RE: PostGreSQL TDE encryption patch - Mailing list pgsql-general

From Patrick FICHE
Subject RE: PostGreSQL TDE encryption patch
Date
Msg-id AM6PR05MB5287A0090C27F6C018997FB1EF920@AM6PR05MB5287.eurprd05.prod.outlook.com
Whole thread Raw
In response to PostGreSQL TDE encryption patch  ("Bhalodiya, Chirag" <chirag.bhalodiya@contractors.roche.com>)
Responses Re: PostGreSQL TDE encryption patch  ("Bhalodiya, Chirag" <chirag.bhalodiya@contractors.roche.com>)
List pgsql-general

Hi

 

CYBERTEC provided good installation guide (https://www.cybertec-postgresql.com/en/products/postgresql-transparent-data-encryption/).

 

Here is their answer to your question :

Q: Can I upgrade to an encrypted database?
A: In place encryption of existing clusters is currently not supported. A dump and reload to an encrypted instance is required, or logical replication can be used to perform the migration online.

 

Regards,

 

Patrick Fiche

Database Engineer, Aqsacom Sas.

c. 33 6 82 80 69 96

 

01-03_AQSA_Main_Corporate_Logo_JPEG_White_Low.jpg

 

From: Bhalodiya, Chirag <chirag.bhalodiya@contractors.roche.com>
Sent: Thursday, June 25, 2020 9:50 AM
To: pgsql-general@postgresql.org
Subject: PostGreSQL TDE encryption patch

 

Hi,

 

We are migrating our product to PostGreSQL from Oracle and as part of HIPPA(https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act) guidelines, we have a requirement to encrypt entire tablespace/specific tables using Transparent data encryption(TDE).

 

I was looking at TDE solution in PostGreSQL and went through following wiki:

 

I found following TDE patch from this wiki:  

 

However, I am not sure how to apply this patch and I had the following questions:

1. We are using PostGreSQL 12. Is it possible to apply patches on top of existing PostGreSQL installation?

2. Will it be available anytime sooner with a major release like PostGreSQL 13? 

 

Regards,

Chirag.

Attachment

pgsql-general by date:

Previous
From: Klaudie Willis
Date:
Subject: Re: n_distinct off by a factor of 1000
Next
From: Christoph Moench-Tegeder
Date:
Subject: Re: Log the incoming old SSL certs by pid or any way