Solved

Testing encryption key of a backup


Userlevel 3

I’m missing something simple here I thnk…

all of my backups are unencrypted and I want to encrypt them, I set one to do that, stored the key in VEEAM and of course offsite too, but how do I know it’s working? 

I tried a guest file restore from that backup, picked a file, it restored fine, but nowhere did VEEAM asked me to provide the password..  I assume this is because it knows it, but that doesn’t make me feel comfortable with the process.

 

I suppose the test could be to install backup & replication on another computer and try the restore from there? a bit of work though so I’m thinking there’s an easier way

 

or am I worrying about nothing? 

icon

Best answer by dips 15 February 2023, 18:00

View original

13 comments

Userlevel 7
Badge +7

Hi,

Try removing the backup from your config and then import it back in again. You can do this by going to Backups > Disk > Right Click on the backup set and then ‘Remove from Configuration’

Rescan your repository and add it back in and you should see it appear under Backups as Encrypted where you have to enter the password. 

 

Userlevel 7
Badge +17

Yes, the encryption key is stored in the Veeam database and when the encrypted backups are stores on this server you don’t need to give the key again to restore.

 

You can do the following - with a test backup...

  • delete the backups of a backup job from configuration under Backups → Disk
  • rescan the repository the backup are on
  • The backups will appear under Backup → Disk (Encrypted)  in the Veeam Console
  • The right-click on this backup and select “Specify Password”
  • Specify the password and the backups will be shown under Disk (Imported)
  • Now you can map these backup to the backup job again and all is like in the beginning.

Edit:
😎 OK, too slow, because I had to do it myself to get the correct namings.

Userlevel 3

Thanks, that worked like a charm. Took a minute to figure out, so if anyone else is new to this and struggling… do what dips said

to rescan your repository go to backup infrastructure → backup repositories → right click on the one that you removed the backup from → rescan → let it finish

then it still won’t show up under backups → disk , but it will be under backups → disk (encrypted) → where you can right click on it and put the password in which puts it into disk (imported) list

 

I got to play around with this a bit, it seems intuitive enough, I just don’t use it enough to be comfortable with it.

 

Userlevel 3

thanks JMeixner, I stumbled through that on my own, but your description was perfect.

Userlevel 7
Badge +17

thanks JMeixner, I stumbled through that on my own, but your description was perfect.

Thank you, @PepTown 😎
and fine that you got it solved.

Userlevel 7
Badge +11

If you are using the same key on the backup configuration you can try to restore the configuration on the same Veeam Backup Server.

During the restore you will be prompt to type the key.

Userlevel 7
Badge +6

Ya’ll came up with the easy button on this.  I was thinking build a new Veeam server (I mean, being realistic here), and then importing the configuration database or at least adding the repository and scanning it into the configuration database.  Which would also work...but…..a bit more work...

Does this still work on v12, as I can only see ‘detach’?

Ta

Userlevel 7
Badge +17

Yes, this works with V12, too.

Is it the detach option?

Ta

Userlevel 7
Badge +7

Is it the detach option?

Ta

What are you trying to do? Yes, this option is in V12 as @JMeixner mentioned

Thanks

Userlevel 7
Badge +17

Try to follow my step by step procedure above in the thread (the one after the “best answer”).

Comment