Ah, so what you are suggesting is actually to encrypt to both my personal key and the machine's private key?
Okay cool, thank you for taking the time to fill me in. Given this move away from using separate signing and encryption keys where the host doesn't have the secret encryption key, is there any point in using PGP keys at all as opposed to just using symmetric encryption with GPG_PW? I thought that the whole point of using keypairs was that the host wouldn't have both parts of the pair.
Hello, thank you for the reply and the info! I think that duplicity will just restart a backup if it can't resume because it doesn't have the key to decrypt, right? I'm happy with that, and also don't mind restoring the metadata manually if necessary. Just to note, there is the security advantage that old versions of files, or deleted files, can't be recovered from backups by an attacker.
Cannot use separate signing and encryption keys with no secret encryption key without disabling GPG tests
Oops, sorry, that does indeed fix it. Thanks for the reply.
New check for encryption secret keys broken for symmetric encryption
Fix build with ld's --as-needed flag