Hi folks,
I tested changing the encryption key for PBS backups. Unfortunately, the backup job and verification job did not notify me that the key had been changed. This is the behavior of PVE/PBS as I understand it from the documentation. No surprise, just confirmation.
So it's great to have immutable backups, but for a malicious actor who has gained access to PVE, it's just a matter of how long the retention is set on the PBS side.
It would be great to monitor not only data integrity but also encryption integrity. So a verification job or other job would notify us of the encryption key change.
Or am I misunderstanding something? Thanks for enlightening me.
I tested changing the encryption key for PBS backups. Unfortunately, the backup job and verification job did not notify me that the key had been changed. This is the behavior of PVE/PBS as I understand it from the documentation. No surprise, just confirmation.
So it's great to have immutable backups, but for a malicious actor who has gained access to PVE, it's just a matter of how long the retention is set on the PBS side.
It would be great to monitor not only data integrity but also encryption integrity. So a verification job or other job would notify us of the encryption key change.
Or am I misunderstanding something? Thanks for enlightening me.
Last edited: