Skip to main content
Find the failing layer first. Oracle Database reports its errors in SQL*Plus and in the database alert log. The Futurex PKCS #11 library writes its errors to the log file set by <LOG-FILE> in /etc/fxpkcs11.cfg.

The library does not load

Symptom: file does not report a 64-bit SPARC library, or ldd libfxpkcs11.so shows file not found for a dependency. Resolution:
  1. Confirm that file libfxpkcs11.so reports ELF 64-bit MSB dynamic lib SPARCV9. Oracle Database on Solaris SPARC loads only the 64-bit SPARC build.
  2. For a missing libcrypto.so.3 or libssl.so.3, confirm that the OpenSSL 3 libraries are installed in /lib/64.
  3. For a missing libstdc++.so.6 or libgcc_s.so.1, install the GCC runtime libraries from the Oracle Solaris package repository.

The configuration test cannot connect to CryptoHub

Symptom: configTest shows empty Token Info, or the log does not show Established connection to HSM. Resolution:
  1. Confirm that the server can reach CryptoHub on TCP port 2001, and that no TLS inspection device is in the path.
  2. Confirm that client.p12 and the .cer files are in the same directory as fxpkcs11.cfg.
  3. Confirm that the Oracle software owner can read fxpkcs11.cfg, client.p12, and the .cer files.
  4. Confirm that the Oracle software owner can write to the <LOG-FILE> location.

The HSM key store does not open

Symptom: ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN fails with ORA-28353: failed to open wallet, or v$encryption_wallet still shows the HSM key store as CLOSED. Resolution:
  1. Run find /opt/oracle/extapi -type f. The output must show exactly one library file.
  2. Confirm that TDE_CONFIGURATION contains KEYSTORE_CONFIGURATION=HSM.
  3. Confirm that you put the CryptoHub endpoint PIN in double quotes. Without double quotes, Oracle Database changes the PIN to uppercase.
  4. Run configTest as the Oracle software owner to confirm that the library can reach CryptoHub.
  5. Confirm that the endpoint is still active in the Oracle Database TDE service in CryptoHub.

The master key cannot be found

Symptom: ADMINISTER KEY MANAGEMENT SET KEY fails with ORA-28374: typed master key not found in wallet or ORA-28396: rekey of enc$ dictionary table failed. Encrypted data fails with ORA-28365 or ORA-28374 while the HSM key store shows OPEN. Resolution: The database has data that an earlier master encryption key protects, and CryptoHub does not have that key. This happens when a database that already used TDE is connected to a new key store without a key migration.
  • Connect the database to the key store that holds the earlier master encryption key, and then migrate the key. For the migration steps, see [Managing the Keystore and the Master Encryption Key](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key store-and-tde-master-encryption-key.html) in the Oracle documentation.
  • A new master encryption key cannot replace an earlier key that is lost. Data that the lost key protects cannot be recovered.

The software key store secret cannot be added

Symptom: ADMINISTER KEY MANAGEMENT ADD SECRET fails with ORA-28417: password-based keystore is not open. Resolution: Set TDE_CONFIGURATION to KEYSTORE_CONFIGURATION=FILE, and then open the software key store with ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD". Then add the secret again. See Configure auto-login for the HSM key store.

The HSM key store does not open at startup

Symptom: After a restart with auto-login configured, v$encryption_wallet shows the HSM key store as CLOSED, and the FILE row does not show AUTOLOGIN. Resolution:
  1. Confirm that cwallet.sso is in the tde subdirectory of WALLET_ROOT, for example /u01/app/oracle/admin/ORCL/wallet/tde.
  2. Confirm that TDE_CONFIGURATION is KEYSTORE_CONFIGURATION=HSM|FILE.
  3. Confirm that the secret uses the client name HSM_PASSWORD and holds the current CryptoHub endpoint PIN.
  4. Re-create the auto-login key store with the steps in Configure auto-login for the HSM key store.