Manual
Perform the following steps to use the manual method:1
Run the following command to manually open the hardware keystore, making the HSM accessible:
Sql
2
Optionally, disable access with the following command:
Sql
You must re-enable access to the HSM every time you restart the database instance with the manual option.
Automatic
Perform the following steps to use the automatic method:An auto-login wallet stores the HSM credentials in an auto-login software keystore. This configuration reduces the system security, but it supports automated operations. Additionally, it facilitates deployments that require the HSM to log in again automatically.
1
If the hardware keystore is open, close it with the following command:
Sql
2
If you have not migrated from a software keystore, create the software keystore with the hardware keystore password in the appropriate location (for example,
/etc/ORACLE/WALLETS/orcl).Sql
3
If you have migrated and are using an auto-login software keystore in a specific location (for example, The location of the keystore for the ADMINISTER KEY MANAGEMENT merge statement does not need to be the location of the keystore in use.
/etc/ORACLE/WALLETS/HSM), create the software password keystore with the hardware keystore password from the auto-login keystore.Sql
4
Reconfigure the
sqlnet.ora file and add the keystore location of the software keystore created in step 2 to the DIRECTORY setting of the ENCRYPTION_WALLET_LOCATION setting.Sql
5
To make the change take effect, either reconnect to the database or log out and then log in again.
6
Open the software keystore.
Sql
The Software\Keystore\Password value needs to match the value set in step 2.
7
Add or update the secret in the software keystore.The SECRET is the HSM password, and the client is HSM_PASSWORD.HSM_PASSWORD is an Oracle-defined client name representing the HSM password as a secret in the software keystore.
Sql
8
Close the software keystore.
Sql
9
Create (or re-create) the auto-login keystore.
Sql
10
Update the
sqlnet.ora file to use the HSM location.Sql
The HSM auto-login keystore should open automatically the next time that a TDE operation executes.
11
To confirm that the auto-login wallet is working, reboot the database, reconnect, and run the following query:
Sql
If the auto-login wallet was configured properly, the following output displays:
Sql

