Skip to content

Commit a9a1888

Browse files
committed
reactor: consolidate encryption troubleshooting into enc. chapter
Signed-off-by: Josh <josh.t.richards@gmail.com>
1 parent 1f36994 commit a9a1888

1 file changed

Lines changed: 4 additions & 52 deletions

File tree

admin_manual/issues/general_troubleshooting.rst

Lines changed: 4 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -429,59 +429,11 @@ You can run the following SQL query to reset those after **backing up the databa
429429
430430
UPDATE oc_filecache SET unencrypted_size=0 WHERE encrypted=0;
431431
432-
Troubleshooting downloading or decrypting files
433-
-----------------------------------------------
432+
Troubleshooting encrypted files
433+
-------------------------------
434434

435-
Bad signature error
436-
^^^^^^^^^^^^^^^^^^^
437-
438-
In some rare cases it can happen that encrypted files cannot be downloaded
439-
and return a "500 Internal Server Error". If the Nextcloud log contains an error about
440-
"Bad Signature", then the following command can be used to repair affected files::
441-
442-
occ encryption:fix-encrypted-version userId --path=/path/to/broken/file.txt
443-
444-
Replace "userId" and the path accordingly.
445-
The command will do a test decryption for all files and automatically repair the ones with a signature error.
446-
447-
.. _troubleshooting_encryption_key_not_found:
448-
449-
Encryption key cannot be found
450-
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
451-
452-
If the logs contain an error stating that the encryption key cannot be found, you can manually search the data directory for a folder that has the same name as the file name.
453-
For example if a file "example.md" cannot be decrypted, run::
454-
455-
find path/to/datadir -name example.md -type d
456-
457-
Then check the results located in the ``files_encryption`` folder.
458-
If the key folder is in the wrong location, you can move it to the correct folder and try again.
459-
460-
The ``data/files_encryption`` folder contains encryption keys for group folders and system-wide external storages
461-
while ``data/$userid/files_encryption`` contains the keys for specific user storage files.
462-
463-
.. note::
464-
465-
This can happen if encryption was disabled at some point but the :ref:`occ command for decrypt-all<occ_disable_encryption_label>` was not run, and
466-
then someone moved the files to another location. Since encryption was disabled, the keys did not get moved.
467-
468-
Encryption key cannot be found with external storage or group folders
469-
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
470-
471-
To resolve this issue, please run the following command::
472-
473-
sudo -E -u www-data php occ encryption:fix-key-location <user-id>
474-
475-
This will attempt to recover keys that were not moved properly.
476-
477-
If this doesn't resolve the problem, please refer to the section :ref:`Encryption key cannot be found<troubleshooting_encryption_key_not_found>` for a manual procedure.
478-
479-
.. note::
480-
481-
There were two known issues where:
482-
483-
- moving files between an encrypted and non-encrypted storage like external storage or group folder `would not move the keys with the files <https://github.com/nextcloud/groupfolders/issues/1896>`_.
484-
- putting files on system-wide external storage would store the keys in the `wrong location <https://github.com/nextcloud/server/pull/32690>`_.
435+
.. tip::
436+
Please also refer to the troubleshooting section in the encryption chapter: :doc:`../configuration_files/encryption_configuration`.
485437

486438
Fair Use Policy
487439
---------------

0 commit comments

Comments
 (0)