572f733bd2b8ff26636d3d4f27e2ef94e6dca97a

Author
zertrin <zrk951@gmail.com>
Committer
zertrin <zrk951@gmail.com>
Date

Message

Merge pull request #12 from puredoze/master

Added support for using separate signature and encryption keys
/!\ configuration file altered, please look at the diff

Diff

 1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
 2index 9c6b4054aed62a84c8baaf10d5b98d90b1e4e735..448a73e1471480399c119bba54fb3f3b4ca61c37 100644
 3--- a/duplicity-backup.conf.example
 4+++ b/duplicity-backup.conf.example
 5@@ -45,17 +45,28 @@ AWS_SECRET_ACCESS_KEY="foobar_aws_access_key"
 6 
 7 # ENCRYPTION INFORMATION
 8 # Do you want your backup to be encrypted? yes/no
 9-# If yes, please make sure you specify either PASSPHRASE or GPG_KEY
10+# If yes, please make sure you specify either PASSPHRASE or GPG_ENC_KEY/GPG_SIGN_KEY
11 ENCRYPTION='yes'
12 
13 # If you are NOT running this from a cron, comment this line out
14 # and duplicity should prompt you for your password.
15+# Otherwise this password is either used for symmetric encryption
16+# (your backups will be encrypted with this password) or is used
17+# for the "GPG_SIGN_KEY" (see below).
18 # Comment out if you aren't using encryption
19 PASSPHRASE="foobar_gpg_passphrase"
20 
21-# Specify which GPG key you would like to use (even if you have only one).
22-# Comment out if you're using only PASSPHRASE or not using encryption
23-GPG_KEY="foobar_gpg_key"
24+# Specify which GPG keys you would like to use (even if you have only one).
25+# If you are running this from a cron, it is highly recommended to create separate 
26+# signature and encryption keys, because you have to specify the password for the 
27+# GPG_SIGN_KEY via the above PASSPHRASE variable 
28+# (see http://www.debian-administration.org/articles/209#d0e109).
29+# If you are not running the script from a cron, duplicity should prompt you for the 
30+# GPG_SIGN_KEY password.
31+# Comment out if you're using only PASSPHRASE (symmetric encryption) or not using 
32+# encryption at all.
33+GPG_ENC_KEY="foobar_gpg_key"
34+GPG_SIGN_KEY="foobar_gpg_key"
35 
36 # BACKUP SOURCE INFORMATION
37 # The ROOT of your backup (where you want the backup to start);
38diff --git a/duplicity-backup.sh b/duplicity-backup.sh
39index e899d5c05ab0d3e739c2957dbf3d4eb6214c2771..3a08dd3b2a8c6b3ccdcbed8665ff5a7d156e5913 100755
40--- a/duplicity-backup.sh
41+++ b/duplicity-backup.sh
42@@ -158,8 +158,8 @@ S3CMD="$(which s3cmd)"
43 LOCKFILE=${LOGDIR}backup.lock
44 
45 if [ "$ENCRYPTION" = "yes" ]; then
46-  if [ ! -z "$GPG_KEY" ]; then
47-    ENCRYPT="--encrypt-key=${GPG_KEY} --sign-key=${GPG_KEY}"
48+  if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
49+    ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
50   elif [ ! -z "$PASSPHRASE" ]; then
51     ENCRYPT=""
52   fi
53@@ -196,7 +196,8 @@ fi
54 check_variables ()
55 {
56   if [[ ${ROOT} = "" || ${DEST} = "" || ${INCLIST} = "" || \
57-         ${GPG_KEY} = "foobar_gpg_key" || \
58+         ${GPG_ENC_KEY} = "foobar_gpg_key" || \
59+         ${GPG_SIGN_KEY} = "foobar_gpg_key" || \         
60          ${PASSPHRASE} = "foobar_gpg_passphrase" || \
61          ${LOGDIR} = "/home/foobar_user_name/logs/test2/" || \
62          ( ${DEST_IS_S3} = true && ${AWS_ACCESS_KEY_ID} = "foobar_aws_key_id" ) || \