Re: Enquiry about TDE with PgSQL

Поиск
Список
Период
Сортировка
От Christophe Pettus
Тема Re: Enquiry about TDE with PgSQL
Дата
Msg-id 9358BA09-E2C6-4116-9E9E-3DA5D31A11DA@thebuild.com
обсуждение исходный текст
Ответ на RE: Enquiry about TDE with PgSQL  ("Clay Jackson (cjackson)" <Clay.Jackson@quest.com>)
Список pgsql-general

> On Oct 31, 2025, at 10:32, Clay Jackson (cjackson) <Clay.Jackson@quest.com> wrote:
>
> Pardo me for jumping in here - but would filesystem level encryption possibly meet your requirements?

If we're talking about PCI DSS, the answer is: Yes, but.  Filesystem-level encryption is acceptable IF the encryption
keys(or other passwords used to unlock them) are separate from the user access controls to the host that has the
encryptedvolume attached.  You have to go through a second step of decrypting the volume (or making it available for
decryptedreads) separate from just mounting it. 


В списке pgsql-general по дате отправления: