[tls] Use standalone secure channel and key schedule implementations

The TLS implementation has become too complex to reason about safely,
and needs to be split up into smaller and well-defined units before
adding any further complexity (e.g. to support TLS version 1.3).

Use the standalone secure channel implementation to ensure that the
connection can be used for encrypted communication with a trusted
peer, with the secure channel operations being provided by the
standalone TLS key schedule implementation.

The TLS implementation is now just a protocol engine, and is no longer
responsible for policy decisions on whether or not the connection is
secure.  The TLS code delegates this decision to the underlying secure
channel, by refusing to transmit or receive application data unless
the secure channel has successfully been marked as established.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2 files changed
tree: 848d22c0e117376fe98003060b48e1cc1dad09f0
  1. .claude/
  2. .github/
  3. contrib/
  4. src/
  5. AGENTS.md
  6. CHANGELOG.md
  7. CLAUDE.md
  8. CONTRIBUTING.md
  9. COPYING
  10. COPYING.GPLv2
  11. COPYING.UBDL
  12. README.md
  13. RELEASE.md
  14. RELNOTES.tmpl.md
  15. SECURITY.md
README.md

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.