[Encrypted InnoDB tablespace backups] keyring_file dependency should be documented

Bug #1656282 reported by Laurynas Biveinis
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Percona XtraBackup moved to https://jira.percona.com/projects/PXB
Status tracked in 2.4
2.4
Triaged
Medium
Unassigned

Bug Description

[In:/doc/percona-xtrabackup/LATEST/advanced/encrypted_innodb_tablespace_backups.html]

Currenly, the doc page discusses taking backups of encrypted tablespaces without mentioning anything about server keyrings in use. That XB introduces keyring_file_data option, implies that it works only with keyring_file and not with any other keyring plugin. This should be documented.

Tags: doc
Revision history for this message
Sergei Glushchenko (sergei.glushchenko) wrote :

Eventually, xtrabackup should support keyring plugins.

Another option is to fetch master keys from server itself using 'keyring_key_fetch' from recently introduced keyring_udf and re-encrypt tablespace keys with the backup master key provided at the time of backup.

As for current implementation, we should state that it only works with default keyring file plugin.

Revision history for this message
Laurynas Biveinis (laurynas-biveinis) wrote :

Does XB query the running server for the active keyring plugin currently?

Revision history for this message
Sergei Glushchenko (sergei.glushchenko) wrote :

It doesn't. When this support was added the only available plugin was keyring_file.

Revision history for this message
Laurynas Biveinis (laurynas-biveinis) wrote :

Perhaps adding such check sooner would help with better diagnostics once plugins proliferate and someone attempts using older XB versions to take backups on such servers

Revision history for this message
Sergei Glushchenko (sergei.glushchenko) wrote :

Agree. Reported as bug 1658612

Revision history for this message
Shahriyar Rzayev (rzayev-sehriyar) wrote :

Percona now uses JIRA for bug reports so this bug report is migrated to: https://jira.percona.com/browse/PXB-779

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.