640e4971218872885bb2f30f26fa37391816b087

Author
puredoze <puredoze@gmail.com>
Committer
puredoze <puredoze@gmail.com>
Date

Message

Added support for using separate signature and encryption keys

Diff

 1diff --git a/duplicity-backup.conf.example b/duplicity-backup.conf.example
 2index 9c6b4054aed62a84c8baaf10d5b98d90b1e4e735..b3af280edfb3e1c29676a10f531f3594d4ef2cfe 100644
 3--- a/duplicity-backup.conf.example
 4+++ b/duplicity-backup.conf.example
 5@@ -45,17 +45,25 @@ AWS_SECRET_ACCESS_KEY="foobar_aws_access_key"
 6 
 7 # ENCRYPTION INFORMATION
 8 # Do you want your backup to be encrypted? yes/no
 9-# If yes, please make sure you specify either PASSPHRASE or GPG_KEY
10+# If yes, please make sure you specify either PASSPHRASE or GPG_ENC_KEY/GPG_SIGN_KEY
11 ENCRYPTION='yes'
12 
13 # If you are NOT running this from a cron, comment this line out
14 # and duplicity should prompt you for your password.
15+# Otherwise this password is either used for symetric encryption
16+# (your backups will be encrypted with this password) or is used
17+# for the "GPG_SIGN_KEY" (see below).
18 # Comment out if you aren't using encryption
19 PASSPHRASE="foobar_gpg_passphrase"
20 
21-# Specify which GPG key you would like to use (even if you have only one).
22-# Comment out if you're using only PASSPHRASE or not using encryption
23-GPG_KEY="foobar_gpg_key"
24+# Specify which GPG keys you would like to use (even if you have only one).
25+# It is highly recommended to create separate signature and encryption keys. 
26+# When run, duplicity should prompt you for the GPG_SIGN_KEY password 
27+# (or specify the PASSPHRASE above if you run this script from a cron).
28+# Comment out if you're using only PASSPHRASE (symetric encryption) or not using 
29+# encryption at all.
30+GPG_ENC_KEY="foobar_gpg_key"
31+GPG_SIGN_KEY="foobar_gpg_key"
32 
33 # BACKUP SOURCE INFORMATION
34 # The ROOT of your backup (where you want the backup to start);
35diff --git a/duplicity-backup.sh b/duplicity-backup.sh
36index e899d5c05ab0d3e739c2957dbf3d4eb6214c2771..3a08dd3b2a8c6b3ccdcbed8665ff5a7d156e5913 100755
37--- a/duplicity-backup.sh
38+++ b/duplicity-backup.sh
39@@ -158,8 +158,8 @@ S3CMD="$(which s3cmd)"
40 LOCKFILE=${LOGDIR}backup.lock
41 
42 if [ "$ENCRYPTION" = "yes" ]; then
43-  if [ ! -z "$GPG_KEY" ]; then
44-    ENCRYPT="--encrypt-key=${GPG_KEY} --sign-key=${GPG_KEY}"
45+  if [ ! -z "$GPG_ENC_KEY" ] && [ ! -z "$GPG_SIGN_KEY" ]; then
46+    ENCRYPT="--encrypt-key=${GPG_ENC_KEY} --sign-key=${GPG_SIGN_KEY}"
47   elif [ ! -z "$PASSPHRASE" ]; then
48     ENCRYPT=""
49   fi
50@@ -196,7 +196,8 @@ fi
51 check_variables ()
52 {
53   if [[ ${ROOT} = "" || ${DEST} = "" || ${INCLIST} = "" || \
54-         ${GPG_KEY} = "foobar_gpg_key" || \
55+         ${GPG_ENC_KEY} = "foobar_gpg_key" || \
56+         ${GPG_SIGN_KEY} = "foobar_gpg_key" || \         
57          ${PASSPHRASE} = "foobar_gpg_passphrase" || \
58          ${LOGDIR} = "/home/foobar_user_name/logs/test2/" || \
59          ( ${DEST_IS_S3} = true && ${AWS_ACCESS_KEY_ID} = "foobar_aws_key_id" ) || \