# After enabling TDE and creating encrypted table still unencrypted data visible in DB file

**URL:** <https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834>\
**Category:** PG\_TDE – Transparent Data Encryption (TDE)\
**Created:** [July 25, 2025, 12:55pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834 "2025-07-25T12:55:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fborden](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@fborden](https://forums.percona.com/u/fborden)\
**Post date:** [July 25, 2025, 12:55pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834/1 "2025-07-25T12:55:40Z")

</div>

Hello all,

## I have enabled PG\_TDE and stored the key in Oracle Key Vault. Next I created a table ENC\_TEST with access method TDE\_HEAP. test=# SELECT pg\_tde\_is\_encrypted(‘enc\_test’) encrypted; encrypted

t  
(1 row)

This shows the table is supposed to be encrypted.

When I go to the pg\_wal directory and run strings on the datafile after an insert like this:  
test=# insert into enc\_test values (‘john doe’);

INSERT 0 1

[postgres@percona pg\_wal]$ strings 000000010000000000000001 |grep “john doe”

john doe

What is wrong?

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [July 25, 2025, 3:17pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834/2 "2025-07-25T15:17:00Z")

</div>

Did you enable WAL encryption? [4. Configure WAL Encryption (tech preview) - Percona Transparent Data Encryption for PostgreSQL](https://docs.percona.com/pg-tde/wal-encryption.html)  
Table encryption is different from WAL encryption.

Table encryption:

```auto
postgres=# CREATE TABLE test_encrypted (id SERIAL, name varchar(20)) USING tde_heap;
CREATE TABLE
postgres=#
postgres=# INSERT INTO test_encrypted (name) VALUES ('Alice');
INSERT 0 1
postgres=# INSERT INTO test_encrypted (name) VALUES ('Bob');
INSERT 0 1
postgres=# INSERT INTO test_encrypted (name) VALUES ('Charlie');
INSERT 0 1
postgres=# SELECT * FROM test_encrypted;
 id | name
----+---------
  1 | Alice
  2 | Bob
  3 | Charlie
(3 rows)

postgres=# SELECT pg_relation_filepath('test_encrypted');
 pg_relation_filepath
----------------------
 base/5/16433

bash-5.1$ cd /data/db/base/5/
bash-5.1$ ls -la 16433
-rw------- 1 postgres root 8192 Jul 25 15:07 16433
bash-5.1$ strings 16433
$zc6
c{,w
.r8[G
}#$m
...
```

---

<div class="post-metadata">

**Author:** ![fborden](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@fborden](https://forums.percona.com/u/fborden)\
**Post date:** [July 25, 2025, 3:46pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834/3 "2025-07-25T15:46:03Z")

</div>

Thank you Matthew,

I will look at this after my holidays.

Regards,  
Frank

---

<div class="post-metadata">

**Author:** ![mohit\_joshi](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@mohit\_joshi](https://forums.percona.com/u/mohit_joshi)\
**Post date:** [July 25, 2025, 3:51pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834/4 "2025-07-25T15:51:32Z")

</div>

Hi @fborden - To enable WAL encryption, you need to perform below steps. Assuming you will be using OKV, find the steps below

Step 1: Add a global key provider  
SELECT pg\_tde\_add\_global\_key\_provider\_kmip(  
‘OKV’,  
‘10.0.0.107’,  
5696,  
‘/var/lib/pgsql/pg\_okv/ssl/cert.pem’,  
‘/var/lib/pgsql/pg\_okv/ssl/key.pem’,  
‘/var/lib/pgsql/pg\_okv/ssl/CA.pem’  
);

Step 2: Create a Key using the database key provider created in Step 1  
SELECT pg\_tde\_create\_key\_using\_global\_key\_provider(  
‘percona-key’,  
‘OKV’  
);

SELECT pg\_tde\_set\_server\_key\_using\_global\_key\_provider(‘percona-key’,‘OKV’);

ALTER SYSTEM SET pg\_tde.wal\_encrypt=‘ON’

Restart PG server to enable WAL encryption.

Note: Enabling WAL encryption ensures that all writes into the WAL files are encrypted from the point WAL encryption is enabled. It does not encrypt previously written data into WAL files.
