| From: | Miriade Srl via PostgreSQL Announce <announce-noreply(at)postgresql(dot)org> |
|---|---|
| To: | PostgreSQL Announce <pgsql-announce(at)lists(dot)postgresql(dot)org> |
| Subject: | pg_vault_tde v1.7.1 : Transparent Data Encryption for PostgreSQL 17 and 18 |
| Date: | 2026-09-10 14:16:09 |
| Message-ID: | 178904976945.2258529.13580985702706001175@wrigleys.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-announce |
`pg_vault_tde` provides Transparent Data Encryption for PostgreSQL 17 and 18. A table access method, `encrypted_heap`, encrypts every tuple with AES-256-GCM before it reaches the storage manager and decrypts it after it leaves, so applications require no changes.
Keys are held outside the database: HashiCorp Vault or OpenBao through the Transit engine, a PKCS#11 token or HSM, or a local PKCS#12 wallet. Data encryption keys are per table and can be rotated online. Requirements are PostgreSQL 17 or 18, OpenSSL 3.x, and the library listed in `shared_preload_libraries`.
The current release is 1.7.1. It corrects the AAD derivation for out-of-line TOAST values, with the consequence that **TOAST data written by 1.7.0 or earlier does not authenticate under 1.7.1**: affected tables must be exported before the new binary is installed. The procedure is documented in the [README](https://github.com/labmiriade/pg_vault_tde).
`pg_vault_tde` is released under the PostgreSQL licence. Sources, documentation and binary `.deb` and `.rpm` packages are on [GitHub](https://github.com/labmiriade/pg_vault_tde); the distribution is on [PGXN](https://pgxn.org/dist/pg_vault_tde/).
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Swiss PostgreSQL Users Group via PostgreSQL Announce | 2026-09-11 12:24:12 | CERN PGDay 2027: Announcement and CfP |
| Previous Message | Dalibo via PostgreSQL Announce | 2026-09-10 14:13:05 | PostgreSQL Migrator 1.0 : first stable release |