-
- Influencer
- Posts: 10
- Liked: 8 times
- Joined: Jun 23, 2016 5:48 pm
- Full Name: Grant Emsley
- Contact:
Verify existing passwords for encryption
It would be really, really nice if in the Manage Credentials screen, there was a "Verify" password right under Edit. That button would prompt you to enter the password and verify that it matches. Right now the only way I've found to make sure I have the correct password is to try to open a backup file with the extract tool. That only works for some backup methods though - I haven't found a way to make sure the password is correct for object storage or NAS backups.
Having all our backups encrypted is great for security - but it would be really nice to make sure the passwords we think are used to decrypt them are correct! In a disaster where our veeam server (and enterprise manager if using that) are gone, we're really going to need those passwords, and I worry someone might have screwed up entering the password into veeam or our password manager, and that the two might not match. Being able to easily test that once in awhile would give me some extra peace of mind.
Having all our backups encrypted is great for security - but it would be really nice to make sure the passwords we think are used to decrypt them are correct! In a disaster where our veeam server (and enterprise manager if using that) are gone, we're really going to need those passwords, and I worry someone might have screwed up entering the password into veeam or our password manager, and that the two might not match. Being able to easily test that once in awhile would give me some extra peace of mind.
-
- Product Manager
- Posts: 2581
- Liked: 708 times
- Joined: Jun 14, 2013 9:30 am
- Full Name: Egor Yakovlev
- Location: Prague, Czech Republic
- Contact:
Re: Verify existing passwords for encryption
Hi Grant.
Noted as feature request for future versions.
However:
- The eye icon does reveal real entered password when it's being created in the first place, so chance for mistake diminished.
- Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
- Last but not least, Veeam Enterprise Manager can export decryption keyset in case you have lost an original passphrase. That must be configured in advance.
Thanks!
Noted as feature request for future versions.
However:
- The eye icon does reveal real entered password when it's being created in the first place, so chance for mistake diminished.
- Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
- Last but not least, Veeam Enterprise Manager can export decryption keyset in case you have lost an original passphrase. That must be configured in advance.
Thanks!
-
- Influencer
- Posts: 10
- Liked: 8 times
- Joined: Jun 23, 2016 5:48 pm
- Full Name: Grant Emsley
- Contact:
Re: Verify existing passwords for encryption
Thanks!
> Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
Nope, because I can test it BEFORE I need to do a disaster recovery. If I find out the password is wrong now, we can either figure out the correct password and update our password manager, or set it to the correct password and start new backups right away. If i'm verifying it after the disaster has happened, well them I guess I'm in trouble, but that's on me.
> Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
Nope, because I can test it BEFORE I need to do a disaster recovery. If I find out the password is wrong now, we can either figure out the correct password and update our password manager, or set it to the correct password and start new backups right away. If i'm verifying it after the disaster has happened, well them I guess I'm in trouble, but that's on me.
-
- Veeam Software
- Posts: 23
- Liked: 4 times
- Joined: May 14, 2018 7:59 pm
- Full Name: Lee Rivas
- Contact:
Re: Verify existing passwords for encryption
+1 for encrytion verification
-
- Novice
- Posts: 8
- Liked: 1 time
- Joined: Mar 30, 2023 5:02 pm
- Full Name: Abbie Utley
- Contact:
Re: Verify existing passwords for encryption
+1 for encryption verification
-
- Veeam Legend
- Posts: 409
- Liked: 232 times
- Joined: Apr 11, 2023 1:18 pm
- Full Name: Tyler Jurgens
- Contact:
Re: Verify existing passwords for encryption
+1 for encryption verification. Would be really nice to see this feature - I always tell all Veeam users to encrypt their backups with a stern warning not to forget that password. This would give a great means of verification. Another scenario is when you take over a Veeam environment from a previous employee. Yes, you should be doing restore tests, but this would be a quick and easy method to at least ensure you have the right encryption key before going down the path to fully testing backups.
Tyler Jurgens
Veeam Legend x3 | vExpert ** | VMCE | VCP 2020 | Tanzu Vanguard | VUG Canada Leader | VMUG Calgary Leader
Blog: https://explosive.cloud
Twitter: @Tyler_Jurgens BlueSky: @explosive.cloud
Veeam Legend x3 | vExpert ** | VMCE | VCP 2020 | Tanzu Vanguard | VUG Canada Leader | VMUG Calgary Leader
Blog: https://explosive.cloud
Twitter: @Tyler_Jurgens BlueSky: @explosive.cloud
-
- Service Provider
- Posts: 20
- Liked: 5 times
- Joined: Jul 02, 2019 8:06 pm
- Full Name: Michael anderson
- Contact:
Re: Verify existing passwords for encryption
+1 for Encryption Verification - kind of a bummer this hasn't been implemented in any shape yet. I have lots of customers ask me about this and the best I have to offer has already been suggested in this thread, or I have them mount their configuration restore.
Agreed that it's not too late, if you're using the Verify option then you're likely using it in advance, there's still time to change the key and run new backups.
Not everyone wants to run enterprise manager, and sometimes being able to export the decryption keyset is actually viewed as a downside. What if you don't want any way to break the key?
The eye icon has a limited character limit it will expose. If your key is long enough you can't see it all.Egor Yakovlev wrote: ↑Jul 02, 2021 4:11 pm However:
- The eye icon does reveal real entered password when it's being created in the first place, so chance for mistake diminished.
- Say we add "Verify". You have your encrypted backups with the key of choice. You click "Verify" and it says "Wrong!". Kind of late, huh?
- Last but not least, Veeam Enterprise Manager can export decryption keyset in case you have lost an original passphrase. That must be configured in advance.
Agreed that it's not too late, if you're using the Verify option then you're likely using it in advance, there's still time to change the key and run new backups.
Not everyone wants to run enterprise manager, and sometimes being able to export the decryption keyset is actually viewed as a downside. What if you don't want any way to break the key?
-
- Service Provider
- Posts: 171
- Liked: 26 times
- Joined: Feb 13, 2017 2:56 pm
- Full Name: Henrik Grevelund
- Contact:
Re: Verify existing passwords for encryption
+1 for encryption verification
When writing backup to S3, also sending the configuration backup that way, it's pretty difficult to verify that no one changed it.
When writing backup to S3, also sending the configuration backup that way, it's pretty difficult to verify that no one changed it.
Have nice day,
Henrik
Henrik
Who is online
Users browsing this forum: Google [Bot], mattskalecki, restore-helper, sdv, Semrush [Bot] and 81 guests