Comprehensive data protection for all workloads
Post Reply
grantemsley
Influencer
Posts: 10
Liked: 8 times
Joined: Jun 23, 2016 5:48 pm
Full Name: Grant Emsley
Contact:

Verify existing passwords for encryption

Post by grantemsley » 1 person likes this post

It would be really, really nice if in the Manage Credentials screen, there was a "Verify" password right under Edit. That button would prompt you to enter the password and verify that it matches. Right now the only way I've found to make sure I have the correct password is to try to open a backup file with the extract tool. That only works for some backup methods though - I haven't found a way to make sure the password is correct for object storage or NAS backups.

Having all our backups encrypted is great for security - but it would be really nice to make sure the passwords we think are used to decrypt them are correct! In a disaster where our veeam server (and enterprise manager if using that) are gone, we're really going to need those passwords, and I worry someone might have screwed up entering the password into veeam or our password manager, and that the two might not match. Being able to easily test that once in awhile would give me some extra peace of mind.
Egor Yakovlev
Product Manager
Posts: 2581
Liked: 708 times
Joined: Jun 14, 2013 9:30 am
Full Name: Egor Yakovlev
Location: Prague, Czech Republic
Contact:

Re: Verify existing passwords for encryption

Post by Egor Yakovlev »

Hi Grant.

Noted as feature request for future versions.

However:
- The eye icon does reveal real entered password when it's being created in the first place, so chance for mistake diminished.
- Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
- Last but not least, Veeam Enterprise Manager can export decryption keyset in case you have lost an original passphrase. That must be configured in advance.

Thanks!
grantemsley
Influencer
Posts: 10
Liked: 8 times
Joined: Jun 23, 2016 5:48 pm
Full Name: Grant Emsley
Contact:

Re: Verify existing passwords for encryption

Post by grantemsley » 3 people like this post

Thanks!

> Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?

Nope, because I can test it BEFORE I need to do a disaster recovery. If I find out the password is wrong now, we can either figure out the correct password and update our password manager, or set it to the correct password and start new backups right away. If i'm verifying it after the disaster has happened, well them I guess I'm in trouble, but that's on me.
lee.rivas
Veeam Software
Posts: 23
Liked: 4 times
Joined: May 14, 2018 7:59 pm
Full Name: Lee Rivas
Contact:

Re: Verify existing passwords for encryption

Post by lee.rivas »

+1 for encrytion verification
utleyab
Novice
Posts: 8
Liked: 1 time
Joined: Mar 30, 2023 5:02 pm
Full Name: Abbie Utley
Contact:

Re: Verify existing passwords for encryption

Post by utleyab »

+1 for encryption verification
tyler.jurgens
Veeam Legend
Posts: 409
Liked: 232 times
Joined: Apr 11, 2023 1:18 pm
Full Name: Tyler Jurgens
Contact:

Re: Verify existing passwords for encryption

Post by tyler.jurgens »

+1 for encryption verification. Would be really nice to see this feature - I always tell all Veeam users to encrypt their backups with a stern warning not to forget that password. This would give a great means of verification. Another scenario is when you take over a Veeam environment from a previous employee. Yes, you should be doing restore tests, but this would be a quick and easy method to at least ensure you have the right encryption key before going down the path to fully testing backups.
Tyler Jurgens
Veeam Legend x3 | vExpert ** | VMCE | VCP 2020 | Tanzu Vanguard | VUG Canada Leader | VMUG Calgary Leader
Blog: https://explosive.cloud
Twitter: @Tyler_Jurgens BlueSky: @explosive.cloud
mike.anderson
Service Provider
Posts: 20
Liked: 5 times
Joined: Jul 02, 2019 8:06 pm
Full Name: Michael anderson
Contact:

Re: Verify existing passwords for encryption

Post by mike.anderson »

+1 for Encryption Verification - kind of a bummer this hasn't been implemented in any shape yet. I have lots of customers ask me about this and the best I have to offer has already been suggested in this thread, or I have them mount their configuration restore.
Egor Yakovlev wrote: Jul 02, 2021 4:11 pm However:
- The eye icon does reveal real entered password when it's being created in the first place, so chance for mistake diminished.
- Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
- Last but not least, Veeam Enterprise Manager can export decryption keyset in case you have lost an original passphrase. That must be configured in advance.
The eye icon has a limited character limit it will expose. If your key is long enough you can't see it all.

Agreed that it's not too late, if you're using the Verify option then you're likely using it in advance, there's still time to change the key and run new backups.

Not everyone wants to run enterprise manager, and sometimes being able to export the decryption keyset is actually viewed as a downside. What if you don't want any way to break the key?
Henrik.Grevelund
Service Provider
Posts: 171
Liked: 26 times
Joined: Feb 13, 2017 2:56 pm
Full Name: Henrik Grevelund
Contact:

Re: Verify existing passwords for encryption

Post by Henrik.Grevelund »

+1 for encryption verification

When writing backup to S3, also sending the configuration backup that way, it's pretty difficult to verify that no one changed it.
Have nice day,
Henrik
Post Reply

Who is online

Users browsing this forum: Google [Bot], mattskalecki, restore-helper, sdv, Semrush [Bot] and 81 guests