Supported hardware
- Excrypt HSM (formerly Vectera Plus), firmware
7.2.x.xor later.
Supported operating systems
- Linux with OpenSSL 1.0.x, 1.1.x, or 3.x. The Futurex PKCS #11 package includes a build for each OpenSSL branch; use the build that matches the OpenSSL version on the computer (
openssl version). The 64-bit (x64) builds cover all three branches; the 32-bit (x86) builds cover only OpenSSL 1.0.x and 1.1.x. - Windows 10 or later
Required access
- Both default administrator identities (Admin1 and Admin2), or two identities with equivalent permissions. Creating application partitions and identities requires dual control, so both must log in.
- Local administrator/root privileges on the computer where Oracle Database is installed.
Network and firewall
- Allow outbound TCP port 9100 (default Excrypt port) from the computer running Oracle Database to the Excrypt HSM, specified by FQDN (for example,
hsm.example.com) or CIDR (for example,10.0.0.0/24). - If you configure the HSM over the network with FXCLI or Excrypt Manager, allow TCP port 9009 (default admin port) from that workstation to the HSM. Administrator logins work only on the admin port.
Other
- OpenSSL, to create the client TLS key and certificate signing request.
- Oracle Database 12c
- Installation Guide for Oracle Database 12c: https://docs.oracle.com/en/database/oracle/oracledatabase/12.2/ladbi/index.html
- Oracle Guide to securing data with Oracle TDE (general concepts: how to enable TDE): https://docs.oracle.com/cd/B28359_01/network.111/b28530/asotrans.htm#g1011122
- Oracle Guide to use HSM with TDE: https://docs.oracle.com/cd/E11882_ 01/network.112/e40393/asotrans.htm#ASOAG640
This guide assumes that the Oracle database is already installed and configured to support TDE: https://docs.oracle.com/cd/B28359_01/network.111/b28530/asotrans.htm#g1011122.

