pg_vault_tde v1.7.1 : Transparent Data Encryption for PostgreSQL 17 and 18

From: Miriade Srl via PostgreSQL Announce <announce-noreply(at)postgresql(dot)org>
To: PostgreSQL Announce <pgsql-announce(at)lists(dot)postgresql(dot)org>
Subject: pg_vault_tde v1.7.1 : Transparent Data Encryption for PostgreSQL 17 and 18
Date: 2026-09-10 14:16:09
Message-ID: 178904976945.2258529.13580985702706001175@wrigleys.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-announce

`pg_vault_tde` provides Transparent Data Encryption for PostgreSQL 17 and 18. A table access method, `encrypted_heap`, encrypts every tuple with AES-256-GCM before it reaches the storage manager and decrypts it after it leaves, so applications require no changes.

Keys are held outside the database: HashiCorp Vault or OpenBao through the Transit engine, a PKCS#11 token or HSM, or a local PKCS#12 wallet. Data encryption keys are per table and can be rotated online. Requirements are PostgreSQL 17 or 18, OpenSSL 3.x, and the library listed in `shared_preload_libraries`.

The current release is 1.7.1. It corrects the AAD derivation for out-of-line TOAST values, with the consequence that **TOAST data written by 1.7.0 or earlier does not authenticate under 1.7.1**: affected tables must be exported before the new binary is installed. The procedure is documented in the [README](https://github.com/labmiriade/pg_vault_tde).

`pg_vault_tde` is released under the PostgreSQL licence. Sources, documentation and binary `.deb` and `.rpm` packages are on [GitHub](https://github.com/labmiriade/pg_vault_tde); the distribution is on [PGXN](https://pgxn.org/dist/pg_vault_tde/).

Browse pgsql-announce by date

  From Date Subject
Next Message Swiss PostgreSQL Users Group via PostgreSQL Announce 2026-09-11 12:24:12 CERN PGDay 2027: Announcement and CfP
Previous Message Dalibo via PostgreSQL Announce 2026-09-10 14:13:05 PostgreSQL Migrator 1.0 : first stable release