Skip to content
Richard Grundy edited this page Jan 2, 2020 · 79 revisions

Steps to setup RPi0 with Zymkey SE

Setting up the RaspberryPi Zero is not as straight forward as you would think. Mainly because we opt for using the Raspbian Buster Lite and it's terminal only interface can make it difficult to know all the commands needed. So this will serve as a quick reference.

Use Cloned SDcard Image to Skip Below

  • diskutil list to see the disk names
  • append r to the disk name found. points to the card’s raw storage space to speed up process
  • gzip -dc /Users/rgrundy/Documents/personal/workspace/rpi0/passninja-image-no-zymkey.gz | sudo dd of=/dev/rdisk1 bs1m
  • takes about 25mins
  • boot RPi0, log in as root and change username:
    • usermod -l NEW_USERNAME username
    • groupmod username -n NEW_USERNAME
    • mv /home/username /home/NEW_USERNAME
    • nano /etc/passwd
      • edit NEW_USERNAME account to point to /home/NEW_USERNAME
  • add Wifi of new user here
  • Encrypt the boot file system and enable LUKS here

Download latest image from web

Use Etcher to flash into SDcard

  • Download Balena Etcher from here.
  • Install Etcher and launch.
  • Select the downloaded image zip file.
  • Select a Drive (Use an SDcard with micro SDcard, insert on right side of Macbook) and select.
  • Click on "Flash!".

Boot RPi

  • Slide micro SDcard into RPi with the metal contacts facing the PCB (Printed Circuit Board).
  • Connect RPi to a monitor via HDMI cable
  • Connect USB keyboard to RPi
  • Apply USB power to the RPi
  • Wait for boot to complete and login with user: pi; pwd: raspberry

Change password

$ passwd
Changing password for pi.
(current) UNIX password: raspberry
Enter UNIX password: pi2$PI
Retype UNIX password: pi2$PI
passwd: password updated successfully

Setup keyboard for US

  • Change keyboard layout
$ sudo vi /etc/default/keyboard

set -> XKBLAYOUT="us"
  • Reboot RPi
$ sudo reboot

Setup WiFi and USB tethering

$ sudo iwlist wlan0 scan | more // may not be needed if you already know the SSID
$ sudo vi /etc/wpa_supplicant/wpa_supplicant.conf

network={
    ssid="RichardsiPhone"
    psk="123456789+"
}
network={
    ssid="CasaBahia"
    psk="CasaBahia"
}

$ sudo wpa_cli reconfigure
Selected interface 'p2p-dev-wlan0'
OK
$ apt-get update
$ apt-get install gvfs ipheth-utils libimobiledevice-utils gvfs-backends gvfs-bin gvfs-fuse ifuse usbmuxd
$ vi /etc/network/interfaces

#iface eth0 inet manual
allow-hotplug eth0
iface eth0 inet dhcp

$ sudo reboot
$ ping google.com

Setup SSH for remote login and I2C for Zymkey SE

$ sudo raspi-config
Interfacing Options
SSH
Yes
Ok
I2C
Yes
Ok
Finish

Install Zymkit hardware

Follow these steps to place Zymkey on proper pins. Once in place continue:

$ sudo reboot
$ ifconfig
wlan0 inet addr:"IPAddress"

From remote computer
$ ssh pi@"IPAddress"

Install Zymkit services

$ sudo apt-get update && sudo apt-get upgrade
$ sudo apt-get install python-pip

if keys not found, do this:

$ sudo gpg --keyserver keys.gnupg.net --recv-key _missing_key_
$ sudo gpg -a --export _missing_key_ | sudo apt-key add -

Now you can continue installing Zymkey and LUKS/dm-crypt with apt-get (20mins)

curl -G https://s3.amazonaws.com/zk-sw-repo/install_zk_sw.sh | sudo bash
# this will reboot but need check progress after reboot before next step
# should see Zymkey binding (led 0.33Hz) and `sudo journalctl -u zkbootrtc.service` no errors
# insert blank USB flash drive of 16GB+ for next step

curl -G https://s3.amazonaws.com/zk-sw-repo/mk_encr_sd_rfs.sh | sudo bash
# this will reboot (phase 1 complete, running from USB)

# check progress using `df -h` iteratively, watch cryptfs fill to 1.8GB
# this will reboot (phase 2 complete, running from encrypted SDcard, Zymkey LED should blink 1 every 3secs)

You can now cut the Zymkey fuse tab and insert the coincell battery

Install NodeJs and other useful packages

$ wget https://nodejs.org/dist/v8.16.0/node-v8.16.0-linux-armv6l.tar.xz
## Follow https://github.com/nodejs/help/wiki/Installation with VERSION=v8.16.0 and DISTRO=linux-armv6l

$ sudo apt-get install -y build-essential netatalk git libusb-dev libusb-1.0-0-dev libudev-dev
$ sudo apt-get install -y bluetooth bluez libbluetooth-dev libudev-dev mercurial cmake

Setup ACS Drivers and PCSCLite

$ git clone https://github.com/acshk/acsccid.git
$ cd acsccid
$ sudo apt-get install -y perl flex pkg-config libusb-1.0-0-dev automake gettext libtool pcscd libpcsclite1 libpcsclite-dev
$ ./bootstrap
$ ./configure
$ make
$ sudo make install

Install PassNinja

First we need to prepare the passninja-rpi-toolchain on our development laptop. For this we will need to install Docker. Next we need to clone and build the toolchain:

$ git clone https://github.com/flomio/passninja-rpi-toolchain.git
$ cd passninja-rpi-toolchain && mkdir rootfs && ./build_docker.sh && ./run_docker.sh

Now from within the Docker instance:

$ rsync -vR --progress -rl --delete-after --safe-links passninja@192.168.1.64:/{lib,usr,etc/ld.so.conf.d,opt/vc/lib} /home/develop/rootfs/
$
$ git config --global user.email "richard@flomio.com"
$ git config --global user.name "Richard Grundy"
$ git clone https://github.com/flomio/passninja-cli.git
$ cd passninja-cli && git checkout remove-xpc && npm i && npm run build

Now from the RPi:

$ sudo su 
$ cp -R out /root/passninja && cd /root/passninja
$ vi passninja.service

[Unit]
Description=Passninja Scan Terminal service
After=network.target
StartLimitIntervalSec=0

[Service]
Type=simple
RestartSec=1
User=root
ExecStart=/usr/local/bin/node /root/passninja/pn.js scan --http --config /home/bioconn
ect/config.json
Restart=always

[Install]
WantedBy=multi-user.target

$ sudo cp -f /root/passninja/passninja.service /lib/systemd/system/
$ sudo chmod 644 /lib/systemd/system/passninja.service
$ sudo systemctl daemon-reload
$ sudo systemctl enable passninja.service
Created symlink from /etc/systemd/system/multi-user.target.wants/passninja.service to /lib/systemd/system/passninja.service.
$ sudo systemctl start passninja.service  ## start daemon
$ sudo systemctl status passninja.service ## check status
$ sudo systemctl stop passninja.service  ## stop daemon
$ sudo journalctl -f -u passninja.service ## check logs

You can now plug in FloBLE Mini module and scan PassNinja demo passes

Create Customer Account

While logged in as root, create user accounts with passninja config.json file:

$ adduser username
set default password to be `new.user`
$ login username
$ vi config.json
{
  "httpUrl": "http://localhost:3000/fancy/path",
  "passTypeId": "pass.com.passninja.demo.boardingPass",
  "collectorId": 77501435
}

Add basic tools for verifying passninja POST functionality:

$ vi .profile

# Nodejs
VERSION=v8.16.0
DISTRO=linux-armv6l
export PATH=/usr/local/lib/nodejs/node-$VERSION-$DISTRO/bin:$PATH

$ source .profile
$ wget https://bin.equinox.io/c/4VmDzA7iaHb/ngrok-stable-linux-arm.zip
$ unzip ngrok-stable-linux-arm.zip && rm ngrok-stable-linux-arm.zip
$ mkdir simple-express-server && npm init 

package name: (simple-express-server)
version: (1.0.0)
description: listens for a POST request
entry point: (index.js)
test command:
git repository:
keywords:
author: Richard Grundy
license: (ISC)

$ npm install express body-parser nodemon --save
$ vi index.js

const express = require('express')
const bodyParser = require('body-parser');

const app = express()
const port = 3000

app.use(bodyParser.urlencoded({ extended: false }));
app.use(bodyParser.json());

app.get('/', (req, res) => res.send('Express is alive'))
app.post('/fancy/path',function(request,response){
  var body=request.body;
  console.log("Body: %j",body);
  response.end("received");
});

app.listen(port, () => console.log(`Express app listening on port ${port}!`))

To test you can run:

  • details in simple-express-server ./node_modules/nodemon/bin/nodemon.js index.js
  • simpler in home dir node simple-express-server/index.js

Create a concealed Passninja account and Cleanup

In order to remotely manage the reader terminals to support customer needs we install a service account. We will do so without a home directory to conceal it's identity.

$ sudo su
$ useradd -d /home passninja
$ usermod -aG sudo passninja
$ passwd passninja

Now that we have everything in place, you should be able to plug in a FloBLE Plus reader, scan demo passes, and see POST requests received on the username account. Now that this is done, you can delete the original pi account. SSH in with the newly created passninja account:

$ ssh passninja@192.168.1.64
$ sudo su
$ userdel -r pi

Retest to make sure nothing broke as a result.

Install Lock Control

$ git clone https://github.com/flomio/lock-control-node.git
$ git checkout car-door
$ npm install
$ sudo cp -f /home/pi/lock-control-node/lock-control-node.service /lib/systemd/system/
$ sudo chmod 644 /lib/systemd/system/lock-control-node.service
$ sudo systemctl daemon-reload
$ sudo systemctl enable lock-control-node.service
$ sudo systemctl start lock-control-node.service  ## start daemon
$ sudo journalctl -f -u lock-control-node.service ## check logs

Clone this wiki locally