Diff
1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
2index 9c6b4054aed62a84c8baaf10d5b98d90b1e4e735..448a73e1471480399c119bba54fb3f3b4ca61c37 100644
3--- a/duplicity-backup.conf.example
4+++ b/duplicity-backup.conf.example
5@@ -45,17 +45,28 @@ AWS_SECRET_ACCESS_KEY="foobar_aws_access_key"
6
7 # ENCRYPTION INFORMATION
8 # Do you want your backup to be encrypted? yes/no
9-# If yes, please make sure you specify either PASSPHRASE or GPG_KEY
10+# If yes, please make sure you specify either PASSPHRASE or GPG_ENC_KEY/GPG_SIGN_KEY
11 ENCRYPTION='yes'
12
13 # If you are NOT running this from a cron, comment this line out
14 # and duplicity should prompt you for your password.
15+# Otherwise this password is either used for symmetric encryption
16+# (your backups will be encrypted with this password) or is used
17+# for the "GPG_SIGN_KEY" (see below).
18 # Comment out if you aren't using encryption
19 PASSPHRASE="foobar_gpg_passphrase"
20
21-# Specify which GPG key you would like to use (even if you have only one).
22-# Comment out if you're using only PASSPHRASE or not using encryption
23-GPG_KEY="foobar_gpg_key"
24+# Specify which GPG keys you would like to use (even if you have only one).
25+# If you are running this from a cron, it is highly recommended to create separate
26+# signature and encryption keys, because you have to specify the password for the
27+# GPG_SIGN_KEY via the above PASSPHRASE variable
28+# (see http://www.debian-administration.org/articles/209#d0e109).
29+# If you are not running the script from a cron, duplicity should prompt you for the
30+# GPG_SIGN_KEY password.
31+# Comment out if you're using only PASSPHRASE (symmetric encryption) or not using
32+# encryption at all.
33+GPG_ENC_KEY="foobar_gpg_key"
34+GPG_SIGN_KEY="foobar_gpg_key"
35
36 # BACKUP SOURCE INFORMATION
37 # The ROOT of your backup (where you want the backup to start);
38diff --git a/duplicity-backup.sh b/duplicity-backup.sh
39index e899d5c05ab0d3e739c2957dbf3d4eb6214c2771..3a08dd3b2a8c6b3ccdcbed8665ff5a7d156e5913 100755
40--- a/duplicity-backup.sh
41+++ b/duplicity-backup.sh
42@@ -158,8 +158,8 @@ S3CMD="$(which s3cmd)"
43 LOCKFILE=${LOGDIR}backup.lock
44
45 if [ "$ENCRYPTION" = "yes" ]; then
46- if [ ! -z "$GPG_KEY" ]; then
47- ENCRYPT="--encrypt-key=${GPG_KEY} --sign-key=${GPG_KEY}"
48+ if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
49+ ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
50 elif [ ! -z "$PASSPHRASE" ]; then
51 ENCRYPT=""
52 fi
53@@ -196,7 +196,8 @@ fi
54 check_variables ()
55 {
56 if [[ ${ROOT} = "" || ${DEST} = "" || ${INCLIST} = "" || \
57- ${GPG_KEY} = "foobar_gpg_key" || \
58+ ${GPG_ENC_KEY} = "foobar_gpg_key" || \
59+ ${GPG_SIGN_KEY} = "foobar_gpg_key" || \
60 ${PASSPHRASE} = "foobar_gpg_passphrase" || \
61 ${LOGDIR} = "/home/foobar_user_name/logs/test2/" || \
62 ( ${DEST_IS_S3} = true && ${AWS_ACCESS_KEY_ID} = "foobar_aws_key_id" ) || \