public inbox for [email protected]
help / color / mirror / Atom feedFrom: ManiR <[email protected]>
To: [email protected]
Subject: Request for cryptographic mechanisms used in PostgreSQL
Date: Tue, 20 Jan 2026 14:47:36 +0530
Message-ID: <CAA5LiFbFsaE1qT+iDtRf0769HG7nFuGzPDa9AJwTzEauNK8J=g@mail.gmail.com> (raw)
Hi PostgreSQL community,
As part of a security documentation update, we are preparing a *Cryptographic
Bill of Materials (CBOM)* to document the cryptographic mechanisms used by
the services deployed in our environment.
We would like your guidance on the *cryptographic mechanisms used by
PostgreSQL*, including:
-
The *types of cryptographic mechanisms* involved (for example, TLS/SSL
for client-server communication, authentication mechanisms, password
hashing, replication security, encryption at rest where applicable)
-
The *cryptographic algorithms and protocols* used
-
The *source or storage location* of cryptographic material (for example,
configuration files, certificates, private keys, system catalogs, or
external key management systems)
-
The *purpose* of each mechanism (for example, data-in-transit
encryption, authentication, access control, replication security)
Our goal is to accurately document PostgreSQL’s cryptographic controls
for *compliance
and audit purposes*. This request is for documentation clarity only and is *not
related to vulnerability disclosure*.
Any clarification or references to official PostgreSQL documentation would
be greatly appreciated.
Thank you for your time and support.
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected]
Subject: Re: Request for cryptographic mechanisms used in PostgreSQL
In-Reply-To: <CAA5LiFbFsaE1qT+iDtRf0769HG7nFuGzPDa9AJwTzEauNK8J=g@mail.gmail.com>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox