See below for configuring the EDB PostgreSQL server for encryption.

Logging in to the EDB PostgreSQL server

Log in to the EDB PostgreSQL server as the EDB user: 

su - enterprisedb

Exporting the wrapping variables 

Export the variables needed to wrap and unwrap the EDB Data Encryption Key.
export PGDATAKEYWRAPCMD='/opt/hcs/bin/htkey encrypt --config-file <config-file-path> --key-name <key-name> --out-file "%p"'
export PGDATAKEYUNWRAPCMD='/opt/hcs/bin/htkey decrypt --config-file <config-file-path> --in-file "%p"'
Where: 
  • <config-file-path> is the absolute path of the Access Token file previously created.

  • <key-name> is the CloudKey previously created.

Enabling encryption

Enable database encryption.

/usr/lib/edb-as/16/bin/initdb -D <data> --data-encryption

Where <data> is the path of an empty data directory. For example:

/var/lib/edb-as/16/main

The command may fail with the following error: 

sh: 1: /opt/hcs/bin/htkey: not found

If this happens, you will need to convert the htkey file to UNIX format using the following command: 

dos2unix /opt/hcs/bin/htkey

Starting the server

Run the following command to start the server.

/usr/lib/edb-as/16/bin/pg_ctl start -D /var/lib/edb-as/16/main

Verifying encryption

Verify that encryption is enabled. 

select data_encryption_version from pg_control_init();