Skip to content
You are reading Consensys Quorum Plugins development version documentation and some displayed features may not be available in the stable release. You can switch to stable version using the version box at screen bottom.

Configure the Encrypted Storage plugin

Encrypt data at rest with the Encrypted Storage plugin and a 256-bit AES encryption key. Store the encryption key locally or in HashiCorp Vault.

TLS is enabled by default for communication between Hyperledger Besu and HashiCorp Vault. Configure TLS in the file used to retrieve the encryption key.


The Encrypted Storage plugin must be enabled when the node is started for the first time and the blockchain database is created. In other words, you cannot encrypt an existing unencrypted database.

The encryption key cannot be changed after the database is created.

Using a locally stored encryption key

Generate the encryption key before configuring encryption. In this example an encrypted key file is created using the openssl rand -out /myNode/encryptionKey 32 command.

Configure encrypted storage using a locally stored encryption key by enabling the Encrypted Storage plugin and setting the appropriate options.


besu --key-value-storage=encrypted-storage --plugin-encrypted-storage-key=/myNode/encryptionKey

The command line:

Using an encryption key stored in HashiCorp Vault


  • HashiCorp server must be running.
  • Encryption key must be written to HashiCorp Vault as a hex string.
  • HashiCorp Vault server certificate authority (CA) certificates. Supported truststore types include PEM, PKCS12, and JKS.

Create the TOML configuration file to obtain the encryption key from HashiCorp Vault and configure TLS. In this example the configuration file is named /myNode/config.toml:


Configure encrypted storage by enabling the Encrypted Storage plugin and setting the appropriate options.


besu --key-value-storage=encrypted-storage --plugin-encrypted-storage-hashicorp-config=/myNode/config.toml

The command line:

ConsenSys has acquired Quorum from J.P. Morgan. Please read the FAQ.
Questions or feedback? You can obtain paid professional support by ConsenSys at