From owner-freebsd-security Mon Nov 26 17:53:24 2001 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-165-226-105.dsl.lsan03.pacbell.net [64.165.226.105]) by hub.freebsd.org (Postfix) with ESMTP id 80F9137B417 for ; Mon, 26 Nov 2001 17:53:21 -0800 (PST) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id E1C5666B27; Mon, 26 Nov 2001 17:53:20 -0800 (PST) Date: Mon, 26 Nov 2001 17:53:20 -0800 From: Kris Kennaway To: Randy Bush Cc: "R.P. Aditya" , freebsd-security@freebsd.org Subject: Re: crypted remote backup Message-ID: <20011126175320.C20635@xor.obsecurity.org> References: Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="vEao7xgI/oilGqZ+" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from randy@psg.com on Mon, Nov 26, 2001 at 05:12:41PM -0800 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --vEao7xgI/oilGqZ+ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Nov 26, 2001 at 05:12:41PM -0800, Randy Bush wrote: > > If you want rsync to only copy the updated/modified stuff you'll have > > to do the encryption on the "source" server and keep it in a separate > > "tree" >=20 > so i have been thinking >=20 > > and using PGP/GPG to do the encryption is the easiest way I've found to > > do it. >=20 > is this feasible for 2GB files? I wouldn't recommend using it on all 2GB..a single bit error will render your backup useless. That's why I suggested breaking the file into chunks in my earlier mail. I wouldn't recommend using PGP either; you probably don't need it, and it will be slower than alternatives. Just use OpenSSL..e.g. an appropriate symmetric cipher and passphrase. Kris --vEao7xgI/oilGqZ+ Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE8AvIPWry0BWjoQKURAkm4AKCQxkjexCoNrplni7NytYkKy7ti3ACfaGp1 f+XKE7Hp08/XZ8Ioy3J/nT4= =sGvD -----END PGP SIGNATURE----- --vEao7xgI/oilGqZ+-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message