Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vF0UA-005vGA-De for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 01:32:53 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1vF0U9-002Wkf-AM for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 01:32:52 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vF0U8-002WkX-RW for pgsql-general@lists.postgresql.org; Sat, 01 Nov 2025 01:32:51 +0000 Received: from smtp76.iad3b.emailsrvr.com ([146.20.161.76]) by makus.postgresql.org with smtp (Exim 4.96) (envelope-from ) id 1vF0U6-004pI3-0W for pgsql-general@postgresql.org; Sat, 01 Nov 2025 01:32:50 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=g001.emailsrvr.com; s=feedback; t=1761960768; bh=t2AQXELn42iTwKXwCYstp7I5QXZThqohiY2uULoW05k=; h=Subject:From:Date:To:From; b=MNFT+RYIyCBn/E1+MnGJTMK37egsVKPpnWxFGsQJIDO15OSDdET/ljgxrIh3diy8q UCn+XNrb8w0qPz72sWyP8Lz+wW/mYjnpvzsv30SFtVFkZeV+gzw+ORu0f/S2Exr5Lu RYTaZxCrKKbyPvQs2AwgsVT+ulXpNjZ14nviCPnE= X-Auth-ID: xof@thebuild.com Received: by smtp2.relay.iad3b.emailsrvr.com (Authenticated sender: xof-AT-thebuild.com) with ESMTPSA id 6AC9220212; Fri, 31 Oct 2025 21:32:48 -0400 (EDT) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3776.700.51.11.4\)) Subject: Re: Enquiry about TDE with PgSQL From: Christophe Pettus In-Reply-To: Date: Fri, 31 Oct 2025 18:32:17 -0700 Cc: pgsql-general , Kai Wagner , Laurenz Albe , Ron Johnson Content-Transfer-Encoding: quoted-printable Message-Id: <86A619E7-04B7-45EB-850A-54CBD388733C@thebuild.com> References: To: Bruce Momjian X-Mailer: Apple Mail (2.3776.700.51.11.4) X-Classification-ID: ffa945b9-45b8-443b-8bf3-449ae6ee3139-1-1 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk > On Oct 31, 2025, at 17:21, Bruce Momjian wrote: >=20 > I think column-level encryption, on the client side, actually does > improve security and is preferable to file system level TDE, and I = think > many here feel the same way. Absolutely. Unfortunately, too many IT security policies are basically = a grab-bag of things that someone has read that all claimed to be "best = practice," and the degree to which they can be educated on the topic is = variable.=