once again, apologies for the delay, still not getting notified.
This is automatic, so there are no direct places to see this.
If you can run pass on the commandline, that suggests you have it installed and the Duplicati can use it (assuming it is configured as well).
I can confirm that pass is not installed, the command does not exist in my environment
You can start the secret tool, as it will report the default provider:
sudo -u duplicati /opt/duplicati/duplicati-secret-tool info
Supported secret providers on Linux:
env - Secrets from environment variables
file-secret - Secrets from a file
awssm - Secrets from AWS Secrets Manager
hcv - Secrets from HashiCorp Vault
gcsm - Secrets from Google Cloud Storage Secret Manager
azkv - Secrets from Azure Key Vault
pass - Secrets from Unix pass (not supported)
Authorization required, but no authorization protocol specified
libsecret - Secrets from libsecret
No information found for secret provider '': path
I would suggest lauching Duplicati once with --disable-db-encryption on the old version. This will decrypt the fields in the database (since the key is apparently available). You can then configure DUPLICATI__SECRET_PROVIDER=file:// with the encryption key, and start again without the --disable-db-encryption switch to have it encrypted with the new key.
After that, you can upgrade to the latest version, and it will use the file.
Sadly, this does not reveal where the key was in the first place.
Thank you, I ran it with --disable-db-encryption but, to prevent other issues I decided not to re-encrypt the DB. Given it’s a single-user workstation running Duplicati and the filesystem where the DB lives is LUKS encrypted, I think that’s pretty safe (feel free to disagree if you advise to re-encrypt it, I’ll do it). I can re-encrypt, but I’m not sure what’s the best way/best long-term solution.
Thanks again for the help!