-
matteu
- Veeam Legend
- Posts: 1039
- Liked: 171 times
- Joined: May 11, 2018 8:42 am
- Contact:
Change backup job encryption key
Hello,
I would like to change my backup encryption key because it isn't compliant with complexity.
I read the documentation here : https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
And specifically this : If you change the password or start using KMS keys for the already encrypted job, during the next job session Veeam Backup & Replication will create a new incremental backup file. The created backup file and subsequent backup files in the backup chain will be encrypted with the new password or KMS key.
That means I will need the first + second password everytime right ? Because the Full backup will always have the old KMS key ?
Or does after the retention passed, I will only need the new one ?
My configuration is :
Backup job : Object storage with no Active full with 31 days retention
Backup copy : on LHR repository with GFS enabled.
I guess for the backup job if I do a new active full with new password, I will not need the old password after 31 days (maybe a little more)
But for backup copy, I will need the older for all my GFS point and does the next synthetic full will use the old or new password ?
The documentation just talk about incremental backup and is not really clear about the next full...
I would like to change my backup encryption key because it isn't compliant with complexity.
I read the documentation here : https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
And specifically this : If you change the password or start using KMS keys for the already encrypted job, during the next job session Veeam Backup & Replication will create a new incremental backup file. The created backup file and subsequent backup files in the backup chain will be encrypted with the new password or KMS key.
That means I will need the first + second password everytime right ? Because the Full backup will always have the old KMS key ?
Or does after the retention passed, I will only need the new one ?
My configuration is :
Backup job : Object storage with no Active full with 31 days retention
Backup copy : on LHR repository with GFS enabled.
I guess for the backup job if I do a new active full with new password, I will not need the old password after 31 days (maybe a little more)
But for backup copy, I will need the older for all my GFS point and does the next synthetic full will use the old or new password ?
The documentation just talk about incremental backup and is not really clear about the next full...
-
mwhite
- Influencer
- Posts: 15
- Liked: 2 times
- Joined: Oct 03, 2017 6:27 am
- Contact:
Re: Change backup job encryption key
The first backup (full or incremental) after the password change will use the new password and encryption keys.
If you migrate the backups to a new veeam console you will need all passwords to decrypt the backups (the existing console will still have the historical keys in the DB).
See https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
If you migrate the backups to a new veeam console you will need all passwords to decrypt the backups (the existing console will still have the historical keys in the DB).
See https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
-
matteu
- Veeam Legend
- Posts: 1039
- Liked: 171 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Change backup job encryption key
Thanks for your answer.
That means if I change password encryption once a year I will have to keep all my historycal passwords ?
That means if I change password encryption once a year I will have to keep all my historycal passwords ?
-
Servior
- Influencer
- Posts: 22
- Liked: 6 times
- Joined: May 19, 2021 7:11 am
- Contact:
Re: Change backup job encryption key
It depends. If you just change the keys, without changing the VBR server, the keys are remembered as long as you don’t remove the backups from configuration.
If you remove the backups from configuration and want to re-import them, you need the keys which were used for the backups.
When you do a full regularly and retention applies, the old backups will be gone after the retention and therefore the need for the keys.
If you remove the backups from configuration and want to re-import them, you need the keys which were used for the backups.
When you do a full regularly and retention applies, the old backups will be gone after the retention and therefore the need for the keys.
-
Mildur
- Product Manager
- Posts: 12162
- Liked: 3487 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Change backup job encryption key
Hi Matteu
We have an entire chapter about "how decryption works" in Help Center.
Import VBM: Only latest KMS key or password has to be provided
Import VBK: All KMS keys or passwords used to encrypt the backup need to be provided
As long you still have the metadata file of your backup, only the latest key/password is required.
Best,
Fabian
We have an entire chapter about "how decryption works" in Help Center.
Import VBM: Only latest KMS key or password has to be provided
Import VBK: All KMS keys or passwords used to encrypt the backup need to be provided
As long you still have the metadata file of your backup, only the latest key/password is required.
Best,
Fabian
Product Management Analyst @ Veeam Software
-
matteu
- Veeam Legend
- Posts: 1039
- Liked: 171 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Change backup job encryption key
Thanks for your answer.
-
FCU_JE
- Enthusiast
- Posts: 48
- Liked: 20 times
- Joined: Oct 09, 2024 6:17 pm
- Contact:
Re: Change backup job encryption key
IMO the ""cost"" to keeping around the old encryption keys is negligible. Whereas the ""cost"" to deleting the keys and being unable to use old backups could be very high.
Keep your old passwords handy in a secret system/password database/whatever subject to its own backup system outside of Veeam, and you're good to go.
Keep your old passwords handy in a secret system/password database/whatever subject to its own backup system outside of Veeam, and you're good to go.
Who is online
Users browsing this forum: DatatoSecure, Google [Bot] and 357 guests