Menu
AWS CloudHSM
User Guide

Oracle TDE with AWS CloudHSM: Set Up the Prerequisites

To accomplish Oracle TDE integration with AWS CloudHSM, you need the following:

  • An active AWS CloudHSM cluster with at least one HSM.

  • An Amazon EC2 instance running the Amazon Linux operating system with the following software installed:

    • The AWS CloudHSM client and command line tools.

    • The AWS CloudHSM software library for PKCS #11.

    • Oracle Database. AWS CloudHSM supports Oracle TDE integration with Oracle Database versions 11 and 12.

  • A cryptographic user (CU) to own and manage the TDE master encryption key on the HSMs in your cluster.

Complete the following steps to set up all of the prerequisites.

To set up the prerequisites for Oracle TDE integration with AWS CloudHSM

  1. Complete the steps in Getting Started. After you do so, you'll have an active cluster with one HSM. You will also have an Amazon EC2 instance running the Amazon Linux operating system. The AWS CloudHSM client and command line tools will also be installed and configured.

  2. (Optional) Add more HSMs to your cluster. For more information, see Adding an HSM.

  3. Connect to your Amazon EC2 client instance and do the following:

    1. Install the AWS CloudHSM software library for PKCS #11.

    2. Install Oracle Database. For more information, see the Oracle Database documentation. AWS CloudHSM supports Oracle TDE integration with Oracle Database versions 11 and 12.

    3. Start the AWS CloudHSM client.

    4. Update the configuration file for the cloudhsm_mgmt_util command line tool.

    5. Use the cloudhsm_mgmt_util command line tool to create a cryptographic user (CU) on your cluster. For more information, see Managing HSM Users.

After you complete these steps, you can Configure the Database.