raspiblitz/home.admin/config.scripts/internet.tor.sh

500 lines
16 KiB
Bash
Raw Normal View History

2018-12-02 19:52:01 +01:00
#!/bin/bash
# Background:
# https://medium.com/@lopp/how-to-run-bitcoin-as-a-tor-hidden-service-on-ubuntu-cff52d543756
# https://bitcoin.stackexchange.com/questions/70069/how-can-i-setup-bitcoin-to-be-anonymous-with-tor
# https://github.com/lightningnetwork/lnd/blob/master/docs/configuring_tor.md
# command info
if [ $# -eq 0 ] || [ "$1" = "-h" ] || [ "$1" = "-help" ]; then
echo "small config script to switch TOR on or off"
2020-11-15 22:16:13 +00:00
echo "internet.tor.sh [status|on|off|prepare|btcconf-on|btcconf-off|lndconf-on|update]"
2019-08-08 17:41:58 +02:00
exit 1
fi
torrc="/etc/tor/torrc"
2019-05-29 19:30:44 +01:00
baseImage="?"
isDietPi=$(uname -n | grep -c 'DietPi')
isRaspbian=$(cat /etc/os-release 2>/dev/null | grep -c 'Raspbian')
isArmbian=$(cat /etc/os-release 2>/dev/null | grep -c 'Debian')
isUbuntu=$(cat /etc/os-release 2>/dev/null | grep -c 'Ubuntu')
if [ ${isRaspbian} -gt 0 ]; then
baseImage="raspbian"
fi
if [ ${isArmbian} -gt 0 ]; then
baseImage="armbian"
fi
if [ ${isUbuntu} -gt 0 ]; then
baseImage="ubuntu"
fi
if [ ${isDietPi} -gt 0 ]; then
baseImage="dietpi"
fi
if [ "${baseImage}" = "?" ]; then
cat /etc/os-release 2>/dev/null
echo "# !!! FAIL !!!"
echo "# Base Image cannot be detected or is not supported."
echo "error='unknown os'"
2019-05-29 19:30:44 +01:00
exit 1
else
echo "os='${baseImage}'"
2019-05-29 19:30:44 +01:00
fi
2019-02-09 15:12:37 +01:00
# function: install keys & sources
prepareTorSources()
{
# Prepare for TOR service
2019-02-09 17:06:42 +01:00
echo "*** INSTALL TOR REPO ***"
echo ""
2019-02-09 15:12:37 +01:00
2019-02-09 17:06:42 +01:00
echo "*** Install dirmngr ***"
2019-02-09 16:41:48 +01:00
sudo apt install dirmngr -y
echo ""
2019-02-09 18:16:36 +01:00
echo "*** Adding KEYS deb.torproject.org ***"
torKeyAvailable=$(sudo gpg --list-keys | grep -c "A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89")
echo "torKeyAvailable=${torKeyAvailable}"
if [ ${torKeyAvailable} -eq 0 ]; then
curl https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | sudo gpg --import
sudo gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | sudo apt-key add -
echo "OK"
else
echo "TOR key is available"
fi
2019-02-09 15:12:37 +01:00
echo ""
echo "*** Adding Tor Sources to sources.list ***"
torSourceListAvailable=$(sudo cat /etc/apt/sources.list | grep -c 'https://deb.torproject.org/torproject.org')
echo "torSourceListAvailable=${torSourceListAvailable}"
if [ ${torSourceListAvailable} -eq 0 ]; then
echo "Adding TOR sources ..."
if [ "${baseImage}" = "raspbian" ] || [ "${baseImage}" = "armbian" ] || [ "${baseImage}" = "dietpi" ]; then
echo "deb https://deb.torproject.org/torproject.org buster main" | sudo tee -a /etc/apt/sources.list
echo "deb-src https://deb.torproject.org/torproject.org buster main" | sudo tee -a /etc/apt/sources.list
elif [ "${baseImage}" = "ubuntu" ]; then
echo "deb https://deb.torproject.org/torproject.org focal main" | sudo tee -a /etc/apt/sources.list
echo "deb-src https://deb.torproject.org/torproject.org focal main" | sudo tee -a /etc/apt/sources.list
fi
echo "OK"
else
echo "TOR sources are available"
2019-05-29 19:30:44 +01:00
fi
2019-02-09 15:12:37 +01:00
echo ""
}
2019-06-13 00:58:52 +02:00
activateBitcoinOverTOR()
{
echo "*** Changing ${network} Config ***"
btcExists=$(sudo ls /home/bitcoin/.${network}/${network}.conf | grep -c "${network}.conf")
if [ ${btcExists} -gt 0 ]; then
# make sure all is turned off and removed and then activate fresh (so that also old settings get removed)
deactivateBitcoinOverTOR
echo "Addding TOR config ..."
sudo chmod 777 /home/bitcoin/.${network}/${network}.conf
echo "onlynet=onion" >> /home/bitcoin/.${network}/${network}.conf
echo "proxy=127.0.0.1:9050" >> /home/bitcoin/.${network}/${network}.conf
echo "main.bind=127.0.0.1" >> /home/bitcoin/.${network}/${network}.conf
echo "test.bind=127.0.0.1" >> /home/bitcoin/.${network}/${network}.conf
echo "dnsseed=0" >> /home/bitcoin/.${network}/${network}.conf
echo "dns=0" >> /home/bitcoin/.${network}/${network}.conf
PASSWORD_B=$(sudo cat /mnt/hdd/${network}/${network}.conf | grep rpcpassword | cut -c 13-)
echo "torpassword=$PASSWORD_B" >> /home/bitcoin/.${network}/${network}.conf
if [ "${network}" = "bitcoin" ]; then
# adding some bitcoin onion nodes to connect to to make connection easier
echo "main.addnode=fno4aakpl6sg6y47.onion" >> /home/bitcoin/.${network}/${network}.conf
echo "main.addnode=toguvy5upyuctudx.onion" >> /home/bitcoin/.${network}/${network}.conf
echo "main.addnode=ndndword5lpb7eex.onion" >> /home/bitcoin/.${network}/${network}.conf
echo "main.addnode=6m2iqgnqjxh7ulyk.onion" >> /home/bitcoin/.${network}/${network}.conf
echo "main.addnode=5tuxetn7tar3q5kp.onion" >> /home/bitcoin/.${network}/${network}.conf
echo "main.addnode=juo4oneckybinerq.onion" >> /home/bitcoin/.${network}/${network}.conf
fi
sudo chmod 444 /home/bitcoin/.${network}/${network}.conf
# copy new bitcoin.conf to admin user for cli access
sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf
sudo chown admin:admin /home/admin/.${network}/${network}.conf
2019-06-13 00:58:52 +02:00
else
2019-08-08 17:41:58 +02:00
echo "BTC config does not found (yet) - try with 'internet.tor.sh btcconf-on' again later"
2019-06-13 00:58:52 +02:00
fi
}
2019-08-08 17:41:58 +02:00
deactivateBitcoinOverTOR()
{
# always make sure also to remove old settings
2019-08-08 17:41:58 +02:00
sudo sed -i "s/^onlynet=.*//g" /home/bitcoin/.${network}/${network}.conf
2020-09-28 21:26:04 +02:00
sudo sed -i "s/^torpassword=.*//g" /home/bitcoin/.${network}/${network}.conf
sudo sed -i "s/^main.addnode=.*//g" /home/bitcoin/.${network}/${network}.conf
sudo sed -i "s/^test.addnode=.*//g" /home/bitcoin/.${network}/${network}.conf
2019-11-23 17:19:09 +01:00
sudo sed -i "s/^proxy=.*//g" /home/bitcoin/.${network}/${network}.conf
sudo sed -i "s/^main.bind=.*//g" /home/bitcoin/.${network}/${network}.conf
sudo sed -i "s/^test.bind=.*//g" /home/bitcoin/.${network}/${network}.conf
2019-11-23 17:19:09 +01:00
sudo sed -i "s/^dnsseed=.*//g" /home/bitcoin/.${network}/${network}.conf
sudo sed -i "s/^dns=.*//g" /home/bitcoin/.${network}/${network}.conf
2019-08-08 17:41:58 +02:00
sudo sed -i '/^ *$/d' /home/bitcoin/.${network}/${network}.conf
sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf
sudo chown admin:admin /home/admin/.${network}/${network}.conf
}
2019-06-13 00:58:52 +02:00
activateLndOverTOR()
{
echo "*** Putting LND behind TOR ***"
lndExists=$(sudo ls /etc/systemd/system/lnd.service | grep -c "lnd.service")
if [ ${lndExists} -gt 0 ]; then
# modify LND service
echo "Make sure LND is disabled"
sudo systemctl disable lnd 2>/dev/null
echo "editing /etc/systemd/system/lnd.service"
2020-03-21 23:18:19 -07:00
sudo sed -i "s/^ExecStart=\/usr\/local\/bin\/lnd.*/ExecStart=\/usr\/local\/bin\/lnd --tor\.active --tor\.streamisolation --tor\.v3 --listen=127\.0\.0\.1\:9735 \${lndExtraParameter}/g" /etc/systemd/system/lnd.service
2020-09-28 21:26:04 +02:00
# check if "tor.password" exists
valueExists=$(sudo cat /mnt/hdd/lnd/lnd.conf | grep -c 'tor.password=')
if [ ${valueExists} -eq 0 ]; then
echo "Adding tor config defaults to /mnt/hdd/lnd/lnd.conf"
PASSWORD_B=$(sudo cat /mnt/hdd/${network}/${network}.conf | grep rpcpassword | cut -c 13-)
sudo -u bitcoin tee -a /mnt/hdd/lnd/lnd.conf >/dev/null <<EOF
[Tor]
tor.password=$PASSWORD_B
EOF
fi
2019-06-13 00:58:52 +02:00
echo "Enable LND again"
sudo systemctl enable lnd
echo "OK"
echo ""
else
2019-08-08 17:41:58 +02:00
echo "LND service not found (yet) - try with 'internet.tor.sh lndconf-on' again later"
2019-06-13 00:58:52 +02:00
fi
}
2019-02-09 15:12:37 +01:00
# if started with prepare
if [ "$1" = "prepare" ] || [ "$1" = "-prepare" ]; then
prepareTorSources
exit 0
fi
# check and load raspiblitz config
# to know which network is running
if [ -f "/home/admin/raspiblitz.info" ]; then
source /home/admin/raspiblitz.info
fi
if [ -f "/mnt/hdd/raspiblitz.conf" ]; then
source /mnt/hdd/raspiblitz.conf
fi
# make sure the network was set (by sourcing raspiblitz.conf)
if [ ${#network} -eq 0 ]; then
echo "FAIL - unknwon network due to missing /mnt/hdd/raspiblitz.conf"
exit 1
fi
# if started with status
if [ "$1" = "status" ]; then
# is Tor activated
if [ "${runBehindTor}" == "on" ]; then
echo "activated=1"
else
echo "activated=0"
fi
echo "config='${torrc}'"
exit 0
fi
# if started with btcconf-on
2019-08-08 17:41:58 +02:00
if [ "$1" = "btcconf-on" ]; then
2019-06-13 00:58:52 +02:00
activateBitcoinOverTOR
exit 0
fi
# if started with btcconf-off
2019-08-08 17:41:58 +02:00
if [ "$1" = "btcconf-off" ]; then
deactivateBitcoinOverTOR
2019-06-13 00:58:52 +02:00
exit 0
fi
# if started with lndconf-on
2019-08-08 17:41:58 +02:00
if [ "$1" = "lndconf-on" ]; then
activateLndOverTOR
exit 0
2018-12-02 19:52:01 +01:00
fi
2018-12-02 21:46:00 +01:00
# add default value to raspi config if needed
2019-08-07 01:49:17 +02:00
checkTorEntry=$(sudo cat /mnt/hdd/raspiblitz.conf | grep -c "runBehindTor")
if [ ${checkTorEntry} -eq 0 ]; then
2018-12-02 21:46:00 +01:00
echo "runBehindTor=off" >> /mnt/hdd/raspiblitz.conf
fi
2018-12-02 19:52:01 +01:00
# location of TOR config
2019-02-05 14:16:23 +00:00
# make sure /etc/tor exists
2019-02-10 16:55:41 +01:00
sudo mkdir /etc/tor 2>/dev/null
2018-12-02 19:52:01 +01:00
2020-11-15 22:16:13 +00:00
if [ "$1" != "update" ]; then
# stop services (if running)
echo "making sure services are not running"
sudo systemctl stop lnd 2>/dev/null
sudo systemctl stop ${network}d 2>/dev/null
sudo systemctl stop tor@default 2>/dev/null
fi
2018-12-02 19:52:01 +01:00
# switch on
2018-12-02 20:43:48 +01:00
if [ "$1" = "1" ] || [ "$1" = "on" ]; then
2018-12-02 19:52:01 +01:00
echo "switching the TOR ON"
# setting value in raspi blitz config
sudo sed -i "s/^runBehindTor=.*/runBehindTor=on/g" /mnt/hdd/raspiblitz.conf
# check if TOR was already installed and is funtional
echo ""
echo "*** Check if TOR service is functional ***"
torRunning=$(curl --connect-timeout 10 --socks5-hostname 127.0.0.1:9050 https://check.torproject.org 2>/dev/null | grep "Congratulations. This browser is configured to use Tor." -c)
2018-12-02 19:52:01 +01:00
if [ ${torRunning} -gt 0 ]; then
clear
echo "You are all good - TOR is already running."
echo ""
exit 0
else
echo "TOR not running ... proceed with switching to TOR."
echo ""
fi
# check if TOR package is installed
packageInstalled=$(dpkg -s tor-arm | grep -c 'Status: install ok')
if [ ${packageInstalled} -eq 0 ]; then
2019-02-09 15:12:37 +01:00
# calling function from above
prepareTorSources
echo "*** Updating System ***"
sudo apt update -y
echo ""
echo "*** Install Tor & NYX ***"
sudo apt install tor tor-arm -y
echo ""
echo "*** Tor Config ***"
2020-09-28 21:26:04 +02:00
sudo mkdir -p /mnt/hdd/tor
sudo mkdir -p /mnt/hdd/tor/sys
sudo chmod -R 700 /mnt/hdd/tor
2020-09-28 21:26:04 +02:00
sudo chown -R debian-tor:debian-tor /mnt/hdd/tor
PASSWORD_B=$(sudo cat /mnt/hdd/${network}/${network}.conf | grep rpcpassword | cut -c 13-)
HASHED_PASSWORD=$(sudo -u debian-tor tor --hash-password "$PASSWORD_B")
cat > ./torrc <<EOF
2018-12-02 19:52:01 +01:00
### See 'man tor', or https://www.torproject.org/docs/tor-manual.html
DataDirectory /mnt/hdd/tor/sys
PidFile /mnt/hdd/tor/sys/tor.pid
SafeLogging 0
Log notice stdout
Log notice file /mnt/hdd/tor/notice.log
Log info file /mnt/hdd/tor/info.log
RunAsDaemon 1
ControlPort 9051
SocksPort 9050
2019-01-13 22:03:23 +01:00
ExitRelay 0
2018-12-02 19:52:01 +01:00
2020-09-28 21:26:04 +02:00
HashedControlPassword $HASHED_PASSWORD
2018-12-02 19:52:01 +01:00
2020-01-23 18:59:53 +01:00
# Hidden Service for WEB ADMIN INTERFACE
2018-12-02 19:52:01 +01:00
HiddenServiceDir /mnt/hdd/tor/web80/
HiddenServiceVersion 3
2018-12-02 19:52:01 +01:00
HiddenServicePort 80 127.0.0.1:80
# Hidden Service for BITCOIN
HiddenServiceDir /mnt/hdd/tor/bitcoin8332/
HiddenServiceVersion 3
HiddenServicePort 8332 127.0.0.1:8332
# Hidden Service for LND (incoming connections)
HiddenServiceDir /mnt/hdd/tor/lnd9735
HiddenServiceVersion 3
HiddenServicePort 9735 127.0.0.1:9735
2020-01-23 18:59:53 +01:00
# Hidden Service for LND RPC
2018-12-02 19:52:01 +01:00
HiddenServiceDir /mnt/hdd/tor/lndrpc10009/
HiddenServiceVersion 3
HiddenServicePort 10009 127.0.0.1:10009
# Hidden Service for LND RPC (v2Fallback)
HiddenServiceDir /mnt/hdd/tor/lndrpc10009fallback/
HiddenServiceVersion 2
HiddenServicePort 10009 127.0.0.1:10009
2018-12-02 19:52:01 +01:00
2020-01-23 18:59:53 +01:00
# Hidden Service for LND REST
HiddenServiceDir /mnt/hdd/tor/lndrest8080/
HiddenServiceVersion 3
2020-01-23 18:59:53 +01:00
HiddenServicePort 8080 127.0.0.1:8080
# Hidden Service for LND REST (v2Fallback)
HiddenServiceDir /mnt/hdd/tor/lndrest8080fallback/
HiddenServiceVersion 2
HiddenServicePort 8080 127.0.0.1:8080
2018-12-02 19:52:01 +01:00
# NOTE: bitcoind get tor service automatically - see /mnt/hdd/bitcoin for onion key
EOF
sudo rm $torrc
sudo mv ./torrc $torrc
sudo chmod 644 $torrc
2020-09-28 21:26:04 +02:00
sudo chown -R debian-tor:debian-tor /var/run/tor/ 2>/dev/null
echo ""
2018-12-02 19:52:01 +01:00
2020-09-10 14:04:29 +02:00
sudo mkdir -p /etc/systemd/system/tor@default.service.d
2020-09-28 21:26:04 +02:00
sudo tee /etc/systemd/system/tor@default.service.d/raspiblitz.conf >/dev/null <<EOF
# DO NOT EDIT! This file is generate by raspiblitz and will be overwritten
[Service]
ReadWriteDirectories=-/mnt/hdd/tor
EOF
2019-06-12 23:40:56 +02:00
else
echo "TOR package/service is installed and was prepared earlier .. just activating again"
fi
2019-06-12 23:40:56 +02:00
# ACTIVATE TOR SERVICE
echo "*** Enable TOR Service ***"
sudo systemctl daemon-reload
sudo systemctl enable tor@default
echo ""
2018-12-02 19:52:01 +01:00
2019-06-13 00:58:52 +02:00
# ACTIVATE BITCOIN OVER TOR (function call)
activateBitcoinOverTOR
2018-12-11 01:00:55 +01:00
2019-06-13 00:58:52 +02:00
# ACTIVATE LND OVER TOR (function call)
activateLndOverTOR
2018-12-02 19:52:01 +01:00
2020-01-26 23:57:27 +01:00
# ACTIVATE APPS OVER TOR
source /mnt/hdd/raspiblitz.conf 2>/dev/null
if [ "${BTCRPCexplorer}" = "on" ]; then
/home/admin/config.scripts/internet.hiddenservice.sh btc-rpc-explorer 80 3002
fi
if [ "${rtlWebinterface}" = "on" ]; then
2020-07-18 15:26:56 +02:00
/home/admin/config.scripts/internet.hiddenservice.sh RTL 80 3002 443 3003
2020-01-26 23:57:27 +01:00
fi
if [ "${BTCPayServer}" = "on" ]; then
2020-07-18 15:26:56 +02:00
/home/admin/config.scripts/internet.hiddenservice.sh btcpay 80 23002 443 23003
2020-01-26 23:57:27 +01:00
fi
if [ "${ElectRS}" = "on" ]; then
/home/admin/config.scripts/internet.hiddenservice.sh electrs 50002 50002 50001 50001
fi
2020-04-23 23:10:30 +02:00
if [ "${LNBits}" = "on" ]; then
2020-07-18 15:26:56 +02:00
/home/admin/config.scripts/internet.hiddenservice.sh lnbits 80 5002 443 5003
fi
if [ "${thunderhub}" = "on" ]; then
/home/admin/config.scripts/internet.hiddenservice.sh thunderhub 80 3012 443 3013
fi
if [ "${specter}" = "on" ]; then
# specter makes only sense to be served over https
/home/admin/config.scripts/internet.hiddenservice.sh cryptoadvance-specter 443 25441
2020-02-10 12:33:03 +01:00
fi
2020-01-26 23:57:27 +01:00
2020-09-05 22:30:19 +02:00
echo "Setup logrotate"
2020-09-28 21:26:04 +02:00
# add logrotate config for modified Tor dir on ext. disk
sudo tee /etc/logrotate.d/raspiblitz-tor >/dev/null <<EOF
2020-09-05 22:30:19 +02:00
/mnt/hdd/tor/*log {
daily
rotate 5
compress
delaycompress
missingok
notifempty
2020-09-28 21:26:04 +02:00
create 0640 debian-tor debian-tor
2020-09-05 22:30:19 +02:00
sharedscripts
postrotate
if invoke-rc.d tor status > /dev/null; then
invoke-rc.d tor reload > /dev/null
fi
endscript
}
EOF
2020-09-28 21:26:04 +02:00
sudo systemctl restart tor@default
2020-09-05 22:30:19 +02:00
2018-12-02 19:52:01 +01:00
echo "OK - TOR is now ON"
echo "needs reboot to activate new setting"
exit 0
fi
# switch off
2018-12-02 20:43:48 +01:00
if [ "$1" = "0" ] || [ "$1" = "off" ]; then
2018-12-02 19:52:01 +01:00
echo "switching TOR OFF"
# setting value in raspi blitz config
sudo sed -i "s/^runBehindTor=.*/runBehindTor=off/g" /mnt/hdd/raspiblitz.conf
# disable TOR service
echo "*** Disable TOR service ***"
sudo systemctl disable tor@default
echo ""
2019-08-08 17:41:58 +02:00
# DEACTIVATE BITCOIN OVER TOR (function call)
deactivateBitcoinOverTOR
2018-12-02 19:52:01 +01:00
echo ""
echo "*** Removing TOR from LND ***"
sudo systemctl disable lnd
2018-12-11 01:00:55 +01:00
echo "editing /etc/systemd/system/lnd.service"
2020-03-21 23:18:19 -07:00
sudo sed -i "s/^ExecStart=\/usr\/local\/bin\/lnd.*/ExecStart=\/usr\/local\/bin\/lnd --externalip=\${publicIP}:\${lndPort} \${lndExtraParameter}/g" /etc/systemd/system/lnd.service
sudo sed -i '/\[Tor\]*/d' /mnt/hdd/lnd/lnd.conf
sudo sed -i '/^tor.password=*/d' /mnt/hdd/lnd/lnd.conf
2018-12-11 01:00:55 +01:00
2018-12-02 19:52:01 +01:00
sudo systemctl enable lnd
echo "OK"
echo ""
2020-09-28 21:26:04 +02:00
echo "*** Stop TOR service ***"
sudo systemctl stop tor@default
echo ""
if [ "$2" == "clear" ]; then
echo "*** Deinstall Tor & Delete Data ***"
sudo apt remove tor tor-arm -y
sudo rm -r /mnt/hdd/tor 2>/dev/null
fi
2018-12-02 19:52:01 +01:00
echo "needs reboot to activate new setting"
exit 0
fi
2020-11-15 22:16:13 +00:00
# update
if [ "$1" = "update" ]; then
# as in https://2019.www.torproject.org/docs/debian#source
prepareTorSources
echo "# Install the dependencies"
sudo apt update
sudo apt install -y build-essential fakeroot devscripts
sudo apt build-dep -y tor deb.torproject.org-keyring
rm -rf /home/admin/download/debian-packages
mkdir -p /home/admin/download/debian-packages
cd /home/admin/download/debian-packages
echo "# Building Tor from the source code ..."
apt source tor
cd tor-*
debuild -rfakeroot -uc -us
cd ..
echo "# Stopping the tor.service before updating"
sudo systemctl stop tor
echo "# Update ..."
sudo dpkg -i tor_*.deb
echo "# Starting the tor.service "
sudo systemctl start tor
echo "# Installed $(tor --version)"
exit 0
fi
echo "FAIL - Unknown Parameter $1"
2018-12-02 19:52:01 +01:00
echo "may needs reboot to run normal again"
exit 1