mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
1037cf358fa1f9be298342ff6645cf940fdf6853
TLS version 1.3 defers the NewSessionTicket until after the handshake has completed, and allows the server to send multiple NewSessionTicket messages (e.g. to refresh short-lived tickets). The default session ID generated in tls_save() will currently end up with the same value on each invocation. While session IDs are unused in TLS version 1.3, this could lead to confusing debug messages and packet captures. Add a function tls_random() to generate random nonces using the channel ephemeral secret, a label, and a 64-bit counter, and this function to generate unique session IDs. Non-sequential record IVs are also generated using channel ephemeral secrets. Simplify this code by using tls_random() instead of a direct call to channel_ephemeral(). Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE network bootloader
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
-
boot from a web server via HTTP or HTTPS,
-
boot from an iSCSI, FCoE, or AoE SAN,
-
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.
Languages
C
98.5%
Assembly
0.6%
Python
0.3%
Perl
0.3%
Makefile
0.2%