mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
1901e3224059061104217c320fae0bfd59e06650
As detailed in commit511dfd2("[crypto] Reject non-canonical ECDSA signature data structures"), changing the representation of a valid ECDSA signature to a different valid representation of the same signature does not conceptually make it an invalid signature. However, some large public test vector sets conflate the concepts of "altered representation" and "invalid representation" in a way that makes it difficult to determine which tests ought to pass and which ought to fail without extensive manual analysis. Reject any ECDSA signature object that does not have the expected total length. The signature parsing logic already ensures that the expected structure exists, and so the total length can be correct only if every object used the expected DER encoding. This length check completely subsumes the checks that were introduced in commit511dfd2("[crypto] Reject non-canonical ECDSA signature data structures"), since there is no way to insert additional information without also affecting the length. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE network bootloader
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
-
boot from a web server via HTTP or HTTPS,
-
boot from an iSCSI, FCoE, or AoE SAN,
-
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.
Languages
C
98.5%
Assembly
0.6%
Python
0.3%
Perl
0.3%
Makefile
0.2%