#!/bin/bash # Background: # https://medium.com/@lopp/how-to-run-bitcoin-as-a-tor-hidden-service-on-ubuntu-cff52d543756 # https://bitcoin.stackexchange.com/questions/70069/how-can-i-setup-bitcoin-to-be-anonymous-with-tor # https://github.com/lightningnetwork/lnd/blob/master/docs/configuring_tor.md # INFO # -------------------- # basic install of Tor is done by the build script now .. on/off will just switch service on/off # also thats where the sources are set and the preparation is done # command info if [ $# -eq 0 ] || [ "$1" = "-h" ] || [ "$1" = "-help" ]; then echo "script to switch Tor on or off" echo "internet.tor.sh [status|on|off|btcconf-on|btcconf-off|lndconf-on|update]" exit 1 fi torrc="/etc/tor/torrc" activateBitcoinOverTOR() { echo "*** Changing ${network} Config ***" btcExists=$(sudo ls /home/bitcoin/.${network}/${network}.conf | grep -c "${network}.conf") if [ ${btcExists} -gt 0 ]; then # make sure all is turned off and removed and then activate fresh (so that also old settings get removed) deactivateBitcoinOverTOR echo "# Make sure the user bitcoin is in the debian-tor group" sudo usermod -a -G debian-tor bitcoin sudo chmod 777 /home/bitcoin/.${network}/${network}.conf echo "Adding Tor config to the the ${network}.conf ..." # deprecate 'torpassword=' sudo sed -i "s/^torpassword=.*//g" /home/bitcoin/.${network}/${network}.conf echo "onlynet=onion" >> /home/bitcoin/.${network}/${network}.conf echo "proxy=127.0.0.1:9050" >> /home/bitcoin/.${network}/${network}.conf echo "main.bind=127.0.0.1" >> /home/bitcoin/.${network}/${network}.conf echo "test.bind=127.0.0.1" >> /home/bitcoin/.${network}/${network}.conf echo "dnsseed=0" >> /home/bitcoin/.${network}/${network}.conf echo "dns=0" >> /home/bitcoin/.${network}/${network}.conf if [ "${network}" = "bitcoin" ]; then # adding some bitcoin onion nodes to connect to to make connection easier echo "main.addnode=ira7kqcbff52wofoong2dieh2xlvmw4e7ya3znsqn7wivn6armetvrqd.onion" >> /home/bitcoin/.${network}/${network}.conf echo "main.addnode=xlpi353v7ia5b73msynr7tmddgxoco7n2r2bljt5txpv6bpzzphkreyd.onion" >> /home/bitcoin/.${network}/${network}.conf echo "main.addnode=ccjrb6va3j6re4lg2lerlt6wyvlb4tod7qbe7rwiouuapb7etvterxyd.onion" >> /home/bitcoin/.${network}/${network}.conf echo "main.addnode=s7m4mnd6bokujhywsocxibispktruormushdroeaeqeb3imvztfs3vid.onion" >> /home/bitcoin/.${network}/${network}.conf echo "main.addnode=ldvhlpsrvspquqnl3gutz7grfu5lb3m2dgnezpl3tlkxgpoiw2g5mzid.onion" >> /home/bitcoin/.${network}/${network}.conf echo "main.addnode=gliovxxzyy2rkwaoz25khf6oa64c3csqzjn3t6dodsjuf34w6a6ktsyd.onion" >> /home/bitcoin/.${network}/${network}.conf fi # remove empty lines sudo sed -i '/^ *$/d' /home/bitcoin/.${network}/${network}.conf sudo chmod 444 /home/bitcoin/.${network}/${network}.conf # copy new bitcoin.conf to admin user for cli access sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf sudo chown admin:admin /home/admin/.${network}/${network}.conf else echo "BTC config does not found (yet) - try with 'internet.tor.sh btcconf-on' again later" fi } deactivateBitcoinOverTOR() { # always make sure also to remove old settings sudo sed -i "s/^onlynet=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^main.addnode=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^test.addnode=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^proxy=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^main.bind=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^test.bind=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^dnsseed=.*//g" /home/bitcoin/.${network}/${network}.conf sudo sed -i "s/^dns=.*//g" /home/bitcoin/.${network}/${network}.conf # remove empty lines sudo sed -i '/^ *$/d' /home/bitcoin/.${network}/${network}.conf sudo cp /home/bitcoin/.${network}/${network}.conf /home/admin/.${network}/${network}.conf sudo chown admin:admin /home/admin/.${network}/${network}.conf } activateLndOverTOR() { echo "*** Putting LND behind Tor ***" lndExists=$(sudo ls /etc/systemd/system/lnd.service | grep -c "lnd.service") if [ ${lndExists} -gt 0 ]; then echo "# Make sure the user bitcoin is in the debian-tor group" sudo usermod -a -G debian-tor bitcoin # deprecate 'torpassword=' sudo sed -i '/\[Tor\]*/d' /mnt/hdd/lnd/lnd.conf sudo sed -i '/^tor.password=*/d' /mnt/hdd/lnd/lnd.conf # modify LND service echo "Make sure LND is disabled" sudo systemctl disable lnd 2>/dev/null echo "editing /etc/systemd/system/lnd.service" sudo sed -i "s/^ExecStart=\/usr\/local\/bin\/lnd.*/ExecStart=\/usr\/local\/bin\/lnd --tor\.active --tor\.streamisolation --tor\.v3 --listen=127\.0\.0\.1\:9735 \${lndExtraParameter}/g" /etc/systemd/system/lnd.service echo "Enable LND again" sudo systemctl enable lnd echo "OK" echo "" else echo "LND service not found (yet) - try with 'internet.tor.sh lndconf-on' again later" fi } # check and load raspiblitz config # to know which network is running if [ -f "/home/admin/raspiblitz.info" ]; then source /home/admin/raspiblitz.info fi if [ -f "/mnt/hdd/raspiblitz.conf" ]; then source /mnt/hdd/raspiblitz.conf fi # if started with status if [ "$1" = "status" ]; then # is Tor activated if [ "${runBehindTor}" == "on" ]; then echo "activated=1" else echo "activated=0" fi echo "config='${torrc}'" exit 0 fi # if started with btcconf-on if [ "$1" = "btcconf-on" ]; then activateBitcoinOverTOR exit 0 fi # if started with btcconf-off if [ "$1" = "btcconf-off" ]; then deactivateBitcoinOverTOR exit 0 fi # if started with lndconf-on if [ "$1" = "lndconf-on" ]; then activateLndOverTOR exit 0 fi # add default value to raspi config if needed checkTorEntry=$(sudo cat /mnt/hdd/raspiblitz.conf | grep -c "runBehindTor") if [ ${checkTorEntry} -eq 0 ]; then echo "runBehindTor=off" >> /mnt/hdd/raspiblitz.conf fi # location of TOR config # make sure /etc/tor exists sudo mkdir /etc/tor 2>/dev/null if [ "$1" != "update" ]; then # stop services (if running) echo "making sure services are not running" sudo systemctl stop lnd 2>/dev/null sudo systemctl stop ${network}d 2>/dev/null sudo systemctl stop tor@default 2>/dev/null fi # switch on if [ "$1" = "1" ] || [ "$1" = "on" ]; then echo "# switching Tor ON" # *** CURL TOR PROXY *** echo "socks5-hostname localhost:9050" > .curlrc.tmp sudo cp ./.curlrc.tmp /root/.curlrc sudo chown root:root /home/admin/.curlrc sudo cp ./.curlrc.tmp /home/pi/.curlrc sudo chown pi:pi /home/pi/.curlrc sudo cp ./.curlrc.tmp /home/admin/.curlrc sudo chown admin:admin /home/admin/.curlrc rm .curlrc.tmp # make sure the network was set (by sourcing raspiblitz.conf) if [ ${#network} -eq 0 ]; then echo "!! FAIL - unknown network due to missing /mnt/hdd/raspiblitz.conf" echo "# switching Tor config on for RaspiBlitz services is just possible after basic hdd/ssd setup" echo "# but with new 'Tor by default' basic Tor socks will already be available from the start" exit 1 fi # setting value in raspi blitz config sudo sed -i "s/^runBehindTor=.*/runBehindTor=on/g" /mnt/hdd/raspiblitz.conf # check if Tor was already installed and is funtional echo "" echo "*** Check if Tor service is functional ***" torRunning=$(curl --connect-timeout 10 --socks5-hostname 127.0.0.1:9050 https://check.torproject.org 2>/dev/null | grep "Congratulations. This browser is configured to use Tor." -c) if [ ${torRunning} -gt 0 ]; then clear echo "You are all good - Tor is already running." echo "" exit 0 else echo "Tor not running ... proceed with switching to Tor." echo "" fi # install package just in case it was deinstalled packageInstalled=$(dpkg -s tor-arm | grep -c 'Status: install ok') if [ ${packageInstalled} -eq 0 ]; then sudo apt install tor tor-arm torsocks -y fi # create tor data directory if it not exist if [ ! -d "/mnt/hdd/tor" ]; then echo "# - creating tor data directory" sudo mkdir -p /mnt/hdd/tor sudo mkdir -p /mnt/hdd/tor/sys else echo "# - tor data directory exists" fi # make sure its the correct owner sudo chmod -R 700 /mnt/hdd/tor sudo chown -R debian-tor:debian-tor /mnt/hdd/tor # create tor config .. if not exists or is old isTorConfigOK=$(sudo cat /etc/tor/torrc 2>/dev/null | grep -c "BITCOIN") if [ ${isTorConfigOK} -eq 0 ]; then echo "# - updating Tor config ${torrc}" PASSWORD_B=$(sudo cat /mnt/hdd/${network}/${network}.conf | grep rpcpassword | cut -c 13-) HASHED_PASSWORD=$(sudo -u debian-tor tor --hash-password "$PASSWORD_B") cat > ./torrc <