Diff
1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
2index 04d8f0906422fcb0e27a1070ab0700882ec64349..43fd688ef32f959ae93f741a06ced6dc945ee3f9 100644
3--- a/duplicity-backup.conf.example
4+++ b/duplicity-backup.conf.example
5@@ -81,6 +81,17 @@ PASSPHRASE="foobar_gpg_passphrase"
6 GPG_ENC_KEY="foobar_gpg_key"
7 GPG_SIGN_KEY="foobar_gpg_key"
8
9+# Do you want to hide the key id of the encrypted files? yes/no
10+# It uses the gpg's --hidden-recipient command to obfuscate the owner of the backup.
11+# On restore, gpg will automatically try all available secret keys in order to
12+# decrypt the backup. See gpg(1) for more details.
13+# HIDE_KEY_ID='yes'
14+
15+# You can optionally specify the secret keyring file to use for the encryption and
16+# signing keys. If not specified, the default secret keyring is used which is
17+# usually located at ~/.gnupg/secring.gpg
18+# SECRET_KEYRING="/home/foobar_user_name/.gnupg/duplicity.gpg
19+
20 # BACKUP SOURCE INFORMATION
21 # The ROOT of your backup (where you want the backup to start);
22 # This can be / or somwhere else -- I use /home/ because all the
23diff --git a/duplicity-backup.sh b/duplicity-backup.sh
24index 26dc124eebfd5a30d55c3f9de787ba40e62b518a..eb90088f674652f3d81dd2ccae7edbec2be995c6 100755
25--- a/duplicity-backup.sh
26+++ b/duplicity-backup.sh
27@@ -186,7 +186,15 @@ LOCKFILE=${LOGDIR}backup.lock
28
29 if [ "$ENCRYPTION" = "yes" ]; then
30 if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
31- ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
32+ if [ "$HIDE_KEY_ID" = "yes" ]; then
33+ ENCRYPT="--hidden-encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
34+ else
35+ ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
36+ fi
37+ if [ ! -z "$SECRET_KEYRING" ]; then
38+ KEYRING="--secret-keyring ${SECRET_KEYRING}"
39+ ENCRYPT="${ENCRYPT} --encrypt-secret-keyring=${SECRET_KEYRING}"
40+ fi
41 elif [ ! -z "$PASSPHRASE" ]; then
42 ENCRYPT=""
43 fi
44@@ -506,10 +514,10 @@ backup_this_script()
45 if [ ! -z "$GPG_ENC_KEY" -a ! -z "$GPG_SIGN_KEY" ]; then
46 export GPG_TTY=`tty`
47 if [ "$GPG_ENC_KEY" = "$GPG_SIGN_KEY" ]; then
48- gpg -a --export-secret-keys ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-and-sign-secret.key.txt
49+ gpg -a --export-secret-keys ${KEYRING} ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-and-sign-secret.key.txt
50 else
51- gpg -a --export-secret-keys ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-secret.key.txt
52- gpg -a --export-secret-keys ${GPG_SIGN_KEY} > ${TMPDIR}/duplicity-backup-sign-secret.key.txt
53+ gpg -a --export-secret-keys ${KEYRING} ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-secret.key.txt
54+ gpg -a --export-secret-keys ${KEYRING} ${GPG_SIGN_KEY} > ${TMPDIR}/duplicity-backup-sign-secret.key.txt
55 fi
56 fi
57