Backing up and restoring Workstations#
Qubes OS has a backup utility that allows for backup and restoration of user-specified qubes and templates.
Warning
Backups contain sensitive data, and must be created and stored just as securely as SecureDrop Workstation laptops.
To perform backups, you will need:
a LUKS-encrypted USB flash or external hard drive (of sufficient size, if backing up additional local data)
a secure place to store backup credentials (such as a password manager on your primary laptop)
SecureDrop Workstation requires only that you back up instance-specific secrets and configuration files, although you can optionally back up some additional local data.
When backing up SecureDrop Workstation, there are three distinct sets of data you can back up:
The Submission Private Key and SecureDrop Workstation config in
dom0(required)The messages and files from SecureDrop Inbox stored in
sd-app(optional)If you skip this step, all previous messages exchanged between Sources and Journalists, as well as any submitted files you have downloaded, will not be included in the backup. The first time you log in on a restored SecureDrop Workstation, everything will need to be re-downloaded from your SecureDrop server.
This option is only recommended when performing a migration to a new SecureDrop Workstation installation (not for long-term storage).
Other customizations beyond the standard SecureDrop Workstation configuration provided by Freedom of the Press Foundation (optional)
These may include additional qubes and their templates, custom RPC policies, etc.
If you have additional customizations you wish to back up, we suggest capturing that as a separate backup without the Submission Private Key, SecureDrop Workstation config file, or any messages and files from SecureDrop Inbox so that you can avoid proliferating copies of sensitive assets.
Backup#
Back up a Journalist Workstation#
Note
Before starting your backup, decide whether you want to back up your data from sd-app, noting the caveats listed above.
Preserve files from dom0 and sd-gpg#
Preserve configuration files and private key material by copying them into dom0.
In a dom0 terminal opened via
▸
▸ Other Tools ▸ Xfce Terminal:
qvm-run --pass-io sd-gpg 'gpg -a --export-secret-keys' > sd-keys.asc
mv sd-keys.asc ~/.config/securedrop-manage/
If you have made customizations to dom0 (for example, custom RPC policy files):
mkdir ~/etc-qubes && cp -r /etc/qubes ~/etc-qubes
mkdir ~/etc-qubes-rpc && cp -r /etc/qubes-rpc ~/etc-qubes-rpc
Select qubes to back up#
Ensure your storage medium is plugged in, attached to sd-devices, and unlocked.
Navigate to
▸
▸ Qubes Tools ▸ Backup Qubes, and move all qubes from Selected to Available by pressing the << button.
To target a qube for backup, highlight it and move it into the Selected column by pressing the > button. Select:
dom0the
sd-appqube (optional)any customized qubes that you may wish to preserve, and their templates (optional)
If your Journalist Workstation also functions as an Admin Workstation, make sure to also select:
the
sd-adminqubethe
sd-vaultqube
You do not need to back up the other sd- qubes.
Perform the backup#
Click Next, and in Backup destination, specify the sd-devices qube and directory corresponding to your storage medium’s current mount point.
Set a strong, unique backup encryption passphrase (7-word diceware), and ensure this passphrase is stored securely outside SecureDrop Workstation.
Note
This passphrase protects sensitive components of your SecureDrop instance, including the Submission Private Key, and unencrypted submissions (if sd-app is backed up). Ensure it is a very strong password and is stored securely.
Uncheck save backup profile, then proceed with the backup.
Back up an Admin Workstation#
The process for backing up an Admin Workstation is similar to the process for a Journalist Workstation, although here there are fewer sensitive assets that are copied.
To perform a backup of the Admin Workstation:
Back up the sd-admin qube#
Ensure your storage medium is plugged in, attached to sd-devices, and unlocked.
Navigate to
▸
▸ Qubes Tools ▸ Backup Qubes, and move all qubes from Selected to Available by pressing the << button.
Highlight the sd-admin and sd-vault qubes, then move them into the Selected column by pressing the > button. You do not need to back up the other sd- qubes.
Click Next, then select the backup destination, set the encryption passphrase, and uncheck save backup profile as described previously in Perform the backup, then proceed with the backup.
Verify the backup#
Qubes OS recommends verifying the integrity of the backup once the backup completes, and this should be done on the same machine where the backup was created. This can be done by using the Restore Backup GUI tool and selecting Test restore to verify backup integrity (no data actually restored). For details, see the Qubes OS backup documentation.
Warning
Any files or data not mentioned above and not backed up elsewhere are at risk of being lost or destroyed. Ensure that any other data on your system (for example, using KeepassXC in the vault qube, or data stored in other qubes) have been backed up and the integrity of the backup has been verified.
Restore#
Reinstall Qubes OS#
To restore SecureDrop Workstation, follow our pre-install tasks to provision a Qubes OS system complete with updated base templates, and download the SecureDrop Workstation packages.
Rename or delete redundant app qubes#
By default, Qubes OS will create the app qubes personal, work, untrusted and vault as part of the installation process. Rename or delete any of these newly created app qubes whose names conflict with the app qubes you intend to restore from a backup.
Example: If you wish to restore the vault qube, rename or delete the existing vault qube prior to restoring the backup. You can do so in
▸ Apps ▸ vault ▸ Settings (the qube must not be running).
Restore backup (SecureDrop Workstation components)#
Note
If you are migrating from one machine to another or from one version of Qubes OS to another, we suggest you wipe (reformat) or destroy the drive after you have successfully restored it onto the new machine (which should ideally happen the same day). In all cases, follow your organization’s internal policies on handling sensitive assets and information.
Plug in your backup medium, attach it to the sys-usb qube, and unlock it using the same process as during the backup.
Navigate to
▸
▸ Qubes Tools ▸ Restore Backup, and enter the location of the backup file. You do not need to adjust the default Restore options, unless you have made customizations to the backup. Enter the decryption/verification passphrase, and proceed to restoring the available qubes.
If you are restoring a Journalist Workstation, you should ensure you restore:
dom0sd-app(optional)
If you are restoring an Admin Workstation, you should ensure you restore:
sd-adminsd-vault
If you are using a combination Journalist and Admin Workstation, restore all items listed above.
We suggest restoring only those qubes, provisioning SecureDrop Workstation, and then restoring any customized qubes you may have had once that process is complete. This way SecureDrop Workstation is provisioned on a clean system and can implement the security measures it requires before any additional qubes are configured.
Note
When migrating to a newer version of Qubes OS (for example, Qubes 4.1 to Qubes 4.2), you may notice that the original templates for certain qubes are not present on your new machine. For the purposes of this guide (optional sd-app backup), this is not a problem. Allow the qube to be restored with the default template suggested by the operating system (the current Fedora base template). Do not start the qube. Continue through the reinstallation process. The correct template will be configured as you follow the rest of these instructions.
If you are restoring your own customized qubes and templates, you will need to take additional steps. You may decide to create new templates for your custom qubes and provision them with the necessary applications/customizations (recommended), or you may upgrade your existing templates following the upstream documentation (Fedora templates, Debian templates), then upgrade their package repositories to the Qubes 4.2 repositories using:
sudo qubes-dom0-update -y qubes-dist-upgrade qubes-dist-upgrade --template-standalone --upgrade
More information can be found in the upstream documentation. Contact Support with any questions.
Reinstall SecureDrop Workstation#
Retrieve the previous SecureDrop Workstation configuration from the backup folder on dom0. From the dom0 home directory:
ls -d */*/* | grep home-restore
You should see a directory called home-restore-$YYYY-MM-DD-HHMMSS/dom0-home/$USERNAME. We will call this $RESTORE_DIR in the instructions below.
cp ~/$RESTORE_DIR/securedrop-workstation-dom0-config/{sd-journalist.sec,config.json,sd-keys.asc} ~/.config/securedrop-manage/
Optionally, inspect each file before proceeding. The first file should be an ASCII-armored GPG private key file. The second file should follow the format of the example configuration file, with values for its fields (e.g., hostname, submission_key_fpr) specific to your configuration. The file may be formatted in a single line without whitespace. The third file is a backup of key material from sd-gpg and will be moved into that qube when you have reprovisioned the system.
Verify that the configuration is valid:
sdw-admin --validate
If the above command prints OK, the configuration is valid.
Reinstall SecureDrop Workstation:
sdw-admin --apply
Restore additional keys to sd-gpg#
If you are using a Journalist Workstation and have multiple Submission Keys, perform the following commands from a dom0 terminal:
qvm-copy-to-vm sd-gpg $RESTORE_DIR/securedrop-workstation-dom0-config/sd-keys.asc
qvm-run sd-gpg 'gpg --import /home/user/QubesIncoming/dom0/sd-keys.asc'
Restore customized qubes, RPC policies#
At this stage, you should have a functional SecureDrop Workstation. You may restore any additional customizations or additional qubes, being mindful that you are responsible for the security implications of customizing this system.
Customizations in dom0 must be restored manually, meaning that any RPC policies you have added will need to be moved into place from the $RESTORE_DIR.
Once you are finished with the $RESTORE_DIR and have verified that your system works (download, decrypt, sync), you may delete the $RESTORE_DIR.
(Post-migration instructions) Destroy backup medium#
Wipe (reformat) the LUKS-encrypted storage device that you used to store SecureDrop Workstation configuration material, overwriting the LUKS header and all data with a new encrypted partition, or physically destroy the backup medium, to ensure you are not proliferating copies of sensitive data.