public inbox for [email protected]  
help / color / mirror / Atom feed
From: ManiR <[email protected]>
To: [email protected]
Subject: Request for cryptographic mechanisms used in PostgreSQL
Date: Tue, 20 Jan 2026 14:47:36 +0530
Message-ID: <CAA5LiFbFsaE1qT+iDtRf0769HG7nFuGzPDa9AJwTzEauNK8J=g@mail.gmail.com> (raw)

Hi PostgreSQL community,

As part of a security documentation update, we are preparing a *Cryptographic
Bill of Materials (CBOM)* to document the cryptographic mechanisms used by
the services deployed in our environment.

We would like your guidance on the *cryptographic mechanisms used by
PostgreSQL*, including:

   -

   The *types of cryptographic mechanisms* involved (for example, TLS/SSL
   for client-server communication, authentication mechanisms, password
   hashing, replication security, encryption at rest where applicable)
   -

   The *cryptographic algorithms and protocols* used
   -

   The *source or storage location* of cryptographic material (for example,
   configuration files, certificates, private keys, system catalogs, or
   external key management systems)
   -

   The *purpose* of each mechanism (for example, data-in-transit
   encryption, authentication, access control, replication security)

Our goal is to accurately document PostgreSQL’s cryptographic controls
for *compliance
and audit purposes*. This request is for documentation clarity only and is *not
related to vulnerability disclosure*.

Any clarification or references to official PostgreSQL documentation would
be greatly appreciated.

Thank you for your time and support.


reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: [email protected]
  Cc: [email protected]
  Subject: Re: Request for cryptographic mechanisms used in PostgreSQL
  In-Reply-To: <CAA5LiFbFsaE1qT+iDtRf0769HG7nFuGzPDa9AJwTzEauNK8J=g@mail.gmail.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox