Michael Brown 2e549711c2 [tls] Use server certificate's own public key algorithm for verification
For TLS version 1.1 (without explicit signature hash algorithm
identifiers), we currently use the cipher suite's public key algorithm
when verifying the ServerKeyExchange signature.  This is indirectly
guaranteed to match the server certificate's own public key algorithm.

Use the server certificate's own public key algorithm directly, to be
consistent with the behaviour for client certificates.  The signed
certificate is, by definition, the authoritative source for its own
choice of public key algorithm.

This leaves the public key algorithm aspect of the cipher suite as
being unused outside of debug messages.  We do not enforce the
specification that the certificate's public key algorithm must match
the cipher suite's public key algorithm (if any) because doing so
serves no cryptographic purpose.  For TLS version 1.2 and later, the
explicit signature hash algorithm identifiers override the cipher
suite, and in TLS version 1.3 the whole concept of a public key
algorithm is removed from the scope of the cipher suite.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2026-09-20 20:33:15 +01:00
2026-08-06 12:47:53 +01:00
2026-03-06 15:48:55 +00:00
2026-08-06 12:47:53 +01:00
2015-02-26 17:59:53 +00:00
2026-08-06 00:01:56 +01:00

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.

S
Description
No description provided
Readme
121 MiB
Languages
C 98.5%
Assembly 0.6%
Python 0.3%
Perl 0.3%
Makefile 0.2%