# Pinned iPXE binary checksums. pxe-setup.sh fetches ipxe.efi + # undionly.kpxe from https://boot.ipxe.org and verifies the SHA256 # against these pins. Mismatch = hard fail; the script will not place # mismatched binaries into tftp_root. # # Sources (both from the iPXE project's latest-build tree): # ipxe.efi → https://boot.ipxe.org/x86_64-efi/ipxe.efi # undionly.kpxe → https://boot.ipxe.org/undionly.kpxe # # To bump: fetch fresh binaries, verify via a second trusted source # (e.g. a checksum published by a distro package, or a second mirror), # regenerate with `sha256sum ipxe.efi undionly.kpxe > ipxe-shas.txt`, # and commit. Treat this as a security-sensitive change. # # Format: compatible with `sha256sum -c ipxe-shas.txt` when run from # the directory containing both files. 270afb529c4a8c1a89e2b852eca150789d948edaca9ca7099a12f170cc9c82e5 ipxe.efi a84c7945d5ac941b8284a279bb2c93062bc19370681c9cf9a28b52daa1782a95 undionly.kpxe