The endpoint ZIP file contains the endpoint credential and the PKCS #12 password. Store it as a secret. Delete copies that you do not need after you finish the installation.
</Warning>

Continue to [Install and configure Futurex PKCS #11](./install-and-configure-futurex-pkcs11).
