Thread: Postgres & PKCS11 shenanigans

Postgres & PKCS11 shenanigans

From
Andreas Heijdendael
Date:
Hi fellow postgres enthusiasts,

Been trying to get PKCS11 to work on my PG14 installation but to no 
avail so far.
Included the [engines] section in my openssl.cnf configuration which 
includes links and configuration to the HSM hardware API (Cryptoki.so). 
But it will not budge when I fill in the PKCS11 URI into the Private Key 
location in postgres.conf.

Has any of you got this to work? I can't find anything about it online.

Postgres version: 14

HSM: Thales Protectserver PL1500

Running on Ubuntu 22.04.

Greetings,

Andreas