Question About Master Key, Session Backup, and Disaster Recovery

Hello Everyone,

I have a question about the following scenario.

A customer has enabled Session Backup and Credential Backup in Senhasegura and has completed the Master Key Ceremony .

The customer now wants to free up space on the remote backup storage by deleting session recordings that are older than one year.

I would like to clarify the following:

  • Does the customer need to reconstruct the Master Key or decrypt the session recordings before deleting them?
  • Is the Master Key only used for restoring or decrypting data, or is it also required for deleting old session recordings?
  • In a disaster recovery scenario, if the customer reconstructs the Master Key, which official Senhasegura tool is used to decrypt the backup? After decryption, are the credentials displayed in a text file or accessed through a Senhasegura tool?

If anyone has experience with this scenario or can share the official process, I would really appreciate your guidance.

Thank you!

Hello,

Please find the answers below:

  • No, the Master Key is not required to delete old backups or session recordings stored in Remote Storage. It is only required when you need to decrypt protected backup data.
  • The Master Key is not used for deleting old session recordings. Its purpose is to restore access to encrypted backup data by decrypting it.
  • In a disaster recovery scenario, after reconstructing the Master Key, the AesCrypt (AES Crypt - Downloads) tool is used to decrypt the encrypted backup files (including credentials or session recording files) stored in Remote Storage.
  • After decryption, the data is available in its original form. For example, decrypted credential files can be viewed in plain text, just like opening the contents of an extracted ZIP archive. Likewise, decrypted session recording files are restored as their original files and can be accessed directly.

Got it! Thanks for the information.

I have a couple of questions:

  1. If Session Backup is enabled in the senhasegura platform and the remote storage becomes full because it contains session recordings accumulated over several years, is it possible to identify and delete only the recordings that are older than one year (for example, based on their date)?
  2. In a scenario where a session recording has already been removed from the senhasegura GUI due to the configured purge policy, but a backup copy still exists in the remote storage, how can the customer view that session again? Would they need to use the AES Crypt tool to decrypt the backed-up recording, or is there another recommended method?

Is there any video document steps how to uses aescrypt tool and recontruct merge multiple guardians master key and use is aescrypt tool ?

Hi,

1-You have to do it manually on the remote server.
2-Yes, you need to decrypt using AES Crypt.