mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
7a3b423f6942a507c78dbb40ce6bb944f986a398
The signable digest value is used to bind the server identity to the shared secret, and so the digest must be computed over the parameters used to establish the shared secret in order to be meaningful. The secure channel will refuse to bind the peer identity on the basis of a verified signable digest if the channel does not already contain key material derived from a shared secret. A signable digest that was erroneously constructed before a shared secret was applied is therefore guaranteed to be unusable for binding the channel, provided that the caller uses a sensible sequence of operations (i.e. constructs the signable digest and then immediately attempts to use it to bind the peer identity). Strengthen this guarantee further by refusing to generate a signable digest value unless the key schedule already contains key material. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE network bootloader
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
-
boot from a web server via HTTP or HTTPS,
-
boot from an iSCSI, FCoE, or AoE SAN,
-
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.
Languages
C
98.5%
Assembly
0.6%
Python
0.3%
Perl
0.3%
Makefile
0.2%