<LOG-FILE> in /etc/fxpkcs11.cfg.
The library does not load
Symptom:file does not report a 64-bit SPARC library, or ldd libfxpkcs11.so shows file not found for a dependency.
Resolution:
- Confirm that
file libfxpkcs11.soreportsELF 64-bit MSB dynamic lib SPARCV9. Oracle Database on Solaris SPARC loads only the 64-bit SPARC build. - For a missing
libcrypto.so.3orlibssl.so.3, confirm that the OpenSSL 3 libraries are installed in/lib/64. - For a missing
libstdc++.so.6orlibgcc_s.so.1, install the GCC runtime libraries from the Oracle Solaris package repository.
The configuration test cannot connect to CryptoHub
Symptom:configTest shows empty Token Info, or the log does not show Established connection to HSM.
Resolution:
- Confirm that the server can reach CryptoHub on TCP port 2001, and that no TLS inspection device is in the path.
- Confirm that
client.p12and the.cerfiles are in the same directory asfxpkcs11.cfg. - Confirm that the Oracle software owner can read
fxpkcs11.cfg,client.p12, and the.cerfiles. - Confirm that the Oracle software owner can write to the
<LOG-FILE>location.
The HSM key store does not open
Symptom:ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN fails with ORA-28353: failed to open wallet, or v$encryption_wallet still shows the HSM key store as CLOSED.
Resolution:
- Run
find /opt/oracle/extapi -type f. The output must show exactly one library file. - Confirm that
TDE_CONFIGURATIONcontainsKEYSTORE_CONFIGURATION=HSM. - Confirm that you put the CryptoHub endpoint PIN in double quotes. Without double quotes, Oracle Database changes the PIN to uppercase.
- Run
configTestas the Oracle software owner to confirm that the library can reach CryptoHub. - Confirm that the endpoint is still active in the Oracle Database TDE service in CryptoHub.
The master key cannot be found
Symptom:ADMINISTER KEY MANAGEMENT SET KEY fails with ORA-28374: typed master key not found in wallet or ORA-28396: rekey of enc$ dictionary table failed. Encrypted data fails with ORA-28365 or ORA-28374 while the HSM key store shows OPEN.
Resolution: The database has data that an earlier master encryption key protects, and CryptoHub does not have that key. This happens when a database that already used TDE is connected to a new key store without a key migration.
- Connect the database to the key store that holds the earlier master encryption key, and then migrate the key. For the migration steps, see [Managing the Keystore and the Master Encryption Key](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key store-and-tde-master-encryption-key.html) in the Oracle documentation.
- A new master encryption key cannot replace an earlier key that is lost. Data that the lost key protects cannot be recovered.
The software key store secret cannot be added
Symptom:ADMINISTER KEY MANAGEMENT ADD SECRET fails with ORA-28417: password-based keystore is not open.
Resolution: Set TDE_CONFIGURATION to KEYSTORE_CONFIGURATION=FILE, and then open the software key store with ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD". Then add the secret again. See Configure auto-login for the HSM key store.
The HSM key store does not open at startup
Symptom: After a restart with auto-login configured,v$encryption_wallet shows the HSM key store as CLOSED, and the FILE row does not show AUTOLOGIN.
Resolution:
- Confirm that
cwallet.ssois in thetdesubdirectory ofWALLET_ROOT, for example/u01/app/oracle/admin/ORCL/wallet/tde. - Confirm that
TDE_CONFIGURATIONisKEYSTORE_CONFIGURATION=HSM|FILE. - Confirm that the secret uses the client name
HSM_PASSWORDand holds the current CryptoHub endpoint PIN. - Re-create the auto-login key store with the steps in Configure auto-login for the HSM key store.

