# Percona Postgresql-17 pg\_tde configuration abd setup

**URL:** <https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006>\
**Category:** Percona Server for MySQL 8.0\
**Created:** [January 7, 2026, 11:57pm UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006 "2026-01-07T23:57:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnathan](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Johnathan](https://forums.percona.com/u/Johnathan)\
**Post date:** [January 7, 2026, 11:57pm UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006/1 "2026-01-07T23:57:16Z")

</div>

I want to taste pg\_tde and need help configuring the global and masterkeys. I will later immplement a proper key management later

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [January 8, 2026, 2:41am UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006/2 "2026-01-08T02:41:32Z")

</div>

Hi @Johnathan,  
For testing purposes, you can use a keyring.

> **[Percona Transparent Data Encryption for PostgreSQL - Keyring file configuration](https://docs.percona.com/pg-tde/global-key-provider-configuration/keyring.html)**
>
> This setup is intended for development and stores the keys, unencrypted, in a data file you specify.

---

<div class="post-metadata">

**Author:** ![Johnathan](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Johnathan](https://forums.percona.com/u/Johnathan)\
**Post date:** [January 8, 2026, 5:33am UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006/3 "2026-01-08T05:33:42Z")

</div>

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Johnathan](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Johnathan](https://forums.percona.com/u/Johnathan)\
**Post date:** [January 8, 2026, 9:52pm UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006/4 "2026-01-08T21:52:13Z")

</div>

Do we need different encryption keys for Wal files and different keys for databases ?

---

<div class="post-metadata">

**Author:** ![Nam\_Dinh\_Phuong](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/nam_dinh_phuong/32/14586_2.png) [@Nam\_Dinh\_Phuong](https://forums.percona.com/u/Nam_Dinh_Phuong)\
**Post date:** [May 15, 2026, 5:44am UTC](https://forums.percona.com/t/percona-postgresql-17-pg-tde-configuration-abd-setup/40006/5 "2026-05-15T05:44:18Z")

</div>

Hi Johna,

For testing, you don’t need to manually create separate encryption keys for each WAL file or each database.

For WAL encryption, you can either use the server’s default principal key, or configure a dedicated server/principal key specifically for WAL. If WAL encryption is enabled, it applies globally to WAL writes for the PostgreSQL cluster, not per database.

So for initial testing with keyring, a simple setup is:

1. configure the global key provider

2. create/set a default principal key

3. optionally enable WAL encryption

Later, when you implement proper KMS/key management, you can move to a production-grade key provider and define whether you need separate keys per database or a dedicated WAL key based on your security requirements.

You can follow the document: [4. Configure WAL encryption - Percona Transparent Data Encryption for PostgreSQL](https://docs.percona.com/pg-tde/wal-encryption.html#option-2-configure-a-dedicated-server-principal-key-for-wal)
