1 comments

  • nijave8 minutes ago
    Having http as an alternative to tftp is a nice win. The range of things that can run an http server is much bigger than tftp<p>&gt;Additionally, adding the TLS layer brings back the missing integrity and confidentiality guarantees and thus paves the way to move critical boot components out of the trusted network, possibly even to a remote location&#x2F;Cloud.<p>Doesn&#x27;t secure boot already provide this or am I misunderstanding something? I suppose secure boot only provides integrity but not confidentiality although I&#x27;m not sure how much confidentiality matters given we&#x27;re just talking about the kernel here