Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes15kdownloads
encryption-options.html84 linesDownload Raw Back to html
1<?xml version="1.0" encoding="UTF-8" standalone="no"?>2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>19.8. Encryption Options</title><link rel="stylesheet" type="text/css" href="stylesheet.css" /><link rev="made" href="pgsql-docs@lists.postgresql.org" /><meta name="generator" content="DocBook XSL Stylesheets Vsnapshot" /><link rel="prev" href="preventing-server-spoofing.html" title="19.7. Preventing Server Spoofing" /><link rel="next" href="ssl-tcp.html" title="19.9. Secure TCP/IP Connections with SSL" /></head><body id="docContent" class="container-fluid col-10"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="5" align="center">19.8. Encryption Options</th></tr><tr><td width="10%" align="left"><a accesskey="p" href="preventing-server-spoofing.html" title="19.7. Preventing Server Spoofing">Prev</a> </td><td width="10%" align="left"><a accesskey="u" href="runtime.html" title="Chapter 19. Server Setup and Operation">Up</a></td><th width="60%" align="center">Chapter 19. Server Setup and Operation</th><td width="10%" align="right"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="10%" align="right"> <a accesskey="n" href="ssl-tcp.html" title="19.9. Secure TCP/IP Connections with SSL">Next</a></td></tr></table><hr /></div><div class="sect1" id="ENCRYPTION-OPTIONS"><div class="titlepage"><div><div><h2 class="title" style="clear: both">19.8. Encryption Options <a href="#ENCRYPTION-OPTIONS" class="id_link">#</a></h2></div></div></div><a id="id-1.6.6.11.2" class="indexterm"></a><p>3   <span class="productname">PostgreSQL</span> offers encryption at several4   levels, and provides flexibility in protecting data from disclosure5   due to database server theft, unscrupulous administrators, and6   insecure networks. Encryption might also be required to secure7   sensitive data such as medical records or financial transactions.8  </p><div class="variablelist"><dl class="variablelist"><dt><span class="term">Password Encryption</span></dt><dd><p>9     Database user passwords are stored as hashes (determined by the setting10     <a class="xref" href="runtime-config-connection.html#GUC-PASSWORD-ENCRYPTION">password_encryption</a>), so the administrator cannot11     determine the actual password assigned to the user. If SCRAM or MD512     encryption is used for client authentication, the unencrypted password is13     never even temporarily present on the server because the client encrypts14     it before being sent across the network. SCRAM is preferred, because it15     is an Internet standard and is more secure than the PostgreSQL-specific16     MD5 authentication protocol.17    </p></dd><dt><span class="term">Encryption For Specific Columns</span></dt><dd><p>18     The <a class="xref" href="pgcrypto.html" title="F.28. pgcrypto — cryptographic functions">pgcrypto</a> module allows certain fields to be19     stored encrypted.20     This is useful if only some of the data is sensitive.21     The client supplies the decryption key and the data is decrypted22     on the server and then sent to the client.23    </p><p>24     The decrypted data and the decryption key are present on the25     server for a brief time while it is being decrypted and26     communicated between the client and server. This presents a brief27     moment where the data and keys can be intercepted by someone with28     complete access to the database server, such as the system29     administrator.30    </p></dd><dt><span class="term">Data Partition Encryption</span></dt><dd><p>31     Storage encryption can be performed at the file system level or the32     block level.  Linux file system encryption options include eCryptfs33     and EncFS, while FreeBSD uses PEFS.  Block level or full disk34     encryption options include dm-crypt + LUKS on Linux and GEOM35     modules geli and gbde on FreeBSD.  Many other operating systems36     support this functionality, including Windows.37    </p><p>38     This mechanism prevents unencrypted data from being read from the39     drives if the drives or the entire computer is stolen. This does40     not protect against attacks while the file system is mounted,41     because when mounted, the operating system provides an unencrypted42     view of the data. However, to mount the file system, you need some43     way for the encryption key to be passed to the operating system,44     and sometimes the key is stored somewhere on the host that mounts45     the disk.46    </p></dd><dt><span class="term">Encrypting Data Across A Network</span></dt><dd><p>47      SSL connections encrypt all data sent across the network: the48      password, the queries, and the data returned. The49      <code class="filename">pg_hba.conf</code> file allows administrators to specify50      which hosts can use non-encrypted connections (<code class="literal">host</code>)51      and which require SSL-encrypted connections52      (<code class="literal">hostssl</code>). Also, clients can specify that they53      connect to servers only via SSL.54     </p><p>55      GSSAPI-encrypted connections encrypt all data sent across the network,56      including queries and data returned.  (No password is sent across the57      network.)  The <code class="filename">pg_hba.conf</code> file allows58      administrators to specify which hosts can use non-encrypted connections59      (<code class="literal">host</code>) and which require GSSAPI-encrypted connections60      (<code class="literal">hostgssenc</code>).  Also, clients can specify that they61      connect to servers only on GSSAPI-encrypted connections62      (<code class="literal">gssencmode=require</code>).63     </p><p>64      <span class="application">Stunnel</span> or65      <span class="application">SSH</span> can also be used to encrypt66      transmissions.67     </p></dd><dt><span class="term">SSL Host Authentication</span></dt><dd><p>68     It is possible for both the client and server to provide SSL69     certificates to each other. It takes some extra configuration70     on each side, but this provides stronger verification of identity71     than the mere use of passwords. It prevents a computer from72     pretending to be the server just long enough to read the password73     sent by the client. It also helps prevent <span class="quote">“<span class="quote">man in the middle</span>”</span>74     attacks where a computer between the client and server pretends to75     be the server and reads and passes all data between the client and76     server.77    </p></dd><dt><span class="term">Client-Side Encryption</span></dt><dd><p>78     If the system administrator for the server's machine cannot be trusted,79     it is necessary80     for the client to encrypt the data; this way, unencrypted data81     never appears on the database server. Data is encrypted on the82     client before being sent to the server, and database results have83     to be decrypted on the client before being used.84    </p></dd></dl></div></div><div class="navfooter"><hr /><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="preventing-server-spoofing.html" title="19.7. Preventing Server Spoofing">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="runtime.html" title="Chapter 19. Server Setup and Operation">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="ssl-tcp.html" title="19.9. Secure TCP/IP Connections with SSL">Next</a></td></tr><tr><td width="40%" align="left" valign="top">19.7. Preventing Server Spoofing </td><td width="20%" align="center"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="40%" align="right" valign="top"> 19.9. Secure TCP/IP Connections with SSL</td></tr></table></div></body></html>
codekingpro/portable-devtools · Team Ai