# \[solved\] Can't access data after enabling encryption

**URL:** <https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124>\
**Category:** Pydio Cells\
**Tags:** s3\
**Created:** [March 3, 2020, 6:42pm UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124 "2020-03-03T18:42:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![drzraf](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/drzraf/32/1207_2.png) [@drzraf](https://forum.pydio.com/u/drzraf)\
**Post date:** [March 3, 2020, 6:42pm UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/1 "2020-03-03T18:42:57Z")

</div>

I enabled encryption for my existing instance.

 ![Screenshot from 2020-03-03 15-24-51](https://canada1.discourse-cdn.com/flex032/uploads/pydio/original/2X/9/925becd848b281eeb4be127903d5e87a23236bfd.png)

and enabled it.

 ![Screenshot from 2020-03-03 15-28-33](https://canada1.discourse-cdn.com/flex032/uploads/pydio/original/2X/a/a1a431224ccc1e710ffa40927ae36ac747dc4bad.png)

Once done, I clicked “Re-synchronize” and tried to browse files…  
I can still see them, their metadata and enter directories, but none can be opened/downloaded.

This is a typical request…

`https://domain/io/common-files/test.rtf?AWSAccessKeyId=gateway&Expires=1583260083&Signature=It%2B8%2FpIj00wiaj9U7jULDHUgMds%3D&response-content-disposition=attachment%3B%20filename%3Dtest.rtf&pydio_jwt=xxxxx`

… but the HTTP response is an empty **500** (`content-type: application/xml` and `content-disposition: attachment; filename=test.rtf`)

In `cells` output I can see the following corresponding to this download request:

`ERROR pydio.gateway.data views.handler.encryption.GetObject: failed to get node info {"error": "{\"id\":\"node.key.dao\",\"code\":404,\"detail\":\"no entry for 0aebf3b7-5bc6-42ce-b60f-7eae39eb391b key\",\"status\":\"Not Found\"}"}`

When using `openstack object save pydio test.rtf` I can get the unencrypted file, meaning that:

- Files are not encrypted in the storage backend
- File are unavailable from Pydio

Ironically: this is the opposite of what was initially intended when enabling encryption :S

_Erase and restart_ is obviously not an option for a -production instance, neither is _disabling encryption_ since it’s advertised to render unreadable all data.  
By chance, it’s still a sandbox, but it’s still sufficiently worrying and distrust-prone that I should ask:  
How would I save myself in such a situation?

---

<div class="post-metadata">

**Author:** ![drzraf](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/drzraf/32/1207_2.png) [@drzraf](https://forum.pydio.com/u/drzraf)\
**Post date:** [March 5, 2020, 1:49pm UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/2 "2020-03-05T13:49:48Z")

</div>

Full trace about the `unencrypted` failing to be accessed by `pydio`:

```auto
2020-03-05T13:39:16.162Z	DEBUG	pydio.grpc.tree	ReadNode	{"time": "3.681485ms", "req": "Node:<Path:\"ovh/test.rtf\" MetaStore:<key:\"pydio:meta-data-source-path\" value:\"\\\"test.rtf\\\"\" > > ", "resp": "Node:<Uuid:\"0aebf3b7-5bc6-42ce-b60f-7eae39eb391b\" Path:\"ovh/test.rtf\" Type:LEAF Size:1735 MTime:1582669603 Mode:511 Etag:\"9b97a0f7a45712637d9883c0477618c1\" MetaStore:<key:\"name\" value:\"\\\"test.rtf\\\"\" > MetaStore:<key:\"pydio:meta-data-source-name\" value:\"\\\"ovh\\\"\" > MetaStore:<key:\"pydio:meta-data-source-path\" value:\"\\\"test.rtf\\\"\" > > "}
2020-03-05T13:39:16.268Z	ERROR	pydio.gateway.data	views.handler.encryption.GetObject: failed to get node info	{"error": "{\"id\":\"node.key.dao\",\"code\":404,\"detail\":\"no entry for 0aebf3b7-5bc6-42ce-b60f-7eae39eb391b key\",\"status\":\"Not Found\"}"}
github.com/pydio/cells/common/views.(*EncryptionHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-encryption.go:99
github.com/pydio/cells/common/views.(*AbstractHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-abstract.go:131
github.com/pydio/cells/common/views.(*AbstractHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-abstract.go:131
github.com/pydio/cells/common/views.(*AbstractHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-abstract.go:131
github.com/pydio/cells/common/views.(*AbstractHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-abstract.go:131
github.com/pydio/cells/common/views.(*HandlerEventRead).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-events-read.go:95
github.com/pydio/cells/common/views.(*AclFilterHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-acl-filter.go:197
github.com/pydio/cells/common/views.(*HandlerAuditEvent).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-audit-events.go:47
github.com/pydio/cells/common/views.(*AbstractBranchFilter).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-path-abstract-filter.go:300
github.com/pydio/cells/common/views.(*AbstractBranchFilter).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-path-abstract-filter.go:300
github.com/pydio/cells/common/views.(*AbstractBranchFilter).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-path-abstract-filter.go:300
github.com/pydio/cells/common/views.(*AbstractBranchFilter).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-path-abstract-filter.go:300
github.com/pydio/cells/common/views.(*AbstractBranchFilter).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-path-abstract-filter.go:300
github.com/pydio/cells/common/views.(*ArchiveHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-archive.go:86
github.com/pydio/cells/common/views.(*BinaryStoreHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-binary-store.go:120
github.com/pydio/cells/common/views.(*BinaryStoreHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-binary-store.go:120
github.com/pydio/cells/common/views.(*AbstractHandler).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/handler-abstract.go:131
github.com/pydio/cells/common/views.(*Router).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/common/views/router.go:201
github.com/pydio/cells/vendor/github.com/pydio/minio-srv/cmd/gateway/pydio.(*pydioObjects).GetObject
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/vendor/github.com/pydio/minio-srv/cmd/gateway/pydio/gateway-pydio.go:313
github.com/pydio/cells/vendor/github.com/pydio/minio-srv/cmd/gateway/pydio.(*pydioObjects).GetObjectNInfo.func1
	/opt/teamcity/agent/work/fb9e7e7133d45375/go/src/github.com/pydio/cells/vendor/github.com/pydio/minio-srv/cmd/gateway/pydio/gateway-pydio.go:293

```

If I pass the warning message of encryption disabling, then I can access back existing file that where created unencrypted.

That means unencrypted and encrypted files can coexist inside Pydio, but Pydio seems not to track which one is using encryption and which isn’t. I think that, _at least_ some kind encryption icon should appear in the UI to help user distinguish this and that an error message should be triggered instead of nothing.

---

<div class="post-metadata">

**Author:** ![zayn](https://avatars.discourse-cdn.com/v4/letter/z/a87d85/32.png) [@zayn](https://forum.pydio.com/u/zayn)\
**Post date:** [March 9, 2020, 8:07am UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/3 "2020-03-09T08:07:53Z")

</div>

Hello @drzraf,

I assume that you already had data on that bucket before encryption?  
In that case it will not work, we do not encrypt the resources that already exists.

You must have an empty bucket, then create your encrypted datasource, after that you can move your resources to it.

Could you try and tell me if that is working for you.

---

<div class="post-metadata">

**Author:** ![drzraf](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/drzraf/32/1207_2.png) [@drzraf](https://forum.pydio.com/u/drzraf)\
**Post date:** [March 9, 2020, 4:10pm UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/4 "2020-03-09T16:10:23Z")

</div>

That’s it and replies to my question.  
But I’m not sure the behavior is the best one.

> At _least_ some kind encryption icon should appear in the UI to help user distinguish this and that an error message should be triggered instead of nothing.

---

<div class="post-metadata">

**Author:** ![zayn](https://avatars.discourse-cdn.com/v4/letter/z/a87d85/32.png) [@zayn](https://forum.pydio.com/u/zayn)\
**Post date:** [March 10, 2020, 7:43am UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/5 "2020-03-10T07:43:10Z")

</div>

I"ll add an entry in our backlog for that, it could be good to have an indicator on what is encrypted or not.

---

<div class="post-metadata">

**Author:** ![zayn](https://avatars.discourse-cdn.com/v4/letter/z/a87d85/32.png) [@zayn](https://forum.pydio.com/u/zayn)\
**Post date:** [March 10, 2020, 7:43am UTC](https://forum.pydio.com/t/solved-cant-access-data-after-enabling-encryption/3124/6 "2020-03-10T07:43:46Z")

</div>


