Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vEzZ7-005hvk-5i for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 00:33:56 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1vEzZ5-002Fyy-2g for pgsql-general@arkaria.postgresql.org; Sat, 01 Nov 2025 00:33:54 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vEzZ4-002Fyp-Nl for pgsql-general@lists.postgresql.org; Sat, 01 Nov 2025 00:33:53 +0000 Received: from momjian.us ([72.94.173.45]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1vEzZ1-005KmR-15 for pgsql-general@postgresql.org; Sat, 01 Nov 2025 00:33:53 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=momjian.us; s=2025010100; h=In-Reply-To:Content-Type:MIME-Version:References:Message-ID: Subject:Cc:To:From:Date:Sender:Reply-To:Content-Transfer-Encoding:Content-ID: Content-Description; bh=DcGZlI3zDuUopNRFpO8mBMRrBMHrTyhM3TdwxaxF8ok=; b=nApCY 0KMqUAHubOAnoOOH3lfxLKWZ1BTiWu98eNgGShWbYSZApTiT98HmOFIIPS/LGdxI47J7O7ODg/+xv 6+lcvUwan+pdvO32AxT9+JKQcvx/S0xDH4oEzmrlNQ3l/lFD1l9hq9IYI5PRTjYc3pLTl9wx7DCAQ ZWV3x4hAGx1H+CNGVJgfqXBWSZd0V5tGsOJiAslVRwl195lJ0pemfN5AP3/e+fvP8MsHyJ5jxtbYm yMHd2WB6jCYcVp+tfK4NmEG9Mf22AyTEi1I/DbSvDPjuCP5T45bAcgZCrc3BBqy/OmoXQNeDfuqI6 vFpvNKQtow/bcbQ6gzsO0Nds+HG4A==; Received: from bruce by momjian.us with local (Exim 4.98.2) (envelope-from ) id 1vEzYz-0000000Agm1-2Wn6; Fri, 31 Oct 2025 20:33:49 -0400 Date: Fri, 31 Oct 2025 20:33:49 -0400 From: Bruce Momjian To: "Clay Jackson (cjackson)" Cc: Christophe Pettus , pgsql-general , Kai Wagner , Laurenz Albe , Ron Johnson Subject: Re: Enquiry about TDE with PgSQL Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Sat, Nov 1, 2025 at 12:24:25AM +0000, Clay Jackson (cjackson) wrote: > I can't disagree - but the question them becomes, as Markus and > other have pointed out; would that allow a customer/user to check the > "Encryption" box for PCI or any other "compliance review" I think so. It says storage encryption is insufficient, but it doesn't say client-side column-level encryption is insufficient. -- Bruce Momjian https://momjian.us EDB https://enterprisedb.com Do not let urgent matters crowd out time for investment in the future.