Diff
1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
2index 9c6b4054aed62a84c8baaf10d5b98d90b1e4e735..b3af280edfb3e1c29676a10f531f3594d4ef2cfe 100644
3--- a/duplicity-backup.conf.example
4+++ b/duplicity-backup.conf.example
5@@ -45,17 +45,25 @@ AWS_SECRET_ACCESS_KEY="foobar_aws_access_key"
6
7 # ENCRYPTION INFORMATION
8 # Do you want your backup to be encrypted? yes/no
9-# If yes, please make sure you specify either PASSPHRASE or GPG_KEY
10+# If yes, please make sure you specify either PASSPHRASE or GPG_ENC_KEY/GPG_SIGN_KEY
11 ENCRYPTION='yes'
12
13 # If you are NOT running this from a cron, comment this line out
14 # and duplicity should prompt you for your password.
15+# Otherwise this password is either used for symetric encryption
16+# (your backups will be encrypted with this password) or is used
17+# for the "GPG_SIGN_KEY" (see below).
18 # Comment out if you aren't using encryption
19 PASSPHRASE="foobar_gpg_passphrase"
20
21-# Specify which GPG key you would like to use (even if you have only one).
22-# Comment out if you're using only PASSPHRASE or not using encryption
23-GPG_KEY="foobar_gpg_key"
24+# Specify which GPG keys you would like to use (even if you have only one).
25+# It is highly recommended to create separate signature and encryption keys.
26+# When run, duplicity should prompt you for the GPG_SIGN_KEY password
27+# (or specify the PASSPHRASE above if you run this script from a cron).
28+# Comment out if you're using only PASSPHRASE (symetric encryption) or not using
29+# encryption at all.
30+GPG_ENC_KEY="foobar_gpg_key"
31+GPG_SIGN_KEY="foobar_gpg_key"
32
33 # BACKUP SOURCE INFORMATION
34 # The ROOT of your backup (where you want the backup to start);
35diff --git a/duplicity-backup.sh b/duplicity-backup.sh
36index e899d5c05ab0d3e739c2957dbf3d4eb6214c2771..3a08dd3b2a8c6b3ccdcbed8665ff5a7d156e5913 100755
37--- a/duplicity-backup.sh
38+++ b/duplicity-backup.sh
39@@ -158,8 +158,8 @@ S3CMD="$(which s3cmd)"
40 LOCKFILE=${LOGDIR}backup.lock
41
42 if [ "$ENCRYPTION" = "yes" ]; then
43- if [ ! -z "$GPG_KEY" ]; then
44- ENCRYPT="--encrypt-key=${GPG_KEY} --sign-key=${GPG_KEY}"
45+ if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
46+ ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
47 elif [ ! -z "$PASSPHRASE" ]; then
48 ENCRYPT=""
49 fi
50@@ -196,7 +196,8 @@ fi
51 check_variables ()
52 {
53 if [[ ${ROOT} = "" || ${DEST} = "" || ${INCLIST} = "" || \
54- ${GPG_KEY} = "foobar_gpg_key" || \
55+ ${GPG_ENC_KEY} = "foobar_gpg_key" || \
56+ ${GPG_SIGN_KEY} = "foobar_gpg_key" || \
57 ${PASSPHRASE} = "foobar_gpg_passphrase" || \
58 ${LOGDIR} = "/home/foobar_user_name/logs/test2/" || \
59 ( ${DEST_IS_S3} = true && ${AWS_ACCESS_KEY_ID} = "foobar_aws_key_id" ) || \