[tls] Add definitions for TLS version 1.3 cipher suites

RFC 8446 redefines the concept of a cipher suite for TLS version 1.3
to exclude the key exchange algorithm, leaving it specifying only the
block cipher algorithm and the handshake digest algorithm.

Add definitions for the two cipher suites that we can currently
support (TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384).

We define these as using the null key exchange algorithm.  The null
key exchange algorithm will fail on any attempt at key agreement.  A
server that attempts to rely on the key exchange algorithm implied by
the cipher suite (e.g. a server attempting to illegally use these
cipher suites with TLS version 1.2) will therefore be unable to
establish a shared secret and so will not be able to cause the secure
channel to become established.

We therefore do not explicitly check for and reject a server's attempt
to negotiate a TLS version 1.3 cipher suite under TLS version 1.2 or
earlier: the secure channel abstraction already ensures that such a
negotiation is doomed to failure.

Under TLS version 1.3, the cipher suite's key exchange algorithm
specification will not be used.  We therefore do not explicitly check
for and reject a server's attempt to negotiate a TLS version 1.2 or
earlier cipher suite under TLS version 1.3 or later: we instead just
ignore the key exchange algorithm aspect of that cipher suite.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
4 files changed
tree: 88aae914400960556dfd8f6c0f4b9ec11f17e0dc
  1. .claude/
  2. .github/
  3. contrib/
  4. src/
  5. AGENTS.md
  6. CHANGELOG.md
  7. CLAUDE.md
  8. CONTRIBUTING.md
  9. COPYING
  10. COPYING.GPLv2
  11. COPYING.UBDL
  12. README.md
  13. RELEASE.md
  14. RELNOTES.tmpl.md
  15. SECURITY.md
README.md

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.