Re: Encryption with customer provided key in a multi tenant Postgres JSONB DB - Mailing list pgsql-general

From Saurav Sarkar
Subject Re: Encryption with customer provided key in a multi tenant Postgres JSONB DB
Date
Msg-id CAP+kwAX8=vedAYdM9Qe8az03kQB60REgn1L7C_UEG7yQy8BFcA@mail.gmail.com
Whole thread Raw
In response to Re: Encryption with customer provided key in a multi tenant Postgres JSONB DB  ("David G. Johnston" <david.g.johnston@gmail.com>)
Responses Re: Encryption with customer provided key in a multi tenant Postgres JSONB DB  (Bruce Momjian <bruce@momjian.us>)
List pgsql-general
Hi David,

Thanks for the reply.

I just wanted to check if there is any possibility or any activity ongoing which can enable database or fine granular level encryption in future.

Probably then i can wait otherwise i have to move towards Client Side encryption as you mentioned.

Best Regards,
Saurav

On Thu, Nov 12, 2020 at 11:44 AM David G. Johnston <david.g.johnston@gmail.com> wrote:
On Wed, Nov 11, 2020 at 10:49 PM Saurav Sarkar <saurav.sarkar1@gmail.com> wrote:

We have a multi tenant application where for each tenant we create separate tables . So for e.g. if i have 100 tenants then i have 100 tables.

Now we want to have encryption for the data in the tables with the tenant provided key. Is it possible to encrypt tables in the same database with different keys. ?

I learnt that PostgreSQL itself does not support encryption at database level or other finer granular levels . May i please know if in future can this be supported ? or is it not possible technically at all ?

So you answered your own question...though you can encrypt the data being stored within the table by supplying it pre-encrypted and letting the client deal with encryption and decryption - which is probably your best bet anyway.

Almost everything is possible if you throw enough time and effort at it so I'm not sure how to constructively answer the last two questions.  Why do you ask?

David J.

pgsql-general by date:

Previous
From: Paul Förster
Date:
Subject: Re: Discovering postgres binary directory location
Next
From: Matthias Apitz
Date:
Subject: ECPG sqlca error handling