Files
duplicati/Duplicati/Library/Encryption
Kenneth Skovhede e98c48e078 Update SharpAESCrypt to v3
This PR updates SharpAESCrypt to version 3.0.0.

With this change the written format for encrypted fields in the database and the remote encrypted files will be changed to Stream Format v3, which improves the key deriviation function and includes additional safeguards regarding content length.

The library still supports reading v2 files, but will write all new files as v3.

Environment variables, as well as module options, can toggle this behavior.

# Environment variable overview
- `DUPLICATI__AES_VERSION`: The file format version, either 3 (default) or 2
-`DUPLICATI__AES_V3_ITERATIONS`: The number of Pbkdf iterations to apply (default 300k)
- `DUPLICATI__AES_MINIMAL_HEADER`: Writes AES files with a minimal header (saves ~100 bytes per file)
- `DUPLICATI__AES_IGNORE_PADDING_BYTES`: Legacy setting for reading files written by the mainline AESCrypt tool

# A note on iterations
The iterations protect a weak key by adding additional computational overhead, but only adds overhead if the key is already providing at least 256 bits of high entropy.

For low-power devices, such as 32-bit RPI, this can be set as low as 10k, which will lower encryption and decryption time.  Beware that setting a low iteration count reduces security if the key is not sufficiently strong.
2026-03-13 17:20:33 +01:00
..
2026-03-13 17:20:33 +01:00
2026-03-02 12:57:29 +01:00
2026-03-13 17:20:33 +01:00