---
title: "Breaking: #110319 - Encryption key is checked before ext_localconf.php loading"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:breaking-110319-1785315901"
source: "Changelog/15.0/Breaking-110319-EncryptionKeyCheckedBeforeLoadingExtLocalconf.rst"
modified: "2026-09-15T10:46:36+00:00"
---

# Breaking: #110319 - Encryption key is checked before ext_localconf.php loading

See [forge#110319](https://forge.typo3.org/issues/110319)

## Description

`\TYPO3\CMS\Core\Core\Bootstrap` verifies that
`$GLOBALS['TYPO3_CONF_VARS']['SYS']['encryptionKey']` is not empty and
throws a `\RuntimeException` otherwise. This check has been moved to
run *before* the `ext_localconf.php` files of all active extensions are
loaded. Previously it ran afterwards, and additionally after
`$GLOBALS['TCA']` had been populated.

The encryption key is part of the system configuration and is used for
security-relevant functionality. It must therefore be in place before any
extension code is executed during bootstrap.

In addition, `$GLOBALS['TCA']` is now assigned after
`TcaSchemaFactory->load()` has been called, so consumers can not
observe a state where the global array is populated but the schema
information is not yet available.

## Impact

Installations that set `$GLOBALS['TYPO3_CONF_VARS']['SYS']['encryptionKey']`
from within an `ext_localconf.php` file now run into the
"TYPO3 Encryption Key is empty" exception, as the check is executed before
the file is evaluated.

Code within `ext_localconf.php` files can not rely on
`$GLOBALS['TCA']` being available anymore - which was never a
guaranteed state, as `ext_localconf.php` files are loaded before TCA
is built. This is unchanged, but the assignment now happens later within
the bootstrap.

## Affected installations

Installations that populate the encryption key at runtime from an
`ext_localconf.php` file, for instance by reading it from an
environment variable or an external secret store.

## Migration

Set the encryption key in the system configuration, either directly in
`config/system/settings.php` or in
`config/system/additional.php`, both of which are evaluated before
the check:

**config/system/additional.php**

```php
$GLOBALS['TYPO3_CONF_VARS']['SYS']['encryptionKey'] = getenv('TYPO3_ENCRYPTION_KEY');
```
