The Proxmox VE documentation says it plainly: “Without their key, backups will be inaccessible”. It also names the most common trap: backing up a whole system with a key kept on that same system. If the system is lost, the key goes with it (Proxmox VE, Encryption).
1. Create the key, before the first backup
PBS encryption is done by the client, with AES-256-GCM, before the data leaves the machine. It is optional: you have to turn it on. Do it before the first backup, because an encrypted backup does not deduplicate with an unencrypted one (see encryption and deduplication).
From Proxmox VE
In Datacenter → Storage, on the Proxmox Backup Server storage, Encryption tab: choose Auto-generate a client encryption key. Proxmox VE stores the key in /etc/pve/priv/storage/<STORAGE-ID>.enc, readable by root only, then shows an “Important: Save your Encryption Key” window with two buttons: copy the key, or print it. Do both, right away.
With proxmox-backup-client
proxmox-backup-client key create /root/pbs-key.jsonproxmox-backup-client key create --kdf none /root/pbs-key.json
chmod 600 /root/pbs-key.jsonWithout a path, the key is created in the default location, ~/.config/proxmox-backup/encryption-key.json, where the client also looks for it when --keyfile is missing (Backup Client, Encryption). The full installation guide is in proxmox-backup-client on Linux.
Windows client: version 0.4.0 does not encrypt backups. Encryption is planned for an upcoming version.
2. Back up the key, off the system being backed up
The Proxmox documentation recommends three copies: in a password manager, on a USB drive kept in a safe place, and on paper for the worst case. The paper copy is generated with paperkey, which also produces a QR code:
proxmox-backup-client key paperkey /etc/pve/priv/storage/<STORAGE-ID>.enc \
--output-format text > /root/pbs-key-to-print.txtAlso note the key fingerprint: it is what the missing key message shows when a restore is started without the right key.
proxmox-backup-client key show /etc/pve/priv/storage/<STORAGE-ID>.enc3. Single node or cluster: where the key lives
- Single-node Proxmox VE, the most common case in small organisations: the key only exists on that server. Losing the server means losing the key, and therefore access to every backup, unless a copy was made elsewhere.
- Proxmox VE cluster:
/etc/pveis replicated by pmxcfs to every node. Losing one node does not lose the key. Losing the whole cluster (fire, ransomware encrypting every hypervisor) does: the copy outside the cluster remains essential.
To restore on a rebuilt Proxmox VE: add the PBS storage, then in the Encryption tab choose Upload an existing client encryption key, and paste or drop the key file.
4. The master key: the recovery method built into PBS
PBS provides a recovery mechanism: an RSA key pair, called the master key. The public key is given to the client; with every backup, it adds a copy of the encryption key, encrypted with that public key, named rsa-encrypted.key. The private key, kept offline, recovers the encryption key even if the client is gone (Using a Master Key to Store and Recover Encryption Keys).
proxmox-backup-client key create-master-key # creates master-public.pem and master-private.pem
proxmox-backup-client key import-master-pubkey master-public.pem
# store master-private.pem offline, then remove it from the machineproxmox-backup-client restore <snapshot> rsa-encrypted.key /root/rsa-encrypted.key
proxmox-backup-client key import-with-master-key /root/pbs-key.json \
--master-keyfile /path/master-private.pem --encrypted-keyfile /root/rsa-encrypted.keyIn Proxmox VE, the public key is set on the PBS storage (master-pubkey option, stored in /etc/pve/priv/storage/<STORAGE-ID>.master.pem). The private key follows the same rules as the encryption key: without a copy, no recovery. paperkey also accepts the RSA private key, for a paper copy in a safe. Only backups made after the public key was installed contain rsa-encrypted.key.
5. Changing the key
There is no rotation that re-encrypts existing backups. Changing a storage's key (Proxmox VE labels it Edit existing encryption key (dangerous!)) only applies to the following backups:
- existing backups stay encrypted with the old key: keep it to restore them;
- the first backup with the new key sends all the data again, without deduplication against the previous ones;
- to restore the old ones, Proxmox staff advise on the forum a second storage pointing to the same datastore, with the old key.
proxmox-backup-client key change-passphrase does not change the key: only the passphrase protecting the file.
6. At NimbusBackup: key not requested for backup hosting only
Key not requested for backup hosting only. For a customer who only entrusts us with hosting their backups, the key stays with them, even for a test: if you want to test a restore, the test happens on your side, with your key. The restore tests we run ourselves are part of the managed services for your Proxmox VE, with the key we hold as administrator, a distinct role. We explain this choice, and how it differs from other providers, in the Nimbus vs Cloud-PBS comparison.
The Proxmox VE documentation says: “Do not use encryption if there is no benefit from it, for example, when you are running the server locally in a trusted network” (Proxmox VE, Encryption). A copy hosted outside your premises is the exact opposite of that example: this is where encryption helps, since the host cannot read your data. Encryption remains an option you turn on; that is why the member area permanently counts unencrypted snapshots:

For the role of encryption in a compliance approach (GDPR, NIS2, ANSSI recommendations), see backup security and compliance.
Frequently asked questions
I lost the encryption key: can the backups be recovered?
Only if a copy exists: the key file stored elsewhere, its paper copy, or the RSA master key if you had set it up before those backups. Without any of these copies, the encrypted backups are unreadable, for you as for the PBS host or Proxmox.
Is the key present on every node of a Proxmox VE cluster?
Yes. Proxmox VE stores it in /etc/pve/priv/storage/<STORAGE-ID>.enc, and /etc/pve is replicated by pmxcfs to every node of the cluster. Losing one node does not lose the key; losing the whole cluster does. On a single-node Proxmox VE, the key only exists on that server.
Can the encryption key of a PBS storage be changed?
Yes for the following backups, no for existing ones: they stay encrypted with the old key, which you must keep to restore them. The first backup with the new key sends all the data again, because two different keys do not deduplicate with each other.
An offsite copy the host cannot read
NimbusBackup hosts managed Proxmox Backup Servers. Key not requested for backup hosting only. From €12 excl. VAT per TB per month.
