# APT installation — Ubuntu 24.04

The repository is https://apt.silico.fr/. Package **pgsilicrypto-18** targets
Ubuntu 24.04 (noble), amd64, PostgreSQL 18 and OpenSSL 3.
The SQL extension name remains `pgsilicrypto`, with API schema `sili`.
Other distributions, architectures and PostgreSQL major versions are not
claimed as compatible.

## Prepare the client

PostgreSQL 18 must be available through the client's APT sources. Ubuntu 24.04
ships PostgreSQL 16 by default. If needed, configure the
[official PostgreSQL repository](https://www.postgresql.org/download/linux/ubuntu/)
using suite `noble-pgdg`. Silico does not mirror PostgreSQL packages.

Check `dpkg --print-architecture` and `cat /etc/os-release`.
Install `ca-certificates` and `curl`, then register Silico once:

```bash
sudo install -d -m 755 /etc/apt/keyrings
sudo curl --fail --silent --show-error https://apt.silico.fr/silico-archive-keyring.asc -o /etc/apt/keyrings/silico-archive-keyring.asc
sudo chmod 644 /etc/apt/keyrings/silico-archive-keyring.asc
sudo curl --fail --silent --show-error https://apt.silico.fr/silico.sources -o /etc/apt/sources.list.d/silico.sources
sudo apt-get update
sudo apt-get install pgsilicrypto-18
```

Initial public signing key fingerprint:

```text
FB3F D4B0 436A 3B1A 0317 ED6B 0448 4DD4 2508 1AA3
```

The source uses `Signed-By` to scope trust to Silico.
Do not use `apt-key`, `trusted=yes` or disable signature verification.

## Enable in a selected database

As a PostgreSQL administrator, run in each intended database:

```sql
CREATE EXTENSION pgsilicrypto;
```

The package runs no SQL, creates no database, grants no decryption rights,
supplies no keys and does not restart PostgreSQL.
If PostgreSQL 18 is missing, APT may install it; its package lifecycle remains
under the administrator's control.

## Updates and removal

APT updates system files. Reconnect sessions using the library under administrator
control. SQL migration is separate: follow the
[1.0 to 1.1 upgrade procedure](build-install.md#upgrade-from-10-to-11).
Do not mix a 1.1 SQL catalogue with an old library still loaded in a backend.

Do not remove the package while databases or sessions need it.
`apt-get remove pgsilicrypto-18` removes files, not the SQL extension or user data.
