Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vF68q-007S4z-CG for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 07:35:15 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1vF68o-003u7y-0Y for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 07:35:13 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vF68n-003u7q-Gm for pgsql-general@lists.postgresql.org; Sat, 01 Nov 2025 07:35:12 +0000 Received: from mail-qt1-x831.google.com ([2607:f8b0:4864:20::831]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1vF68j-004ri1-0c for pgsql-general@postgresql.org; Sat, 01 Nov 2025 07:35:11 +0000 Received: by mail-qt1-x831.google.com with SMTP id d75a77b69052e-4ed411e8a29so8397541cf.3 for ; Sat, 01 Nov 2025 00:35:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=percona.com; s=google; t=1761982508; x=1762587308; darn=postgresql.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=hTRzBRBZaI8MUOb8rFPFKHpv7harMbFrU9iljhO8FNI=; b=KQx0LyKurS7UGJdMDli/obdU/dzIpRYSldnlWi2uORpqVf7k6wpOmFmMiLAVhTS4j+ Rtzd7gb6lmojWyqiDNVe3pf541rjtcPkdHTootynbdmh4+7cYCgzBTyYuUJ4O2y54wvH BFZ69r4ANwA66gLq1/OjhSIHgdBLU9lzefhIk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1761982508; x=1762587308; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=hTRzBRBZaI8MUOb8rFPFKHpv7harMbFrU9iljhO8FNI=; b=pNIxkgfg/2EAu+p7xPRh5blQStJVChC2XxYRIKdlcBx+Kcv5UYwKfw5uSzzvoo1n4r 2dhgtERRVf+p5HriUhExZulKVc5miqeMmHpyro7jB2dW82lpK+kOql6ExtC0v2+kKqS9 j/lAMVFM6PEJSd5TDO2Xd6YsDe+RKrDUU1s2kxASQ4tEZK5I/8a+xpeq1XDsiu3uY6Hs b7VM/5uAJt7+uwU9ipPIBVuUu3IUD5WNjNndkK6Q2/U5tOPgkzI3wxAeYlG/gULgB/5w d69ZplXtdUJPgX2pKoP8Au3MYoVl/fb4yKTRNJxZ9AoF0xpqgoSvM873YGbtCyO/ybvG 8RzA== X-Forwarded-Encrypted: i=1; AJvYcCWHwhSV5/NHBDbwynSpz4I3R4+2Ek20eHQ2fBpmBfLFgllvMet1R0+6U8HxOPKB0KeiCOsQAnLWnQ8p8ku+@postgresql.org X-Gm-Message-State: AOJu0YyGfL1Le8Lx2aepB4tHBRsch22WBlg/EiangjTNXj6gYP3OeZaa b0faDeced/OrKHC9HfODcsid5g/X+Tj3jxW47lIkF2cYrzU//dFsh4h++f2+pMdRg/q+kGbIUey ZmFxNk38NWXdlFS5wSa6ROZ22Kdspkgro6VgKXBBOEzaKG+a7xIueX+8d48PGvQtBd6hx5l1AQk A4xJBIyj4tBpWizpglMKQ2AXjoRbK/w+i1KKGO5pHdA38XesCNUtgMMnDCzJgEgIX0KK4fldOkL KAGHHMxsfg7Y7NAZvyegA5+gJ041nme3vI2jGNBg/ReTD4BK+g= X-Gm-Gg: ASbGncsGJ52qVwgFMSV8BuFdL8bTmsf4XwWUrnKWRfXK27a3C7LqfzoS5yTbG7atXvx jcUBPZVbhemmQdAa00awGp9VVe0OJsMRCPEOK1gF4cyRQLbc9x1ZLtppXSYW6LKdlJimfj7WNA8 r5NKLRLhqnP8oarjRwG2+BWpsJpN2JhXMu5feEhMkdcFb7xf4U/P2qvNl8y8EpCUySBOd6Lx99w 9BOIFnycICES3NRzdO575onsZvBbn/ua+WzGrDC8dEct5JBr/bP8k1OGHnzRJ1LQEgwQm5e X-Google-Smtp-Source: AGHT+IEKSth0YOjkNzztFhqLG43CjVVMHWivzo6AgNiUDJ93ptzYWCIuuyjXuBCIVUNhK8RZvvoFhkk6B8sgmxBvcaU= X-Received: by 2002:a05:622a:114:b0:4b1:103b:bb6b with SMTP id d75a77b69052e-4ed31002b4amr67716961cf.61.1761982508173; Sat, 01 Nov 2025 00:35:08 -0700 (PDT) MIME-Version: 1.0 References: <3DC589BC-A5F6-49BC-BFFC-F1FCB0FF7E95@thebuild.com> In-Reply-To: From: Kai Wagner Date: Sat, 1 Nov 2025 08:34:57 +0100 X-Gm-Features: AWmQ_bmLExoPd_ZiQc7orUe1ziARd6BZ6m4lnFLagXdigBhbeBsN9PXinb00w9c Message-ID: Subject: Re: Enquiry about TDE with PgSQL To: Chris Travers Cc: Christophe Pettus , "Clay Jackson (cjackson)" , Bruce Momjian , pgsql-general , Laurenz Albe , Ron Johnson Content-Type: multipart/alternative; boundary="0000000000008022be064283854a" X-CLOUD-SEC-AV-Sent: true X-CLOUD-SEC-AV-Info: percona,google_mail,monitor X-Gm-Spam: 0 X-Gm-Phishy: 0 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --0000000000008022be064283854a Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Sat, Nov 1, 2025 at 5:19=E2=80=AFAM Chris Travers wrote: > I maintain that the way forward is to get TDE in core. Perhaps someone > could pick up the previous patches and try to push them again > I wholeheartedly agree, as in this thread we are trying to do the same thing again, that has already happened all they years before. We lose ourselves in technical reasons, wondering why this makes no sense and how it could be achieved differently, but we forget that we live in a vacuum and bubble here. The auditor, most of the time (as I've seen many times), has no knowledge of these technical aspects. It's a box to check, with a simple 'yes' or 'no'. They don't even wanna hear any "but this also satisfies it, as this isn't clearly stated and worded in the standard". This doesn't get us anywhere anymore; they will not put their checkbox there if there is no simple answer to it. @Bruce Momjian I totally understand your frustration from previous times and also your point of view, that's absolutely valid, no doubt about that. The time has changed over the course of the last 5+ years, and maybe it is time to reconsider. Just because it didn't succeed last time doesn't mean we have to end up in the same spot this time. We discussed it at length, and I am committed to supporting and making happen what's necessary to get TDE fully functional with postgres directly. The way of the implementation is a different question. Who from the former times, or maybe even now, being interested in the topic, would be open for a TDE group, to technically discuss options, possibilities etc. that we can POC on and share for further feedback?! > > Best Wishes, > Chris Travers > > > On Sat, Nov 1, 2025, 8:36=E2=80=AFAM Christophe Pettus = wrote: > >> On Oct 31, 2025, at 17:24, Clay Jackson (cjackson) < >> Clay.Jackson@quest.com> wrote: >> > >> > I can't disagree - but the question them becomes, as Markus and other >> have pointed out; would that allow a customer/user to check the >> "Encryption" box for PCI or any other "compliance review" >> >> The answer is: it depends (doesn't it always?). Doing secure >> column-level encryption meets the PCI standard, and a competent PCI audi= tor >> will know that. However, TDE has this cache as being "the way one does >> it," and if the organization is that way, it's hard to move them off of = it. >> >> As a sign of how the PCI world views TDE, at least one of the major >> credit card associations does not use it, and they have literally >> everyone's credit card number, with expiration date and CVV, sitting on >> their disks. >> >> --0000000000008022be064283854a Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable


On Sat, Nov 1, = 2025 at 5:19=E2=80=AFAM Chris Travers <chris.travers@gmail.com> wrote:
I maintain that the= way forward is to get TDE in core.=C2=A0 Perhaps someone could pick up the= previous patches and try to push them again
I= wholeheartedly=C2=A0agree, as in this thread we are trying to do the same = thing again, that has already happened=C2=A0all they years before. We lose = ourselves in technical reasons, wondering why this makes no sense and how i= t could be achieved differently, but we forget that we live in a vacuum and= bubble here.=C2=A0 The auditor, most of the time (as I've seen many ti= mes), has no knowledge of these technical aspects. It's a box to check,= with a simple 'yes' or 'no'. They don't even wanna hea= r any "but this also satisfies it, as this isn't clearly stated an= d worded in the standard". This doesn't get us anywhere anymore; t= hey will not put their checkbox there if there is no simple answer to it.

@Bruce Momjian=C2=A0I= totally understand your frustration from previous times and also your poin= t of view, that's absolutely valid, no doubt about that. The time has c= hanged over the course of the last 5+ years, and maybe it is time to recons= ider. Just because it didn't succeed last time doesn't mean we have= to end up in the same spot this time. We discussed it at length, and I am = committed to supporting and making happen what's necessary to get TDE f= ully functional with postgres directly. The way of the implementation is a = different question. Who from the former times, or maybe even now, being int= erested in the topic, would be open for a TDE group, to technically discuss= options, possibilities etc. that we can POC on and share for further feedb= ack?!



Best Wishes,
Chris Travers


On Sat, Nov 1, 2025, 8:36=E2=80=AFAM Christophe Pettus <xof@thebuild.com> wrote:
<= /div>
On Oct 31, 2025, at = 17:24, Clay Jackson (cjackson) <Clay.Jackson@quest.com> wrote= :
>
> I can't disagree - but the question them becomes, as Markus and ot= her have pointed out; would that allow a customer/user to check the "E= ncryption" box for PCI or any other "compliance review"

The answer is: it depends (doesn't it always?).=C2=A0 Doing secure colu= mn-level encryption meets the PCI standard, and a competent PCI auditor wil= l know that.=C2=A0 However, TDE has this cache as being "the way one d= oes it," and if the organization is that way, it's hard to move th= em off of it.

As a sign of how the PCI world views TDE, at least one of the major credit = card associations does not use it, and they have literally everyone's c= redit card number, with expiration date and CVV, sitting on their disks.
--0000000000008022be064283854a--