Using EDB PostgreSQL
To use TDE with your EDB PostgreSQL database, you must either create a TDE-enabled database server or migrate an existing database server to a TDE-enabled environment. You cannot enable TDE on an existing database.
Whether you create a database server from scratch or create an instance to migrate an existing database server, you have to create a TDE-enabled database by initializing a database cluster using initdb.
The data key for TDE is generated by initdb and stored in a file called pg_encryption/key.bin under the data directory. This file contains several keys that are used for different purposes at runtime. The data key is a single sequence of random bytes in the file.