mirror of
https://github.com/raspiblitz/raspiblitz.git
synced 2025-09-25 11:13:12 +02:00
LND behind TOR
This commit is contained in:
@@ -198,7 +198,14 @@ cat > ./getpublicip.sh <<EOF
|
||||
echo 'getpublicip.sh started, writing public IP address every 10 minutes into /run/publicip'
|
||||
while [ 0 ];
|
||||
do
|
||||
printf "PUBLICIP=\$(curl -vv ipinfo.io/ip 2> /run/publicip.log)\n" > /run/publicip;
|
||||
torExists=$(sudo ls /mnt/hdd/tor/lnd9735/hostname 2>/dev/null | grep hostname -c)
|
||||
if [ ${torExists} -eq 1 ]; then
|
||||
# use tor onion address
|
||||
printf "PUBLICIP=$(sudo cat /mnt/hdd/tor/lnd9735/hostname)\n" > /run/publicip;
|
||||
else
|
||||
# get public IP
|
||||
printf "PUBLICIP=$(curl -vv ipinfo.io/ip 2> /run/publicip.log)\n" > /run/publicip;
|
||||
fi
|
||||
sleep 600
|
||||
done;
|
||||
EOF
|
||||
|
@@ -28,7 +28,7 @@ fi
|
||||
name="Download"
|
||||
targetDir="/mnt/hdd/download/"
|
||||
targetSize=$size
|
||||
maxTimeoutLoops=500
|
||||
maxTimeoutLoops=10000
|
||||
command="sudo wget -c -r -P ${targetDir} -q --show-progress ${url}"
|
||||
|
||||
# starting session if needed
|
||||
|
@@ -45,126 +45,18 @@ echo "*** Updating System ***"
|
||||
sudo apt-get update
|
||||
echo ""
|
||||
|
||||
echo "*** Install Tor & Config ***"
|
||||
echo "*** Install Tor ***"
|
||||
sudo apt install tor tor-arm -y
|
||||
echo "uncommenting #RunAsDaemon 1"
|
||||
sudo sed -i "s/^#RunAsDaemon 1/RunAsDaemon 1/g" $torrc
|
||||
echo "adding PortForward 1 & ControlPort 9051 after RunAsDaemon 1"
|
||||
sudo sed -i '\|RunAsDaemon 1| {N;s|\n$|\nPortForwarding 1\nControlPort 9051\n|}' $torrc
|
||||
echo "uncommenting #CookieAuthentication 1"
|
||||
sudo sed -i "s/^#CookieAuthentication 1/CookieAuthentication 1/g" $torrc
|
||||
echo "adding CookieAuthFileGroupReadable 1 after CookieAuthentication 1"
|
||||
sudo sed -i '\|CookieAuthentication 1| {N;s|\n$|\nCookieAuthFileGroupReadable 1\n|}' $torrc
|
||||
echo "*** enabling logs of tor to /var/log/tor/notices.log ***"
|
||||
sudo sed -i "s/^#Log notice file/Log notice file/g" $torrc
|
||||
echo "OK - configured tor"
|
||||
|
||||
echo ""
|
||||
|
||||
# NYX - Tor monitor tool
|
||||
# https://nyx.torproject.org/#home
|
||||
echo "*** Installing NYX - TOR monitoring Tool ***"
|
||||
sudo pip install nyx
|
||||
echo ""
|
||||
|
||||
echo "*** Changing ${network} Config ***"
|
||||
echo "Only Connect thru TOR"
|
||||
echo "onlynet=onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "Adding some nodes to connect to"
|
||||
echo "addnode=fno4aakpl6sg6y47.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=toguvy5upyuctudx.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=ndndword5lpb7eex.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=6m2iqgnqjxh7ulyk.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=5tuxetn7tar3q5kp.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf
|
||||
sudo chown admin:admin /home/admin/.${network}/${network}.conf
|
||||
echo ""
|
||||
|
||||
#echo "*** Changing LND Config ***"
|
||||
#echo "tor.active" | sudo tee --append /home/bitcoin/.lnd/lnd.conf
|
||||
#echo "tor.streamisolation" | sudo tee --append /home/bitcoin/.lnd/lnd.conf
|
||||
#echo "tor.v2" | sudo tee --append /home/bitcoin/.lnd/lnd.conf
|
||||
#echo "tor.privatekeypath=/home/bitcoin/.bitcoin/onion_private_key" | sudo tee --append /home/bitcoin/.lnd/lnd.conf
|
||||
#sudo cp /home/bitcoin/.lnd/lnd.conf /home/admin/.lnd/lnd.conf
|
||||
#sudo chown admin:admin /home/admin/.lnd/lnd.conf
|
||||
#echo "OK"
|
||||
#echo ""
|
||||
|
||||
echo "*** Activating TOR system service ***"
|
||||
sudo systemctl restart tor@default
|
||||
echo ""
|
||||
|
||||
echo "*** Setting Permissions ***"
|
||||
# so that Bitcoind can create Tor hidden service
|
||||
echo "setting bitcoind permissions"
|
||||
sudo usermod -a -G debian-tor bitcoin
|
||||
# so that you can run `arm` as user
|
||||
echo "setting pi permissions"
|
||||
sudo usermod -a -G debian-tor pi
|
||||
|
||||
echo "*** Waiting for TOR to boostrap ***"
|
||||
torIsBootstrapped=0
|
||||
while [ ${torIsBootstrapped} -eq 0 ]
|
||||
do
|
||||
echo "--- Checking ---"
|
||||
date +%s
|
||||
sudo cat /var/log/tor/notices.log | grep "Bootstrapped" | tail -n 10
|
||||
torIsBootstrapped=$(sudo cat /var/log/tor/notices.log | grep "Bootstrapped 100" -c)
|
||||
echo "torIsBootstrapped(${torIsBootstrapped})"
|
||||
echo "If this takes too long --> CTRL+c, reboot and check manually"
|
||||
sleep 5
|
||||
done
|
||||
echo "OK - Tor Bootstrap is ready"
|
||||
echo ""
|
||||
|
||||
echo "*** ${network} re-init - Waiting for Onion Address ***"
|
||||
# restarting bitcoind to start with tor and generare onion.address
|
||||
echo "restarting ${network}d ..."
|
||||
sudo systemctl restart ${network}d
|
||||
sleep 8
|
||||
onionAddress=""
|
||||
while [ ${#onionAddress} -eq 0 ]
|
||||
echo "--- Checking ---"
|
||||
date +%s
|
||||
sudo cat /mnt/hdd/${network}/debug.log | grep "tor" | tail -n 10
|
||||
onionAddress=$(${network}-cli getnetworkinfo | grep '"address"' | cut -d '"' -f4)
|
||||
echo "If this takes too long --> CTRL+c, reboot and check manually"
|
||||
sleep 5
|
||||
do
|
||||
echo ""
|
||||
|
||||
|
||||
echo "*** Setting your Onion Address ***"
|
||||
onionPort=$(${network}-cli getnetworkinfo | grep '"port"' | tr -dc '0-9')
|
||||
echo "Your Onion Address is: ${onionAddress}:${onionPort}"
|
||||
echo "TODO: Make LND reachable over TOR when compiled for ARM with TOR support"
|
||||
|
||||
# ACTIVATE LND OVER TOR LATER ... see DEV NOTES AT END OF FILE
|
||||
sudo systemctl disable lnd
|
||||
echo "Writing Public Onion Address to /run/publicip"
|
||||
echo "PUBLICIP=${onionAddress}" | sudo tee /run/publicip
|
||||
sed -i "5s/.*/Wants=${network}d.service/" ./assets/lnd.tor.service
|
||||
sed -i "6s/.*/After=${network}d.service/" ./assets/lnd.tor.service
|
||||
sudo cp /home/admin/assets/lnd.tor.service /etc/systemd/system/lnd.service
|
||||
sudo chmod +x /etc/systemd/system/lnd.service
|
||||
sudo systemctl enable lnd
|
||||
echo "OK"
|
||||
|
||||
|
||||
echo "*** Finshing Setup / REBOOT ***"
|
||||
echo "OK - all should be set"
|
||||
echo ""
|
||||
echo "PRESS ENTER ... to REBOOT"
|
||||
read key
|
||||
|
||||
sudo shutdown -r now
|
||||
exit 0
|
||||
|
||||
DEV NOTES ---> maybe use this /etc/tor/torrc to have all toor config on HDD
|
||||
--> needs /mnt/hdd/tor & with dirs: sys, lnd9735, web80
|
||||
--> all with chown debian-tor:debian-tor & chmod 700
|
||||
--> update getpublicip script to use if available: cat /mnt/hdd/tor/lnd9735/hostname
|
||||
--> Above activate LND tor service when LND is compiled for ARM with TOR service
|
||||
|
||||
echo "*** Tor Config ***"
|
||||
sudo mkdir /mnt/hdd/tor
|
||||
sudo mkdir /mnt/hdd/tor/sys
|
||||
sudo mkdir /mnt/hdd/tor/web80
|
||||
sudo mkdir /mnt/hdd/tor/lnd9735
|
||||
sudo chmod -R 700 /mnt/hdd/tor
|
||||
sudo chown -R debian-tor:debian-tor /mnt/hdd/tor
|
||||
cat > ./torrc <<EOF
|
||||
### See 'man tor', or https://www.torproject.org/docs/tor-manual.html
|
||||
|
||||
DataDirectory /mnt/hdd/tor/sys
|
||||
@@ -194,4 +86,99 @@ HiddenServiceDir /mnt/hdd/tor/lnd9735
|
||||
HiddenServiceVersion 3
|
||||
HiddenServicePort 9735 127.0.0.1:9735
|
||||
|
||||
# NOTE: bitcoind get tor service automatically - see /mnt/hdd/bitcoin for onion key
|
||||
# NOTE: bitcoind get tor service automatically - see /mnt/hdd/bitcoin for onion key
|
||||
EOF
|
||||
sudo rm $torrc
|
||||
sudo mv ./torrc $torrc
|
||||
sudo chmod 644 $torrc
|
||||
echo ""
|
||||
|
||||
# NYX - Tor monitor tool
|
||||
# https://nyx.torproject.org/#home
|
||||
echo "*** Installing NYX - TOR monitoring Tool ***"
|
||||
sudo pip install nyx
|
||||
echo ""
|
||||
|
||||
echo "*** Changing ${network} Config ***"
|
||||
echo "Only Connect thru TOR"
|
||||
echo "onlynet=onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "Adding some nodes to connect to"
|
||||
echo "addnode=fno4aakpl6sg6y47.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=toguvy5upyuctudx.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=ndndword5lpb7eex.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=6m2iqgnqjxh7ulyk.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
echo "addnode=5tuxetn7tar3q5kp.onion" | sudo tee --append /home/bitcoin/.${network}/${network}.conf
|
||||
sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf
|
||||
sudo chown admin:admin /home/admin/.${network}/${network}.conf
|
||||
echo ""
|
||||
|
||||
echo "*** Activating TOR system service ***"
|
||||
sudo systemctl restart tor@default
|
||||
echo ""
|
||||
|
||||
echo "*** Setting Permissions ***"
|
||||
# so that chain network can create Tor hidden service
|
||||
echo "setting bitcoind permissions"
|
||||
sudo usermod -a -G debian-tor bitcoin
|
||||
# so that you can run `arm` as user
|
||||
echo "setting pi permissions"
|
||||
sudo usermod -a -G debian-tor pi
|
||||
|
||||
echo "*** Waiting for TOR to boostrap ***"
|
||||
torIsBootstrapped=0
|
||||
while [ ${torIsBootstrapped} -eq 0 ]
|
||||
do
|
||||
echo "--- Checking ---"
|
||||
date +%s
|
||||
sudo cat /var/log/tor/notices.log | grep "Bootstrapped" | tail -n 10
|
||||
torIsBootstrapped=$(sudo cat /var/log/tor/notices.log | grep "Bootstrapped 100" -c)
|
||||
echo "torIsBootstrapped(${torIsBootstrapped})"
|
||||
echo "If this takes too long --> CTRL+c, reboot and check manually"
|
||||
sleep 5
|
||||
done
|
||||
echo "OK - Tor Bootstrap is ready"
|
||||
echo ""
|
||||
|
||||
echo "*** ${network} re-init - Waiting for Onion Address ***"
|
||||
# restarting bitcoind to start with tor and generare onion.address
|
||||
echo "restarting ${network}d ..."
|
||||
sudo systemctl restart ${network}d
|
||||
sleep 8
|
||||
onionAddress=""
|
||||
while [ ${#onionAddress} -eq 0 ]
|
||||
do
|
||||
echo "--- Checking ---"
|
||||
date +%s
|
||||
sudo cat /mnt/hdd/${network}/debug.log | grep "tor" | tail -n 10
|
||||
onionAddress=$(${network}-cli getnetworkinfo | grep '"address"' | cut -d '"' -f4)
|
||||
echo "If this takes too long --> CTRL+c, reboot and check manually"
|
||||
sleep 5
|
||||
done
|
||||
echo ""
|
||||
|
||||
echo "*** Setting your Onion Address ***"
|
||||
onionPort=$(${network}-cli getnetworkinfo | grep '"port"' | tr -dc '0-9')
|
||||
echo "Your Chain Network Onion Address is: ${onionAddress}:${onionPort}"
|
||||
onionLND=$(sudo cat /mnt/hdd/tor/lnd9735/hostname)
|
||||
echo "Your Lightning Tor Onion Address is: ${onionLND}:9735"
|
||||
echo ""
|
||||
|
||||
# ACTIVATE LND OVER TOR LATER ... see DEV NOTES AT END OF FILE
|
||||
sudo systemctl disable lnd
|
||||
echo "Writing Public Onion Address to /run/publicip"
|
||||
printf "PUBLICIP=${onionLND}\n" > /run/publicip;
|
||||
sed -i "5s/.*/Wants=${network}d.service/" ./assets/lnd.tor.service
|
||||
sed -i "6s/.*/After=${network}d.service/" ./assets/lnd.tor.service
|
||||
sudo cp /home/admin/assets/lnd.tor.service /etc/systemd/system/lnd.service
|
||||
sudo chmod +x /etc/systemd/system/lnd.service
|
||||
sudo systemctl enable lnd
|
||||
echo "OK"
|
||||
|
||||
echo "*** Finshing Setup / REBOOT ***"
|
||||
echo "OK - all should be set"
|
||||
echo ""
|
||||
echo "PRESS ENTER ... to REBOOT"
|
||||
read key
|
||||
|
||||
sudo shutdown -r now
|
||||
exit 0
|
@@ -12,7 +12,7 @@ After=bitcoind.service
|
||||
# get var PUBIP from file
|
||||
EnvironmentFile=/run/publicip
|
||||
|
||||
ExecStart=/usr/local/gocode/bin/lnd --tor.active --tor.v2
|
||||
ExecStart=/usr/local/gocode/bin/lnd --tor.active --tor.v3 --externalip=${PUBLICIP} --listen=127.0.0.1:9735
|
||||
PIDFile=/home/bitcoin/.lnd/lnd.pid
|
||||
User=bitcoin
|
||||
Group=bitcoin
|
||||
|
Reference in New Issue
Block a user