LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 09-30-2009, 08:36 AM   #1
tqz
Member
 
Registered: Jan 2008
Posts: 67

Rep: Reputation: 15
Bacula and encryption


Hello all

I am using bacula to backup my the contents of my server onto a tape and using data encyrption.

Previously, the encryption was working fine and you wouldnt be able to restore files from the tape without the decryption keys. However, I stopped encrypting the tapes for a while whilst doing some testing and now when encrypting the data (although the backup says 'Storage Encryption: yes' in the log), I can restore the files from the tape even though i delete the keypair and master key from where they should be located on the server.

Any ideas what I may be doing wrong or forgotten to do???

Many thanks in advance.


t.
 
Old 09-30-2009, 04:54 PM   #2
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
I would imagine they were never actually getting encrypted to begin with according to the documentation.

Can you post your configuration where you were specifying encryption with the FileDaemon?

And yes, you cannot recover encrypted files without the keys. So if you are recovering data from a time period you thought was being encrypted, I'd imagine they weren't getting encrypted.
 
Old 10-01-2009, 04:11 AM   #3
tqz
Member
 
Registered: Jan 2008
Posts: 67

Original Poster
Rep: Reputation: 15
Hi trickykid and thanks for your response.

In the bacula-fd.conf files I have the following lines for data encryption:-

#added for data encryption
PKI Signatures = Yes
PKI Encryption = Yes
PKI Keypair ="/home/private/ppkey.pem" #Public and private key
PKI Master Key ="/home/private/master.cert" #Only public key


What I found:-

If you comment out the above lines in the config file, restart bacula, delete the keys from the location specified above and restore "encrypted" tape (backed up when encryption was enabled) everything gets restored (when it shouldnt).

If I have the above lines uncommented and delete the keys from the location specified above then the file daemon wont obviously start.Delete/move the keys after restarting bacula files get restored!

Previously however, when I changed the keys/deleted the keys and tried to restore from an encrypted tape all was working fine i.e. I would get a error complaining about the decryption keys and wouldnt be able to restore the contents of the tape.

So I am confused as to what is going on. In the log it does say 'Storage Encryption: yes' for the backup job that I am trying to restore...
 
Old 10-01-2009, 11:11 AM   #4
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Odd indeed. I haven't messed with encryption that much myself but perhaps you should post this to the bacula mailing lists (which is quite active) on your findings. Perhaps someone there could enlighten on what's possibly going on and how you're able to restore encrypted backups without the keys in place or specified.
 
Old 10-02-2009, 04:12 AM   #5
tqz
Member
 
Registered: Jan 2008
Posts: 67

Original Poster
Rep: Reputation: 15
Hi trickykid yes its quite odd! I have just posted on the bacula mailing lists and once I have resolved this problemo will update this thread! Thanks for your help!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Backup using bacula rosv Linux - Server 13 10-29-2011 08:51 AM
Bacula bug???? tqz Linux - Newbie 1 08-07-2009 07:59 AM
Encryption/decryption bacula testing tqz Linux - General 1 02-02-2009 03:54 AM
Linux password encryption and data encryption Tux-Slack Programming 4 06-20-2007 06:46 AM
Mandrake 9.0 Wireless Works without encryption.. does not with encryption topcat Linux - Wireless Networking 3 05-04-2003 08:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 10:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration