Comprehensive data protection for all workloads
Post Reply
matteu
Veeam Legend
Posts: 1039
Liked: 171 times
Joined: May 11, 2018 8:42 am
Contact:

Change backup job encryption key

Post by matteu »

Hello,

I would like to change my backup encryption key because it isn't compliant with complexity.
I read the documentation here : https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
And specifically this : If you change the password or start using KMS keys for the already encrypted job, during the next job session Veeam Backup & Replication will create a new incremental backup file. The created backup file and subsequent backup files in the backup chain will be encrypted with the new password or KMS key.

That means I will need the first + second password everytime right ? Because the Full backup will always have the old KMS key ?
Or does after the retention passed, I will only need the new one ?

My configuration is :
Backup job : Object storage with no Active full with 31 days retention
Backup copy : on LHR repository with GFS enabled.

I guess for the backup job if I do a new active full with new password, I will not need the old password after 31 days (maybe a little more)
But for backup copy, I will need the older for all my GFS point and does the next synthetic full will use the old or new password ?

The documentation just talk about incremental backup and is not really clear about the next full...
mwhite
Influencer
Posts: 15
Liked: 2 times
Joined: Oct 03, 2017 6:27 am
Contact:

Re: Change backup job encryption key

Post by mwhite »

The first backup (full or incremental) after the password change will use the new password and encryption keys.
If you migrate the backups to a new veeam console you will need all passwords to decrypt the backups (the existing console will still have the historical keys in the DB).

See https://helpcenter.veeam.com/docs/vbr/u ... tml?ver=13
matteu
Veeam Legend
Posts: 1039
Liked: 171 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Change backup job encryption key

Post by matteu »

Thanks for your answer.
That means if I change password encryption once a year I will have to keep all my historycal passwords ?
Servior
Influencer
Posts: 22
Liked: 6 times
Joined: May 19, 2021 7:11 am
Contact:

Re: Change backup job encryption key

Post by Servior »

It depends. If you just change the keys, without changing the VBR server, the keys are remembered as long as you don’t remove the backups from configuration.

If you remove the backups from configuration and want to re-import them, you need the keys which were used for the backups.

When you do a full regularly and retention applies, the old backups will be gone after the retention and therefore the need for the keys.
Mildur
Product Manager
Posts: 12162
Liked: 3487 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Change backup job encryption key

Post by Mildur »

Hi Matteu

We have an entire chapter about "how decryption works" in Help Center.

Import VBM: Only latest KMS key or password has to be provided
Import VBK: All KMS keys or passwords used to encrypt the backup need to be provided

As long you still have the metadata file of your backup, only the latest key/password is required.

Best,
Fabian
Product Management Analyst @ Veeam Software
matteu
Veeam Legend
Posts: 1039
Liked: 171 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Change backup job encryption key

Post by matteu »

Thanks for your answer.
FCU_JE
Enthusiast
Posts: 48
Liked: 20 times
Joined: Oct 09, 2024 6:17 pm
Contact:

Re: Change backup job encryption key

Post by FCU_JE »

IMO the ""cost"" to keeping around the old encryption keys is negligible. Whereas the ""cost"" to deleting the keys and being unable to use old backups could be very high.

Keep your old passwords handy in a secret system/password database/whatever subject to its own backup system outside of Veeam, and you're good to go.
Post Reply

Who is online

Users browsing this forum: DatatoSecure, Google [Bot] and 357 guests