worry that anyone on the network can impersonate the server and send me a malicious image. Is there any way I can sign and authenticate images that I receive during PXE?
It's a minefield
Yeah, so how can I remove the mines? :)
Effectively you can't. PXE can't be made more secure, neither can you do much to lock down DHCP (without it becoming miserable to manage)
Any alternatives?
Besides crying you have a few options, but it depends on what you ultimately want to achieve
I want to have a central storage of signed isos that I can boot off remotely (within the same subnet) and have the isos authenticated before running them.
Setup PXE on Linux is a pain in the arse 🙈
Not really, it's just impossible to make secure
Обсуждают сегодня