mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-05 15:08:25 +00:00
Simplified requirements.txt; revised READMEs; less sudo
This commit is contained in:
@@ -99,10 +99,9 @@ Set the following:
|
||||
* `Localisation Options`:
|
||||
* `Locale`: arrow up and down through the list and select or deselect languages with the spacebar.
|
||||
* `en_US.UTF-8 UTF-8` for US English
|
||||
* `Timezone`: Select region first, then timezone (e.g. America; Central).
|
||||
* WiFi settings (only necessary for the option #1 setup above)
|
||||
|
||||
Reboot when prompted within the raspi-config interface.
|
||||
Exit and reboot when prompted within the raspi-config interface.
|
||||
|
||||
Install these dependencies:
|
||||
```
|
||||
@@ -120,14 +119,15 @@ cd ..
|
||||
rm bcm2835-1.60.tar.gz
|
||||
```
|
||||
|
||||
Install python dependencies:
|
||||
```
|
||||
sudo pip3 install -r requirements.txt
|
||||
```
|
||||
|
||||
Download SeedSigner
|
||||
```
|
||||
sudo git clone https://github.com/SeedSigner/seedsigner
|
||||
git clone https://github.com/SeedSigner/seedsigner
|
||||
```
|
||||
|
||||
Install python dependencies:
|
||||
```
|
||||
cd seedsigner
|
||||
pip3 install -r requirements.txt
|
||||
```
|
||||
|
||||
Modify the systemd to run SeedSigner at boot:
|
||||
@@ -141,8 +141,9 @@ Add the following contents to the file:
|
||||
Description=Seedsigner
|
||||
|
||||
[Service]
|
||||
User=pi
|
||||
WorkingDirectory=/home/pi/seedsigner
|
||||
ExecStart=/usr/bin/python3 /home/pi/seedsigner/main.py
|
||||
ExecStart=/usr/bin/python3 main.py
|
||||
Restart=always
|
||||
|
||||
[Install]
|
||||
@@ -155,8 +156,8 @@ Then use Control + X, to exit the program.
|
||||
Run `sudo systemctl enable seedsigner.service` to enable service on boot. (This will restart the seedsigner code automatically at startup and if it crashes.)
|
||||
|
||||
(Optional) Modify the system swap configuration to disable virtual memory:
|
||||
* `sudo nano /etc/dphys-swapfile`
|
||||
add `CONF_SWAPSIZE=100` to `CONF_SWAPSIZE=0`
|
||||
```sudo nano /etc/dphys-swapfile```
|
||||
Change `CONF_SWAPSIZE=100` to `CONF_SWAPSIZE=0`
|
||||
|
||||
Use Control + O, then [enter], to write the file.
|
||||
Then use Control + X, to exit the program.
|
||||
@@ -169,3 +170,5 @@ sudo reboot
|
||||
```
|
||||
|
||||
It will take about a minute after the Pi is powered on for the GUI to launch -- be patient!
|
||||
|
||||
_Reminder: If you used option #2, [return the guide](babel/README.md) to remove the internet access over USB configuration._
|
||||
|
||||
+73
-4
@@ -1,10 +1,17 @@
|
||||
## Relaying internet access to the Pi Zero 1.3 over USB
|
||||
|
||||
Note that this is an optional, alternate way to initialize your SeedSigner. The default method is to work on a separate Raspberry Pi device that has internet access. Be aware that by enabling internet access over USB you are obviously creating a link to the outside world that this project seeks to avoid.
|
||||
|
||||
If you use this setup route, we recommend that you disable internet access over USB when these steps are complete.
|
||||
|
||||
|
||||
### Get started
|
||||
Insert the SD card with your Raspberry Pi OS image into a regular computer. Open a terminal window (macOS: Terminal; Windows: Command Prompt) and navigate to the SD card:
|
||||
```
|
||||
# mac/Linux:
|
||||
cd /Volumes/boot
|
||||
|
||||
# Windows (alter with correct drive letter)
|
||||
# Windows (alter with correct drive letter):
|
||||
cd e:
|
||||
```
|
||||
|
||||
@@ -13,7 +20,7 @@ We need to create an empty file called "ssh" to enable us to remotely terminal i
|
||||
# max/Linux:
|
||||
touch ssh
|
||||
|
||||
# Windows
|
||||
# Windows:
|
||||
type nul > ssh
|
||||
```
|
||||
|
||||
@@ -30,7 +37,7 @@ Open `cmdline.txt` in a basic text editor:
|
||||
# mac/Linux:
|
||||
nano cmdline.txt
|
||||
|
||||
# Windows
|
||||
# Windows:
|
||||
notepad cmdline.txt
|
||||
```
|
||||
|
||||
@@ -60,6 +67,22 @@ At the password prompt enter the Pi's default password: `raspberry`
|
||||
If you now see the Pi's command prompt, you're in!
|
||||
<img src="img/usb_relay_01.png">
|
||||
|
||||
Notice this warning in particular:
|
||||
```
|
||||
SSH is enabled and the default password for the 'pi' user has not been changed.
|
||||
This is a security risk - please login as the 'pi' user and type 'passwd' to set a new password.
|
||||
```
|
||||
|
||||
If someone savvy got access to your SeedSigner, they could sign into it and potentially upload malicious code. To add an extra layer of protection, change the default 'pi' user's password now by typing `passwd`:
|
||||
```
|
||||
pi@raspberrypi:~ $ passwd
|
||||
Changing password for pi.
|
||||
Current password:
|
||||
New password:
|
||||
Retype new password:
|
||||
passwd: password updated successfully
|
||||
```
|
||||
|
||||
|
||||
## Configure host computer to share internet access with the Pi
|
||||
|
||||
@@ -93,4 +116,50 @@ If you see a ping response, the Pi has internet access!
|
||||
|
||||
|
||||
### Windows
|
||||
see: https://www.circuitbasics.com/raspberry-pi-zero-ethernet-gadget/
|
||||
see: https://www.circuitbasics.com/raspberry-pi-zero-ethernet-gadget/
|
||||
|
||||
|
||||
## Complete the setup
|
||||
Return to the main [README](../README.md) and complete the setup steps. But remember to come back here and disable internet access over USB on your SeedSigner.
|
||||
|
||||
|
||||
## Disable internet access
|
||||
Power down the SeedSigner and remove the SD card. Put the SD card back into your computer and use a terminal to navigate to the `boot` drive (same process as above).
|
||||
|
||||
Edit `config.txt`:
|
||||
```
|
||||
# mac/Linux:
|
||||
nano config.txt
|
||||
|
||||
# Windows:
|
||||
notepad config.txt
|
||||
```
|
||||
|
||||
Delete the `dtoverlay=dwc2` line that we added to the end of the file. Exit and save changes (CTRL-X, then "y" in nano).
|
||||
|
||||
|
||||
Edit `cmdline.txt`:
|
||||
```
|
||||
# mac/Linux:
|
||||
nano cmdline.txt
|
||||
|
||||
# Windows:
|
||||
notepad cmdline.txt
|
||||
```
|
||||
|
||||
Delete `modules-load=dwc2,g_ether`. Exit and save changes (CTRL-X, then "y" in nano).
|
||||
|
||||
Eject the SD card and put it back in the SeedSigner. Connect the SeedSigner to your computer with a USB cable. It should no longer show up as a "RNDIS/Ethernet Gadget".
|
||||
|
||||
SSH into the pi and try to `ping 8.8.8.8`. It should fail with no responses.
|
||||
|
||||
For full security, put the SD card back in your computer one last time and delete the `ssh` file from `boot`:
|
||||
```
|
||||
# mac/Linux:
|
||||
rm ssh
|
||||
|
||||
# Windows:
|
||||
del ssh
|
||||
```
|
||||
|
||||
You're now good to go with a SeedSigner that is back to being fully air-gapped!
|
||||
+2
-22
@@ -1,28 +1,8 @@
|
||||
asn1crypto==0.24.0
|
||||
certifi==2018.8.24
|
||||
chardet==3.0.4
|
||||
colorzero==1.1
|
||||
cryptography==2.6.1
|
||||
embit==0.4.2
|
||||
entrypoints==0.3
|
||||
gpiozero==1.5.1
|
||||
idna==2.6
|
||||
imutils==0.5.4
|
||||
keyring==17.1.1
|
||||
keyrings.alt==3.1.1
|
||||
numpy==1.16.2
|
||||
picamera==1.13
|
||||
Pillow==8.2.0
|
||||
pycrypto==2.6.1
|
||||
PyGObject==3.30.4
|
||||
python-apt==1.8.4.3
|
||||
pyxdg==0.25
|
||||
pyzbar==0.1.8
|
||||
qrcode==6.1
|
||||
requests==2.21.0
|
||||
RPi.GPIO==0.7.0
|
||||
SecretStorage==2.3.1
|
||||
six==1.12.0
|
||||
spidev==3.4
|
||||
ssh-import-id==5.7
|
||||
urllib3==1.24.1
|
||||
six==1.16.0
|
||||
spidev==3.5
|
||||
Reference in New Issue
Block a user