Postgres & PKCS11 shenanigans

From: Andreas Heijdendael <andreas(at)heijdendael(dot)nl>
To: Pgsql-admin <pgsql-admin(at)lists(dot)postgresql(dot)org>
Subject: Postgres & PKCS11 shenanigans
Date: 2024-08-10 14:00:47
Message-ID: 082e317e-3b9f-4754-8700-4aa65c26ef04@heijdendael.nl
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Hi fellow postgres enthusiasts,

Been trying to get PKCS11 to work on my PG14 installation but to no
avail so far.
Included the [engines] section in my openssl.cnf configuration which
includes links and configuration to the HSM hardware API (Cryptoki.so).
But it will not budge when I fill in the PKCS11 URI into the Private Key
location in postgres.conf.

Has any of you got this to work? I can't find anything about it online.

Postgres version: 14

HSM: Thales Protectserver PL1500

Running on Ubuntu 22.04.

Greetings,

Andreas

Browse pgsql-admin by date

  From Date Subject
Next Message Motog Plus 2024-08-10 14:21:12 Re: Seeking Guidance on Upgrading from PostgreSQL 12 to 1
Previous Message Wasim Devale 2024-08-10 13:25:53 Re: Migration from CentOS7 to RedHat 9