[tls] Add support for the supported versions extension

RFC 8446 caps the version number field in ClientHello and ServerHello
to represent at most TLS version 1.2, as a workaround for badly
engineered servers and middleware boxes.  The actual protocol version
is instead negotiated via the supported_versions extension.

Send the list of supported versions in the ClientHello, and parse the
selected version from the supported_version extenion if present in the
ServerHello.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2 files changed
tree: 76ab9e3f34d5ce47101a0f26668fe4aab5671a01
  1. .claude/
  2. .github/
  3. contrib/
  4. src/
  5. AGENTS.md
  6. CHANGELOG.md
  7. CLAUDE.md
  8. CONTRIBUTING.md
  9. COPYING
  10. COPYING.GPLv2
  11. COPYING.UBDL
  12. README.md
  13. RELEASE.md
  14. RELNOTES.tmpl.md
  15. SECURITY.md
README.md

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.