> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshoot Oracle Database 19c TDE on Oracle Solaris SPARC

> Resolve library loading, CryptoHub connection, key store open, master key, and auto-login failures for Oracle Database 19c TDE with CryptoHub on Oracle Solaris SPARC.

Find the failing layer first. Oracle Database reports its errors in SQL\*Plus and in the database alert log. The Futurex PKCS #11 library writes its errors to the log file set by `<LOG-FILE>` in `/etc/fxpkcs11.cfg`.

## The library does not load

**Symptom:** `file` does not report a 64-bit SPARC library, or `ldd libfxpkcs11.so` shows `file not found` for a dependency.

**Resolution:**

1. Confirm that `file libfxpkcs11.so` reports `ELF 64-bit MSB dynamic lib SPARCV9`. Oracle Database on Solaris SPARC loads only the 64-bit SPARC build.
2. For a missing `libcrypto.so.3` or `libssl.so.3`, confirm that the OpenSSL 3 libraries are installed in `/lib/64`.
3. For a missing `libstdc++.so.6` or `libgcc_s.so.1`, install the GCC runtime libraries from the Oracle Solaris package repository.

## The configuration test cannot connect to CryptoHub

**Symptom:** `configTest` shows empty **Token Info**, or the log does not show `Established connection to HSM`.

**Resolution:**

1. Confirm that the server can reach CryptoHub on TCP port 2001, and that no TLS inspection device is in the path.
2. Confirm that `client.p12` and the `.cer` files are in the same directory as `fxpkcs11.cfg`.
3. Confirm that the Oracle software owner can read `fxpkcs11.cfg`, `client.p12`, and the `.cer` files.
4. Confirm that the Oracle software owner can write to the `<LOG-FILE>` location.

## The HSM key store does not open

**Symptom:** `ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN` fails with `ORA-28353: failed to open wallet`, or `v$encryption_wallet` still shows the HSM key store as `CLOSED`.

**Resolution:**

1. Run `find /opt/oracle/extapi -type f`. The output must show exactly one library file.
2. Confirm that `TDE_CONFIGURATION` contains `KEYSTORE_CONFIGURATION=HSM`.
3. Confirm that you put the CryptoHub endpoint PIN in double quotes. Without double quotes, Oracle Database changes the PIN to uppercase.
4. Run `configTest` as the Oracle software owner to confirm that the library can reach CryptoHub.
5. Confirm that the endpoint is still active in the Oracle Database TDE service in CryptoHub.

## The master key cannot be found

**Symptom:** `ADMINISTER KEY MANAGEMENT SET KEY` fails with `ORA-28374: typed master key not found in wallet` or `ORA-28396: rekey of enc$ dictionary table failed`. Encrypted data fails with `ORA-28365` or `ORA-28374` while the HSM key store shows `OPEN`.

**Resolution:** The database has data that an earlier master encryption key protects, and CryptoHub does not have that key. This happens when a database that already used TDE is connected to a new key store without a key migration.

* Connect the database to the key store that holds the earlier master encryption key, and then migrate the key. For the migration steps, see \[Managing the Keystore and the Master Encryption Key]\([https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key](https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/managing-key) store-and-tde-master-encryption-key.html) in the Oracle documentation.
* A new master encryption key cannot replace an earlier key that is lost. Data that the lost key protects cannot be recovered.

## The software key store secret cannot be added

**Symptom:** `ADMINISTER KEY MANAGEMENT ADD SECRET` fails with `ORA-28417: password-based keystore is not open`.

**Resolution:** Set `TDE_CONFIGURATION` to `KEYSTORE_CONFIGURATION=FILE`, and then open the software key store with `ADMINISTER KEY MANAGEMENT SET KEYSTORE OPEN IDENTIFIED BY "SOFTWARE_KEYSTORE_PASSWORD"`. Then add the secret again. See [Configure auto-login for the HSM key store](./configure-auto-login).

## The HSM key store does not open at startup

**Symptom:** After a restart with auto-login configured, `v$encryption_wallet` shows the HSM key store as `CLOSED`, and the `FILE` row does not show `AUTOLOGIN`.

**Resolution:**

1. Confirm that `cwallet.sso` is in the `tde` subdirectory of `WALLET_ROOT`, for example `/u01/app/oracle/admin/ORCL/wallet/tde`.
2. Confirm that `TDE_CONFIGURATION` is `KEYSTORE_CONFIGURATION=HSM|FILE`.
3. Confirm that the secret uses the client name `HSM_PASSWORD` and holds the current CryptoHub endpoint PIN.
4. Re-create the auto-login key store with the steps in [Configure auto-login for the HSM key store](./configure-auto-login).
