Encrypted backups
It is necessary to prevent the backup archive from being unauthorized to read, encrypt the backup with the public key, and separate the recovery private key from the backup node.
Recommended process:
- Use ppk key generate to generate the key pair.
- Configure only the public key in the backup configuration, first perform a dry-run check of inputs, outputs, and destinations.
- Perform a backup and confirm the generation of the
.ppkefile. - Private keys are kept in an independent recovery environment, and decryption and recovery exercises are performed regularly.
See Encryption and Decryption for the parameters and compatible formats of the encryption archive. Do not write private key passwords to configurations, scripts, or tickets.