Ledger Integration for pundixd
Last updated
Last updated
DISCLAIMER
Currently, the cosmos app on Ledger only supports the path m/44/118.
By default, the pundixd keys add
command is defaulted to --algo=eth_secp256k1 --coin-type=60
which is compatible with Ethereum accounts. If you want to use ledger to add a cosmos account, you must specify the flag --algo=secp256k1 --coin-type=118
.
Without this flag, running the following command will return the following error:
pundixd keys add mywallet --ledger --index 102 --keyring-backend file
Error: failed to generate ledger key: failed to recover pubkey: [APDU_CODE_DATA_INVALID] Referenced data reversibly blocked (invalidated): address rejected for path m/44'/60'/0'/0/102
Using a hardware wallet to store your keys greatly improves the security of your crypto assets. The Ledger device acts as an enclave of the seed and private keys, and the process of signing transaction takes place within it. No private information ever leaves the Ledger device. The following is a short tutorial on using the Cosmos Ledger app with the PundiX CLI.
At the core of a Ledger device there is a mnemonic seed phrase that is used to generate private keys. This phrase is generated when you initialize your Ledger. The mnemonic is compatible with Cosmos and can be used to seed new accounts.
DO NOT lose or share your 24 words with anyone. To prevent theft or loss of funds, it is best to keep multiple copies of your mnemonic stored in safe, secure places. If someone is able to gain access to your mnemonic, they will fully control the accounts associated with them.
Before you use a ledger to set up your validator, do make sure you understand this setup. You will need:
Your ledger which has the Cosmos app installed.
PundiX CLI installed on your local machine but this does not have to be a full-node or validator-node if you are remoting into a cloud server. Because your ledger is connected to your local machine, you will need PundiX CLI installed locally and we will be using this to send commands to the cloud server.
Your cloud server to be a full-node/validator node.
To run the ssh port forwarding command
Two terminals opened, first one run the ssh port forwarding command.
The other one with pundixd opened locally and we will be using this terminal to run our commands.
Installing the Cosmos
application on your ledger device is required before you can use it with our PundiX CLI. To do so, you need to:
Install Ledger Live on your machine.
Using Ledger Live, update your Ledger Nano S with the latest firmware/Ledger Nano X.
Open Ledger Live and navigate to the Manager tab.
Connect and unlock your Ledger device.
If asked, allow the manager on your device.
Search for the Cosmos (PUNDIX) app in the app catalog.
Click the Install button to install the app on your Ledger device.
Your Ledger device displays Processing.
Ledger Live displays Installed.
More information on how to set up your Ledger device can be found here.
To see the Cosmos
application when you search for it, you might need to activate the Developer Mode
, located in the Experimental features tab of the Ledger Live application.
You need to install the Cosmos app on your Ledger Nano before moving on to this section
The tool used to generate addresses and transactions on the PundiX network is pundixd
. You will be using pundixd CLI commands for creating transactions and then using your Ledger to sign off before broadcasting the transaction to a specified node using the pundixd CLI.
You need to install PundiX before you proceed further
Connect and unlock your Ledger device.
Open the Cosmos app on your Ledger.
Create an account in pundixd from your ledger key.
Be sure to change the _name
parameter to be a meaningful name. The --ledger
flag tells pundixd
to use your Ledger to seed the account.
Check the ledger and approve the address. Then, in terminal it returns:
Cosmos uses HD Wallets. This means you can setup multiple accounts using the same Ledger seed. To create another account from your Ledger device, run the following, (changing the integer <i> to some value >= 0 to choose the account for HD derivation):
Check the ledger and approve the address. Then, in terminal it returns:
Additionally and importantly, if you wish to have an added layer of protection on your keys, you may add the --keyring-backend
flag and specify the file name. Setting your key up this way will ensure another layer of protection for signing any transactions.
You will be prompted for a keyring passphrase (password must be at least 8 characters) :
In the future, whenever you use this account to sign off on a transaction, you will have to add the --keyring-backend <file_name>
flag and enter the keyring passphrase.
Save a backup of your keyring passphrase in a secure place. Losing your keyring passphrase will result in the lost of all your funds created using the keyring passphrase❗
Also to access your keys in the keyring file DO NOT forget to add the --keyring flag
Run this command to display your address on your Ledger device. Use the _name
you gave your ledger key. The -d
flag is supported in version 1.5.0
and higher.
Confirm that the address displayed on the device matches the address displayed on the terminal.
Next, you need to configure pundixd with the URL of a PundiX full node and the appropriate chain_id
. In this example we connect to the public load balanced full node operated by Function X on the payalebar
chain. But you can point your pundixd
to any PundiX
full node. Be sure that the chain-id
is set to the same chain as the full node.
Test your connection with a query such as:
To run your own full node locally read more here.
You are now ready to start signing and sending transactions. Send a transaction with pundixd using the tx bank send
command.
Be sure to unlock your device with the PIN and open the Cosmos app before trying to run these commands
Use the _name
you set for your Ledger key and PundiX will connect with the Cosmos Ledger app to then sign your transaction.
Assuming you added the --keyring-backend <file>
flag earlier, an example of a transaction would look like the following:
If you are not running a node, be sure to add in the --node
flag to specify which node you would like to broadcast your transaction.
You will be prompted to enter the passphrase for the --keyring-backend
flag:
After inputting y
, you will be prompted to review and approve the transaction on your Ledger device.View Transaction
on your Ledger, be sure to inspect the transaction JSON displayed on the screen. You can scroll through each field and each message. You may refer here to read more about the data fields of a standard transaction object. When prompted with confirm transaction before signing
, Answer y
.
To receive funds to the pundix
account on your Ledger device, retrieve the address for your Ledger account (the ones with TYPE ledger
) with this command:
Not sure what pundixd
can do? Simply run the command without arguments to output documentation for the commands in supports.
The pundixd
help commands are nested. So $ pundixd
will output docs for the top level commands (status, config, query, and tx). You can access documentation for sub commands with further help commands.
For example, to print the query
commands:
Transactions in pundix embed the Standard Transaction type from the Cosmos SDK. The Ledger device displays a serialized JSON representation of this object for you to review before signing the transaction. Here are the fields and what they mean:
chain-id
: The chain to which you are broadcasting the tx, such as the pundix
payalebar or pundix
mainnet.
account_number
: The global id of the sending account assigned when the account receives funds for the first time.
sequence
: The nonce for this account, incremented with each transaction.
fee
: JSON object describing the transaction fee, its gas amount and coin denomination
memo
: optional text field used in various ways to tag transactions.
msgs_<index>/<field>
: The array of messages included in the transaction. Double click to drill down into nested fields of the JSON.