Control: tag -1 + upstream
Control: severity -1 wishlist
Control: retitle -1 [duplicity] please support different passphrases for 
signing and encryption

Hi Dominik,

Dominik George wrote (11 Oct 2013 23:44:46 GMT) :
> When using different encryption and signing keys, the password
> config variable is not passed as PASSPHRASE environment variable,
> making duplicity expect the passphrase on stdin.

I acknowledge this is a limitation of the current implementation.
It's documented in example.dup. FYI backupninja is in maintenance
mode: patches are welcome, but don't expect upstream to add
new features.

> I think there might be some confusion between signing and encrpyting
> anyway, because the config file commentary suggests that a pass-
> phrase is used for unlocking the encryption key, which is plain non-
> sense as GPG always uses public keys for (message) encryption.

I don't think this to be non-sense. The passphrase that unlocks the
encryption key is needed at incremental backup time because duplicity
needs to decrypt the metadata of previous backup sets, in order to
know what's new to backup. If you still think it's non-sense while
being aware of this, please clarify :)

Cheers,
-- 
  intrigeri
  | GnuPG key @ https://gaffer.ptitcanardnoir.org/intrigeri/intrigeri.asc
  | OTR fingerprint @ https://gaffer.ptitcanardnoir.org/intrigeri/otr.asc


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to