Skip to main content
Solved

Backup encryption key testing


bp4JC
Forum|alt.badge.img+3
  • Influencer
  • 136 comments

Is there a way to test the encryption key on backups without having to run a restore? I ran into a situation recently where the encryption password did not work on restored data. I want to setup Enterprise Manager for everyone, but in the interim, I’d like to manually test each encryption key and reset it/run a new full backup if need be.

 

Is there a way to recover an encryption key with Service Provider Console?

Best answer by Mildur

We are testing it with the Configuration Restore Wizard.

In the Restore Wizard, there is a step to put in the password. If it works, the configuration backup was correctly decrypted. I assume it will work with the backup files too.

 

If you need to test it, install vbr on a second server and import the restore points.

VSPC cannot decrypt the passwords.

 

 

PS:

Or you can use the extract utility. It will ask for the password too.

Extract Utility - User Guide for VMware vSphere (veeam.com)

 

extract.exe -dir [-vm vmname] [-host hostname] [-password backupkey] pathtobackup

Displaying List of Machines in Backup - User Guide for VMware vSphere (veeam.com)

View original
Did this topic help you find an answer to your question?

9 comments

Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • Answer
  • August 30, 2021

We are testing it with the Configuration Restore Wizard.

In the Restore Wizard, there is a step to put in the password. If it works, the configuration backup was correctly decrypted. I assume it will work with the backup files too.

 

If you need to test it, install vbr on a second server and import the restore points.

VSPC cannot decrypt the passwords.

 

 

PS:

Or you can use the extract utility. It will ask for the password too.

Extract Utility - User Guide for VMware vSphere (veeam.com)

 

extract.exe -dir [-vm vmname] [-host hostname] [-password backupkey] pathtobackup

Displaying List of Machines in Backup - User Guide for VMware vSphere (veeam.com)


bp4JC
Forum|alt.badge.img+3
  • Author
  • Influencer
  • 136 comments
  • August 30, 2021
Mildur wrote:

We are testing it with the Configuration Restore Wizard.

In the Restore Wizard, there is a step to put in the password. If it works, the configuration backup was correctly decrypted. I assume it will work with the backup files too.

 

If you need to test it, install vbr on a second server and import the restore points.

VSPC cannot decrypt the passwords.

 

 

PS:

Or you can use the extract utility. It will ask for the password too.

Extract Utility - User Guide for VMware vSphere (veeam.com)

 

extract.exe -dir [-vm vmname] [-host hostname] [-password backupkey] pathtobackup

Displaying List of Machines in Backup - User Guide for VMware vSphere (veeam.com)

Thank you!!!!


Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • August 30, 2021

Happy to help :)


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • January 25, 2023

Let me hijack this question 😉

Does anyone have any idea how to easily test encryption passwords for backups stored in object storage? So without having to setup a fresh VBR installation and import the backups there?

 


bp4JC
Forum|alt.badge.img+3
  • Author
  • Influencer
  • 136 comments
  • January 25, 2023
regnor wrote:

Let me hijack this question 😉

Does anyone have any idea how to easily test encryption passwords for backups stored in object storage? So without having to setup a fresh VBR installation and import the backups there?

 

This same solution I used might do the trick. Run the extract utility and enter the encryption password when it asks for it. That will tell you for sure if the password is working or not.


Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • January 25, 2023

You cannot run the extract utility against an object storage bucket :)

VBR is required to read the objects and make any sense of it.


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • January 25, 2023

Exactly thats the problem. If we could mount a S3/blob with the extract utility, it would be easy 😅


HunterLAFR
Forum|alt.badge.img+8
  • Veeam Legend
  • 422 comments
  • January 27, 2023

crazy idea here, what about sure backup?

in V12, as we will be allowed to run a backup directly to S3, would be possible to spin a SureBackup also from an S3 location?

and to read that machine, it will need to decrypt the backup to spin up the VM.

right? or am I in Friday mode and I need a beer? 

🤣

cheers-


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • January 29, 2023

The problem is that you won't notice if anyone has maliciously changed the encryption password. As long as it present in the VBR configuration you will be able use the backups. But as soon as they keys get deleted, you can't decrypt your backups anymore.


Comment