This section explains how to configure the Oracle Server database.

Export Oracle Variables

On the Oracle Server, export the Oracle variables as follows: 

export ORACLE_SID=orcl
export ORACLE_BASE=/opt/oracle
export ORACLE_HOME=$ORACLE_BASE/product/<oracle_db_version>/dbhome_1
export PATH=$PATH:$ORACLE_HOME/bin
export TNS_ADMIN=$ORACLE_HOME/network/admin

Where ORACLE_BASE is the Oracle installation directory. This is usually /opt/oracle or /u01/app/oracle.

Link pkcs11 library

To configure the Oracle PKCS#11 library folder to use the Entrust KeyControl PKCS#11 API.

  1. On the Oracle Server, create the following directory path for the Entrust API library as the oracle user. Configure ownership and permissions on the directory as: owner=oracle; group=oinstall; permissions=775.

    sudo chown -R oracle:oinstall /opt/oracle/
    sudo chmod -R 775 /opt/oracle/
    mkdir -p /opt/oracle/extapi/64/hsm/entrust
    chown oracle:oinstall /opt/oracle/extapi/64/hsm/entrust
    chmod 775 /opt/oracle/extapi/64/hsm/entrust
  2. Link the PKCS#11 library into the directory as the oracle user.

    ln -s /opt/hcs/lib/libpkcs11.so /opt/oracle/extapi/64/hsm/entrust/libpkcs11.so

    Important: The link must be created in /opt/oracle/extapi/64/hsm/entrust/libpkcs11.so or the connection between the Oracle DB and Cryptographic Security Platform Vault will not work.

Bounce the Database

sqlplus / as sysdba

sql> shutdown immediate;

sql> startup