meshtastic/docs/configuration/remote-admin.mdx

148 lines
6.9 KiB
Plaintext
Raw Normal View History

2021-05-01 10:51:51 -07:00
---
2022-11-03 17:10:08 -07:00
id: remote-admin
2022-11-02 13:21:48 -07:00
title: Remote Node Administration
sidebar_label: Remote Nodes
2023-09-19 21:40:54 -07:00
sidebar_position: 3
description: An advanced feature for securely administering remote devices over the mesh network instead of via Bluetooth, Serial, or IPv4.
2021-05-01 10:51:51 -07:00
---
import Tabs from "@theme/Tabs";
import TabItem from "@theme/TabItem";
2022-11-07 20:53:52 -08:00
:::caution Disclaimer
This is an advanced feature intended for experienced users. Its possible (if not done carefully) to apply settings to a remote node that could cause it to disconnect from the mesh. Network admins are advised to use a test node to trial settings before applying changes to a remote node to prevent this.
2022-11-07 20:53:52 -08:00
:::
This feature allows secure remote administration of Meshtastic nodes over the mesh network.
2022-11-07 20:53:52 -08:00
By default, nodes will only respond to administrative commands via the local USB, Bluetooth, or TCP interfaces. This basic security measure prevents unauthorized access and defines how standard administration and settings changes are managed. The only difference with remote administration is that commands are sent securely as Admin Messages over the mesh.
2022-11-07 20:53:52 -08:00
## Prerequisites
For firmware versions 2.5 and later, remote administration is achieved by storing the public key of the local node in one of the Admin Key fields within the remote nodes Security Config. Each remote node can store up to three unique Admin Keys, providing flexibility for managing nodes across the network.
2022-11-07 20:53:52 -08:00
For firmware versions 2.4.x and earlier, this is achieved by creating a secondary channel named `admin` with a shared PSK. In this setup, messages exchanged on this channel are encrypted only with the channels PSK, allowing any node in the channel to administer others.
2021-05-01 10:51:51 -07:00
This `admin` channel method is still supported in firmware versions 2.5 and later, but must be specifically enabled via the "Legacy Admin channel" setting and is only for managing pre-2.5 nodes. A firmware version 2.5 and later node cannot be managed in this way.
:::info
Remote Admin is complemented by setting [Managed Mode](/docs/configuration/radio/security/#managed-mode) on the remote node, which restricts radio configurations on that node. It is not necessary to set Managed Mode for Remote Admin to function.
:::
2021-05-01 10:51:51 -07:00
## Remote Admin Config Client Availability
<Tabs
groupId="settings"
defaultValue="apple"
values={[
{label: 'Android', value: 'android'},
{label: 'Apple', value: 'apple'},
{label: 'CLI', value: 'cli'},
{label: 'Web', value: 'web'},
]}>
<TabItem value="android">
2021-05-01 10:51:51 -07:00
#### Android
2021-05-01 10:51:51 -07:00
#### Setting up Remote Admin Using the PKC Method
1. Connect to the local node that will be administering the remote node.
2. Go to **⋮ > Radio Configuration > [Security](/docs/configuration/radio/security/#public-key)** to find its public key.
3. Copy the public key to use for configuring the remote node.
4. Connect to the node that will be the remotely administered node.
5. Go to the same **Security** menu as in Step 2, and press **"Add"** to paste the public key of the local node into an Admin Key field.
6. Up to 3 Admin Keys may be supplied, one per field, allowing up to 3 controlling nodes.
#### Setting up Remote Admin using the Legacy method
An Admin channel is set up by entering a secondary channel with the name `admin` using the method described in [Channels](/docs/configuration/radio/channels/)
Legacy admin is enabled using the Legacy Admin channel option in [Security Config](/docs/configuration/radio/security/#admin-channel-enabled).
#### Carrying out Remote Admin tasks
2021-05-01 10:51:51 -07:00
1. Open the Meshtastic App, connect to the local controlling node.
2. In the node list pane, select a node by tapping the Short Name in the colored bubble, then select More details.
3. In the more details screen, select Remote Administration, next to a gear icon.
4. From the Remote Administration screen, all Radio and Module configuration options are available.
2021-05-01 10:51:51 -07:00
</TabItem>
<TabItem value="apple">
2021-05-01 10:51:51 -07:00
#### Apple
2021-05-01 10:51:51 -07:00
#### Setting up Remote Admin Using the PKC Method
1. Connect to the node that will be used to administer the remote node.
2. Go to Settings > App Settings on this node and enable **Administration**.
3. Navigate to **Settings > Radio Configuration > [Security](/docs/configuration/radio/security/#public-key)** to find its public key.
4. Copy the public key to use for configuring the remote node.
5. Connect to the remote node.
6. In **Settings > Radio Configuration > Security**, add the public key of the local node as an Admin Key.
7. Up to 3 Admin Keys may be supplied, allowing up to 3 controlling nodes.
8. On the remote node, go to **Settings > App Settings** and enable **Administration**.
2021-05-01 10:51:51 -07:00
#### Setting up Remote Admin using the Legacy method
An Admin channel is set up by entering a secondary channel with the name `admin` using the method described in [Channels](/docs/configuration/radio/channels/)
2023-11-15 16:36:05 -08:00
Legacy admin is enabled using the Legacy Admin channel option in [Security Config](/docs/configuration/radio/security/#admin-channel-enabled).
2021-05-01 10:51:51 -07:00
#### Carrying out Remote Admin tasks
2021-05-01 10:51:51 -07:00
1. Open the Meshtastic App and connect to the local node youre using to administer the remote node.
2. Go to **Settings**.
3. Select the node you want to manage under **Settings > Configure Node**.
4. Suported Radio and Module settings for the remote node will be accessible from the **Settings** screen.
5. When finished administering the remote node, select your own node again in Settings > Configure Node.
2021-05-01 10:51:51 -07:00
</TabItem>
<TabItem value="cli">
2021-05-01 10:51:51 -07:00
#### CLI
2024-11-01 08:14:22 -07:00
#### Setting up Remote Admin Using the PKC Method
2024-11-01 09:14:29 -07:00
1. Connect via USB to the node that will be administering the remote node.
2. Retrieve its Public Key by running:
```bash
meshtastic --get security.public_key
```
3. Copy the public key to use when configuring the remote node.
4. Connect to the remote node via USB.
5. Set the Admin Key on the remote node by running:
```bash
meshtastic --set security.admin_key "PASTEPUBLICKEYHERE"
```
6. You may add up to 3 Admin Keys, enabling control from up to 3 different nodes.
2024-11-01 08:14:22 -07:00
2024-11-01 09:14:29 -07:00
#### Setting up Remote Admin Using the Legacy Method
To use the legacy method, set up an Admin channel as a secondary channel with the name `admin` by following the instructions in the [Channels](/docs/configuration/radio/channels/) section.
Enable Legacy Admin in the [Security Config](/docs/configuration/radio/security/#admin-channel-enabled) by running the following CLI command:
```bash
meshtastic --set security.admin_channel_enabled
```
#### Carrying Out Remote Admin Tasks
2024-11-01 08:14:22 -07:00
2024-11-01 09:28:07 -07:00
Remote admin commands are issued using the `--dest` argument with the `!nodeid` of the target node. Only the `--set` and `--get` commands are supported for remote administration. You can use these commands to modify parameters, add channels, or retrieve settings from the remote node. For example:
2024-11-01 09:14:29 -07:00
```bash
2024-11-01 09:21:58 -07:00
meshtastic --set security.admin_key "PASTEPUBLICKEYHERE" --dest '!28979058'
2024-11-01 09:14:29 -07:00
```
:::info
For Linux/Mac, enclose the `nodeid` value in single quotes: `--dest '!28979058'`. For Windows, quotes are not required: `--dest !28979058`.
:::
2024-11-01 08:14:22 -07:00
</TabItem>
<TabItem value="web">
#### Web
</TabItem>
</Tabs>