Comprehensive data protection for all workloads
Post Reply
dloseke
Service Provider
Posts: 66
Liked: 29 times
Joined: Jul 13, 2018 3:33 pm
Full Name: Derek M. Loseke
Location: Omaha, NE, US
Contact:

Understanding Backup Encryption

Post by dloseke »

Okay, I had a client raise a question on backup encryption, and I wanted to make sure I understood this before I answer their questions.

Client is encrypting, or is looking to encrypt their backup data. I don't recall of the repository is encrypted or if the jobs are encrypted or none. What I know is, that if encryption is not currently enabled and encryption is turned on at the repo or the job, the next job running will be a full to start a new backup chain and the data will be encrypted.

What I'm trying to understand is if a backup is already encrypted, and the encryption password is changed, the next backup will be incremental as scheduled and will use the new encryption password, but the previous user keys are still stored in the configuration database and all backups going forward will use the new user key? One of the things I don't think I fully understand is how if you import a backup metadata file, it is able to decrypt all of the backups in the chain....does the metadata file contain encrypted session keys or something like that? In that case, I'm assuming that data is in both the metadata AND the configuration database?

I've read the Encryption Best Practices, How Encryption Works and How Decryption works articles several times and I think I understand it, but wanted to make sure. Thanks for your help.
Derek M. Loseke, Senior Systems Engineer | Veeam Legend 2022-2024 | VMSP/VMTSP | VCP6-DCV | VSP/VTSP | CCNA | https://technotesanddadjokes.com | @dloseke
HannesK
Product Manager
Posts: 14840
Liked: 3086 times
Joined: Sep 01, 2014 11:46 am
Full Name: Hannes Kasparick
Location: Austria
Contact:

Re: Understanding Backup Encryption

Post by HannesK »

Hello,
I'm focusing on the key question, whether you are able do decrypt all backups of a chain, if multiple passwords were used. The answer is "yes". You will have to provide all passwords then.

The configuration database is irrelevant. Imagine backup files like multiple zip files, each having it's own password.

Best regards,
Hannes
dloseke
Service Provider
Posts: 66
Liked: 29 times
Joined: Jul 13, 2018 3:33 pm
Full Name: Derek M. Loseke
Location: Omaha, NE, US
Contact:

Re: Understanding Backup Encryption

Post by dloseke » 1 person likes this post

Not really sure this answers my question though. My understanding is that if you import the metadata (VBM) file, you only need to provide the most recent encryption password (and multiple passwords if you import the VBK's), but I seek to understand they mechanics behind it, and really the question I need to ensure that I have the correct answer to is if the encryption password is changed, this does NOT start a new backup chain and create new fulls, correct?
Derek M. Loseke, Senior Systems Engineer | Veeam Legend 2022-2024 | VMSP/VMTSP | VCP6-DCV | VSP/VTSP | CCNA | https://technotesanddadjokes.com | @dloseke
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Understanding Backup Encryption

Post by chris.childerhose » 1 person likes this post

Changing the password should not affect the chain and run a full backup that I am aware of it just continues on. Based on this page - https://helpcenter.veeam.com/docs/backu ... ml?ver=110 - this indicates the encryption of files but nothing about fulls when changed.
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
veremin
Product Manager
Posts: 20413
Liked: 2301 times
Joined: Oct 26, 2012 3:28 pm
Full Name: Vladimir Eremin
Contact:

Re: Understanding Backup Encryption

Post by veremin »

is if the encryption password is changed, this does NOT start a new backup chain and create new fulls, correct?
No, it does not:
If you change the password for the already encrypted job, during the next job session Veeam Backup & Replication will create a new incremental backup file. The created backup file and subsequent backup files in the backup chain will be encrypted with the new password.
Thanks!
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 118 guests