Michael Brown 76f7b88f93 [crypto] Allow for signable MD5 or SHA-1 digests with TLS version 1.1
For TLS version 1.1, non-RSA signed digests use SHA-1 instead of
MD5+SHA1.  Commit f095adb ("[tls] Use SHA-1 for TLS version 1.1 ECDSA
signatures") selected the correct digest algorithm for both server and
client authentication.

However, the key schedule currently refuses to generate client
CertificateVerify digests for any digest algorithm other than
MD5+SHA1, on the basis that only the MD5+SHA1 running transcript
digest value is available.

An MD5+SHA1 digest value is just the concatenation of an MD5 digest
value with a SHA-1 digest value, and so the SHA-1 digest value can be
provided for use with ECDSA client certificates.

Fix by special-casing the SHA-1 (and MD5) algorithms when generating a
signable digest value from the TLS version 1.1 key schedule.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2026-09-20 14:39:41 +01:00
2026-08-06 12:47:53 +01:00
2026-03-06 15:48:55 +00:00
2026-08-06 12:47:53 +01:00
2015-02-26 17:59:53 +00:00
2026-08-06 00:01:56 +01:00

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.

S
Description
No description provided
Readme
121 MiB
Languages
C 98.5%
Assembly 0.6%
Python 0.3%
Perl 0.3%
Makefile 0.2%