Diff
1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
2index 37ecf770075bfc0a4891fb748b08d23f94b27000..098cf9fb8368e0efd2cbc89779a4068c06aa70b4 100644
3--- a/duplicity-backup.conf.example
4+++ b/duplicity-backup.conf.example
5@@ -81,6 +81,17 @@ PASSPHRASE="foobar_gpg_passphrase"
6 GPG_ENC_KEY="foobar_gpg_key"
7 GPG_SIGN_KEY="foobar_gpg_key"
8
9+# Do you want to hide the key id of the encrypted files? yes/no
10+# It uses the gpg's --hidden-recipient command to obfuscate the owner of the backup.
11+# On restore, gpg will automatically try all available secret keys in order to
12+# decrypt the backup. See gpg(1) for more details.
13+# HIDE_KEY_ID='yes'
14+
15+# You can optionally specify the secret keyring file to use for the encryption and
16+# signing keys. If not specified, the default secret keyring is used which is
17+# usually located at ~/.gnupg/secring.gpg
18+# SECRET_KEYRING="/home/foobar_user_name/.gnupg/duplicity.gpg
19+
20 # BACKUP SOURCE INFORMATION
21 # The ROOT of your backup (where you want the backup to start);
22 # This can be / or somwhere else -- I use /home/ because all the
23diff --git a/duplicity-backup.sh b/duplicity-backup.sh
24index ba77119eb01de413c11dc514f2a3cb0d2bcdad10..72094c92d32e6be9d7a354ccf599f7b8df998648 100755
25--- a/duplicity-backup.sh
26+++ b/duplicity-backup.sh
27@@ -186,7 +186,18 @@ LOCKFILE=${LOGDIR}backup.lock
28
29 if [ "$ENCRYPTION" = "yes" ]; then
30 if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
31- ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
32+ if [ "$HIDE_KEY_ID" = "yes" ]; then
33+ ENCRYPT="--hidden-encrypt-key=${GPG_ENC_KEY}"
34+ if [ "$COMMAND" != "restore" -a "$COMMAND" != "restore-file" -a "$COMMAND" != "restore-dir" ]; then
35+ ENCRYPT="$ENCRYPT --sign-key=${GPG_SIGN_KEY}"
36+ fi
37+ else
38+ ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
39+ fi
40+ if [ ! -z "$SECRET_KEYRING" ]; then
41+ KEYRING="--secret-keyring ${SECRET_KEYRING}"
42+ ENCRYPT="${ENCRYPT} --encrypt-secret-keyring=${SECRET_KEYRING}"
43+ fi
44 elif [ ! -z "$PASSPHRASE" ]; then
45 ENCRYPT=""
46 fi
47@@ -425,13 +436,13 @@ include_exclude()
48
49 duplicity_cleanup()
50 {
51- echo "-----------[ Duplicity Cleanup ]-----------" >> ${LOGFILE}
52- if [[ "${CLEAN_UP_TYPE}" != "none" ]]; then
53- eval ${ECHO} ${DUPLICITY} ${CLEAN_UP_TYPE} ${CLEAN_UP_VARIABLE} ${STATIC_OPTIONS} --force \
54- ${ENCRYPT} \
55- ${DEST} >> ${LOGFILE}
56- echo >> ${LOGFILE}
57- fi
58+ echo "-----------[ Duplicity Cleanup ]-----------" >> ${LOGFILE}
59+ if [[ "${CLEAN_UP_TYPE}" != "none" && ! -z ${CLEAN_UP_TYPE} && ! -z ${CLEAN_UP_VARIABLE} ]]; then
60+ eval ${ECHO} ${DUPLICITY} ${CLEAN_UP_TYPE} ${CLEAN_UP_VARIABLE} ${STATIC_OPTIONS} --force \
61+ ${ENCRYPT} \
62+ ${DEST} >> ${LOGFILE}
63+ echo >> ${LOGFILE}
64+ fi
65 if [ ! -z ${REMOVE_INCREMENTALS_OLDER_THAN} ] && [[ ${REMOVE_INCREMENTALS_OLDER_THAN} =~ ^[0-9]+$ ]]; then
66 eval ${ECHO} ${DUPLICITY} remove-all-inc-of-but-n-full ${REMOVE_INCREMENTALS_OLDER_THAN} \
67 ${STATIC_OPTIONS} --force \
68@@ -522,10 +533,10 @@ backup_this_script()
69 if [ ! -z "$GPG_ENC_KEY" -a ! -z "$GPG_SIGN_KEY" ]; then
70 export GPG_TTY=`tty`
71 if [ "$GPG_ENC_KEY" = "$GPG_SIGN_KEY" ]; then
72- gpg -a --export-secret-keys ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-and-sign-secret.key.txt
73+ gpg -a --export-secret-keys ${KEYRING} ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-and-sign-secret.key.txt
74 else
75- gpg -a --export-secret-keys ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-secret.key.txt
76- gpg -a --export-secret-keys ${GPG_SIGN_KEY} > ${TMPDIR}/duplicity-backup-sign-secret.key.txt
77+ gpg -a --export-secret-keys ${KEYRING} ${GPG_ENC_KEY} > ${TMPDIR}/duplicity-backup-encryption-secret.key.txt
78+ gpg -a --export-secret-keys ${KEYRING} ${GPG_SIGN_KEY} > ${TMPDIR}/duplicity-backup-sign-secret.key.txt
79 fi
80 fi
81