# Format of --encryption-key-file for fdbbackup/fdbrestore

**URL:** https://forums.foundationdb.org/t/format-of-encryption-key-file-for-fdbbackup-fdbrestore/3767
**Category:** Running FoundationDB
**Created:** [January 27, 2023, 3:43pm UTC](https://forums.foundationdb.org/t/format-of-encryption-key-file-for-fdbbackup-fdbrestore/3767 "2023-01-27T15:43:41Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![pwood](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/pwood/32/1653_2.png) [@pwood](https://forums.foundationdb.org/u/pwood)
#### Post date: [January 27, 2023, 3:43pm UTC](https://forums.foundationdb.org/t/format-of-encryption-key-file-for-fdbbackup-fdbrestore/3767/1 "2023-01-27T15:43:41Z")

</div>

Hey folks,

Hopefully a quick one, I’m just looking for confirmation. We’re looking to use FDB’s encryption at rest facilities for backups, `--encryption-key-file`.

However I’m not finding any reference in the documentation to the format of the file, the help says:  
`--encryption-key-file The AES-128-GCM key in the provided file is used for encrypting backup files.`

So my educated guess is a file with 16 bytes of random data, generated with `openssl rand 16` or similar.

I’m happy to just try it, but I’m of course cautious when it comes to backups. 😃 Can anyone confirm?

P.
