Re: Database level encryption

From: "Kevin Grittner" <Kevin(dot)Grittner(at)wicourts(dot)gov>
To: "Timothy Madden" <terminatorul(at)gmail(dot)com>
Cc: "Scott Marlowe" <scott(dot)marlowe(at)gmail(dot)com>, "Joe Conway" <mail(at)joeconway(dot)com>, <pgsql-admin(at)postgresql(dot)org>
Subject: Re: Database level encryption
Date: 2010-04-05 20:46:48
Message-ID: 4BBA05E80200002500030493@gw.wicourts.gov
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Scott Marlowe <scott(dot)marlowe(at)gmail(dot)com> wrote:
> Timothy Madden <terminatorul(at)gmail(dot)com> wrote:

>> My scenario is how to protect the database if the machine is
>> stolen (it is a mini-laptop), and I would like to encrypt the
>> entire database, that is all columns of all tables, and if
>> possible everything else found in the database.
>>
>> I would like all searching and sorting functions, just like with
>> a normal database (that is, transparent encryption for the
>> application level). The password will be entered by a human in
>> order to start the application.

> Everything you've said so far points to using a mounted encrypted
> drive to store the db.

Agreed. I know you explicitly said you didn't want to use that in
your original post, but you didn't say why. I don't think you're
going to convince anyone here to put effort into something you can
configure to "just work" with so little trouble on existing systems,
without a really good argument.

-Kevin

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Anibal David Acosta 2010-04-05 20:55:23 Re: Database level encryption
Previous Message Scott Marlowe 2010-04-05 20:34:53 Re: Database level encryption