This shows you the differences between two versions of the page.
|
cfg:crosscert [2012/05/15 12:28] mcb30 |
cfg:crosscert [2012/05/15 12:29] (current) mcb30 |
||
|---|---|---|---|
| Line 44: | Line 44: | ||
| The current policy of ''ca.ipxe.org'' is to provide cross-signed certificates for all CAs that are trusted by the [[http://www.mozilla.org/firefox/|Firefox]] web browser. Certificates remain valid for 90 days. | The current policy of ''ca.ipxe.org'' is to provide cross-signed certificates for all CAs that are trusted by the [[http://www.mozilla.org/firefox/|Firefox]] web browser. Certificates remain valid for 90 days. | ||
| - | If you are booting using HTTPS on a private network with no access to [[http://ca.ipxe.org/auto]] then you may wish to create a local mirror, and use the ''crosscert'' setting to direct your clients to download the cross-signed certificates from the local mirror. For example: | + | If you are booting using HTTPS on a private network with no access to [[http://ca.ipxe.org/auto]] then you may wish to create a local mirror, and use the ''crosscert'' setting to direct your clients to download the cross-signed certificates from your local mirror. For example: |
| option ipxe.crosscert "http://192.168.0.10/pub/mirror/ca.ipxe.org/auto"; | option ipxe.crosscert "http://192.168.0.10/pub/mirror/ca.ipxe.org/auto"; | ||