Firewalling the application so that only local images are available seems like the only safe way to use this.
Firewalling the application so that only local images are available seems like the only safe way to use this.
How is that different than pulling an ISO image of your favorite distro, or using a package manager like apt?
Yes, I know that Linux ISOs have checksums and apt uses digital signatures, but so does iPXE. The only difference here would be that for some reason you trust the websites of your Linux distro vendor, but not netboot.xyz?
Well... yeah... that's not that crazy of a position to take.
Not saying there's anything wrong with netboot.xyz, but it's a question of how many cooks to let in the kitchen, and how many public eyes are on each cook.
"Some" reason? I think I'd have a very good reason to place much more trust in the Debian folks than some guy who runs some random netbooting website.
"Some iPXE builds do not support HTTPS connections. If you get an "Operation not supported" error message, run this instead:
chain --autofree http://boot.netboot.xyz"
Which.. think about that advice for a minute.
I'm not going to lie, this made me laugh out loud.
"For some reason, you trust a doctor to perform surgery on you, but not this lovely man that I met on the subway?!"
(The limitation here is that you have to be able to load the installer image into RAM, which does exclude a lot of smaller nettop/thin/SoC clients unfortunately.)