{"id":22499727,"url":"https://github.com/opiproject/sztp","last_synced_at":"2025-08-03T06:32:19.916Z","repository":{"id":61517323,"uuid":"546694446","full_name":"opiproject/sztp","owner":"opiproject","description":"Secure Zero Touch Provisioning (sZTP) in OPI","archived":false,"fork":false,"pushed_at":"2024-08-16T16:32:15.000Z","size":625,"stargazers_count":20,"open_issues_count":34,"forks_count":13,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-08-16T18:05:12.854Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/opiproject.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-10-06T13:48:38.000Z","updated_at":"2024-08-16T16:31:45.000Z","dependencies_parsed_at":"2023-12-26T04:24:05.430Z","dependency_job_id":"23d13695-7edd-4168-9244-f2aaa050bcac","html_url":"https://github.com/opiproject/sztp","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/opiproject%2Fsztp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/opiproject%2Fsztp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/opiproject%2Fsztp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/opiproject%2Fsztp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/opiproject","download_url":"https://codeload.github.com/opiproject/sztp/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":228532157,"owners_count":17933247,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-12-06T22:15:35.373Z","updated_at":"2024-12-06T22:15:36.053Z","avatar_url":"https://github.com/opiproject.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Secure Zero Touch Provisioning (sZTP)\n\n[![Linters](https://github.com/opiproject/sztp/actions/workflows/linters.yml/badge.svg)](https://github.com/opiproject/sztp/actions/workflows/linters.yml)\n[![CodeQL](https://github.com/opiproject/sztp/actions/workflows/codeql.yml/badge.svg)](https://github.com/opiproject/sztp/actions/workflows/codeql.yml)\n[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/opiproject/sztp/badge)](https://securityscorecards.dev/viewer/?platform=github.com\u0026org=opiproject\u0026repo=sztp)\n[![Sztp](https://github.com/opiproject/sztp/actions/workflows/sztp.yml/badge.svg)](https://github.com/opiproject/sztp/actions/workflows/sztp.yml)\n[![Go](https://github.com/opiproject/sztp/actions/workflows/go.yml/badge.svg)](https://github.com/opiproject/sztp/actions/workflows/go.yml)\n[![License](https://img.shields.io/github/license/opiproject/sztp?style=flat-square\u0026color=blue\u0026label=License)](https://github.com/opiproject/sztp/blob/master/LICENSE)\n[![codecov](https://codecov.io/gh/opiproject/sztp/branch/main/graph/badge.svg)](https://codecov.io/gh/opiproject/sztp)\n[![Go Report Card](https://goreportcard.com/badge/github.com/opiproject/sztp/sztp-agent)](https://goreportcard.com/report/github.com/opiproject/sztp/sztp-agent)\n[![Go Doc](https://img.shields.io/badge/godoc-reference-blue.svg)](http://godoc.org/github.com/opiproject/sztp/sztp-agent)\n[![Last Release](https://img.shields.io/github/v/release/opiproject/sztp?label=Latest\u0026style=flat-square\u0026logo=go)](https://github.com/opiproject/sztp/releases)\n[![GitHub stars](https://img.shields.io/github/stars/opiproject/sztp.svg?style=flat-square\u0026label=github%20stars)](https://github.com/opiproject/sztp)\n[![GitHub Contributors](https://img.shields.io/github/contributors/opiproject/sztp.svg?style=flat-square)](https://github.com/opiproject/sztp/graphs/contributors)\n\n## I Want To Contribute\n\nThis project welcomes contributions and suggestions.  We are happy to have the Community involved via submission of **Issues and Pull Requests** (with substantive content or even just fixes). We are hoping for the documents, test framework, etc. to become a community process with active engagement.  PRs can be reviewed by by any number of people, and a maintainer may accept.\n\nSee [CONTRIBUTING](https://github.com/opiproject/opi/blob/main/CONTRIBUTING.md) and [GitHub Basic Process](https://github.com/opiproject/opi/blob/main/doc-github-rules.md) for more details.\n\n## Docs\n\n* [RFC 8572](https://www.rfc-editor.org/rfc/pdfrfc/rfc8572.txt.pdf)\n* [Watsen SZTPD](https://watsen.net/docs/sztpd/0.0.11/admin-guide/#simulator)\n* [cizsle | Cisco ZTP Server](https://pypi.org/project/cizsle)\n* [Juniper](https://www.juniper.net/documentation/us/en/software/junos/junos-install-upgrade/topics/concept/secure-ztp-understanding.html)\n* [Cisco](https://gestaltit.com/events/sulagna/secure-zero-touch-provisioning-with-ciscos-implementation-on-ios-xr)\n* [Nokia](https://infocenter.nokia.com/public/7750SR2110R1A/index.jsp?topic=%2Fcom.nokia.Basic_System_Configuration_Guide_21.10.R1%2Fsecure_ztp.html)\n* [Huawei](https://info.support.huawei.com/info-finder/encyclopedia/en/SZTP.html)\n\n## Videos\n\n* [Cisco Secure Zero-Touch with IOS XR](https://www.youtube.com/watch?v=rl2ucWoTqyg)\n\n## How SZTP works\n\n[See all the details here](./ZTP.md)\n\n```mermaid\ngraph LR;\n    DPU[DPU or IPU]\n    Proxy[DHCP Proxy or Relay*]\n    DPU--\u003eProxy;\n    Proxy--\u003eDHCPServer*;\n    Proxy--\u003eBootstrapServer;\n    Proxy--\u003eFileServer*;\n    Proxy--\u003eDNSServer*;\n    Proxy--\u003eSyslogServer*;\n```\n\n## sZTP on DPU Diagram\n\n![xPU sZTP provisioning block](./doc/sZTP-provisioning-blocks.png)\n\n## Aliases\n\n:exclamation: `docker-compose` is deprecated. For details, see [Migrate to Compose V2](https://docs.docker.com/compose/migrate/).\n\n```text\ncommand -v docker-compose || { shopt -s expand_aliases \u0026\u0026 alias docker-compose='docker compose'; }\n```\n\n## Serial number\n\nGet real serial number using\n\n```bash\nroot@bf2:~# dmidecode -s system-serial-number\nMT2321XZ0KVX\n```\n\n## Before start\n\nChange in `docker-compose.yml` file those settings per your lab:\n\n```text\n      NODE_IP_SUBNET: 10.127.127.0\n      NODE_IP_NETMASK: 255.255.255.0\n      NODE_IP_RANGE_MIN: 10.127.127.100\n      NODE_IP_RANGE_MAX: 10.127.127.253\n      NODE_IP_ADDRESS: 10.127.127.3\n```\n\n## Run everything\n\n```text\ndocker-compose down --volumes --remove-orphans\ndocker-compose up --build --force-recreate\n```\n\n## Test everything\n\n```text\n./scripts/tests.sh\n```\n\n## Run sZTP (Bootstrap) Server only\n\n```text\ndocker-compose up --build bootstrap\n```\n\n## Test sZTP (Bootstrap) Server only\n\nFetching Host-meta\n\n```text\n$ docker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body -H Accept:application/yang-data+json http://bootstrap:7080/.well-known/host-meta\nHTTP/1.1 200 OK\nContent-Type: application/xrd+xml; charset=utf-8\nContent-Length: 104\nDate: Wed, 17 Aug 2022 00:29:54 GMT\nServer: \u003credacted\u003e\n\n\u003cXRD xmlns=\"http://docs.oasis-open.org/ns/xri/xrd-1.0\"\u003e\n  \u003cLink rel=\"restconf\" href=\"/restconf\"/\u003e\n\u003c/XRD\u003e\n```\n\nFetching the RESTCONF Root Resource\n\n```text\n$ docker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body --user my-admin@example.com:my-secret -H Accept:application/yang-data+json http://bootstrap:7080/restconf/\nHTTP/1.1 200 OK\nContent-Type: application/yang-data+json; charset=utf-8\nContent-Length: 137\nDate: Wed, 17 Aug 2022 00:30:32 GMT\nServer: \u003credacted\u003e\n\n{\n    \"ietf-restconf:restconf\" : {\n        \"data\" : {},\n        \"operations\" : {},\n        \"yang-library-version\" : \"2019-01-04\"\n    }\n}\n```\n\nGet the Current (Default) Configuration\n\n```text\n$ docker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body --user my-admin@example.com:my-secret -H \"Accept:application/yang-data+json\" http://bootstrap:7080/restconf/ds/ietf-datastores:running\nHTTP/1.1 200 OK\nContent-Type: application/yang-data+json; charset=utf-8\nContent-Length: 318\nDate: Wed, 17 Aug 2022 00:24:47 GMT\nServer: \u003credacted\u003e\n\n{\n  \"wn-sztpd-1:transport\": {\n    \"listen\": {\n      \"endpoint\": [\n        {\n          \"name\": \"default startup endpoint\",\n          \"use-for\": \"native-interface\",\n          \"http\": {\n            \"tcp-server-parameters\": {\n              \"local-address\": \"0.0.0.0\"\n            }\n          }\n        }\n      ]\n    }\n  }\n}\n```\n\n## Device Getting Onboarding Information\n\nRead the configuration back and validate it is correct:\n\n```text\ndocker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body --user my-admin@example.com:my-secret -H \"Accept:application/yang-data+json\" http://bootstrap:7080/restconf/ds/ietf-datastores:running\n```\n\nGet onboarding info (from device perspective)\n\n```text\n$ docker run --rm --user 0 --network sztp_opi -v sztp_client-certs:/certs docker.io/curlimages/curl:8.5.0 --fail-with-body -X POST --data '{\"ietf-sztp-bootstrap-server:input\":{\"hw-model\":\"model-x\",\"os-name\":\"vendor-os\",\"os-version\":\"17.3R2.1\",\"signed-data-preferred\":[null],\"nonce\":\"BASE64VALUE=\"}}' -H Content-Type:application/yang-data+json --user third-serial-number:my-secret --key /certs/third_private_key.pem --cert /certs/third_my_cert.pem --cacert /certs/opi.pem https://bootstrap:9090/restconf/operations/ietf-sztp-bootstrap-server:get-bootstrapping-data  | tee /tmp/post_rpc_input.json\n{\n  \"ietf-sztp-bootstrap-server:output\": {\n    \"conveyed-information\": \"MIIDfwYLKoZIhvcNAQkQASugggNuBIIDansKICAiaWV0Zi1zenRwLWNvbnZleWVkLWluZm86b25ib2FyZGluZy1pbmZvcm1hdGlvbiI6IHsKICAgICJib290LWltYWdlIjogewogICAgICAiZG93bmxvYWQtdXJpIjogWwogICAgICAgICJodHRwOi8vd2ViOjgwODIvdmFyL2xpYi9taXNjL215LWJvb3QtaW1hZ2UuaW1nIiwKICAgICAgICAiZnRwOi8vd2ViOjMwODIvdmFyL2xpYi9taXNjL215LWJvb3QtaW1hZ2UuaW1nIgogICAgICBdLAogICAgICAiaW1hZ2UtdmVyaWZpY2F0aW9uIjogWwogICAgICAgIHsKICAgICAgICAgICJoYXNoLWFsZ29yaXRobSI6ICJpZXRmLXN6dHAtY29udmV5ZWQtaW5mbzpzaGEtMjU2IiwKICAgICAgICAgICJoYXNoLXZhbHVlIjogIjdiOmNhOmU2OmFjOjIzOjA2OmQ4Ojc5OjA2OjhjOmFjOjAzOjgwOmUyOjE2OjQ0OjdlOjQwOjZhOjY1OmZhOmQ0OjY5OjYxOjZlOjA1OmNlOmY1Ojg3OmRjOjJiOjk3IgogICAgICAgIH0KICAgICAgXQogICAgfSwKICAgICJwcmUtY29uZmlndXJhdGlvbi1zY3JpcHQiOiAiSXlFdlltbHVMMkpoYzJnS1pXTm9ieUFpYVc1emFXUmxJSFJvWlNCd2NtVXRZMjl1Wm1sbmRYSmhkR2x2YmkxelkzSnBjSFF1TGk0aUNnPT0iLAogICAgImNvbmZpZ3VyYXRpb24taGFuZGxpbmciOiAibWVyZ2UiLAogICAgImNvbmZpZ3VyYXRpb24iOiAiUEhSdmNDQjRiV3h1Y3owaWFIUjBjSE02TDJWNFlXMXdiR1V1WTI5dEwyTnZibVpwWnlJK0NpQWdQR0Z1ZVMxNGJXd3RZMjl1ZEdWdWRDMXZhMkY1THo0S1BDOTBiM0ErQ2c9PSIsCiAgICAicG9zdC1jb25maWd1cmF0aW9uLXNjcmlwdCI6ICJJeUV2WW1sdUwySmhjMmdLWldOb2J5QWlhVzV6YVdSbElIUm9aU0J3YjNOMExXTnZibVpwWjNWeVlYUnBiMjR0YzJOeWFYQjBMaTR1SWdvPSIKICB9Cn0=\"\n  }\n}\n```\n\nDecode payload\n\n```text\n$ jq -r .\\\"ietf-sztp-bootstrap-server:output\\\".\\\"conveyed-information\\\" /tmp/post_rpc_input.json | base64 --decode | tail -n +2 | sed  '1i {' | jq . | tee /tmp/post_rpc_fixed.json\n{\n  \"ietf-sztp-conveyed-info:onboarding-information\": {\n    \"boot-image\": {\n      \"download-uri\": [\n        \"https://web:443/my-boot-image.img\",\n        \"ftps://web:990/my-boot-image.img\"\n      ],\n      \"image-verification\": [\n        {\n          \"hash-algorithm\": \"ietf-sztp-conveyed-info:sha-256\",\n          \"hash-value\": \"7b:ca:e6:ac:23:06:d8:79:06:8c:ac:03:80:e2:16:44:7e:40:6a:65:fa:d4:69:61:6e:05:ce:f5:87:dc:2b:97\"\n        }\n      ]\n    },\n    \"pre-configuration-script\": \"IyEvYmluL2Jhc2gKZWNobyAiaW5zaWRlIHRoZSBwcmUtY29uZmlndXJhdGlvbi1zY3JpcHQuLi4iCg==\",\n    \"configuration-handling\": \"merge\",\n    \"configuration\": \"PHRvcCB4bWxucz0iaHR0cHM6L2V4YW1wbGUuY29tL2NvbmZpZyI+CiAgPGFueS14bWwtY29udGVudC1va2F5Lz4KPC90b3A+Cg==\",\n    \"post-configuration-script\": \"IyEvYmluL2Jhc2gKZWNobyAiaW5zaWRlIHRoZSBwb3N0LWNvbmZpZ3VyYXRpb24tc2NyaXB0Li4uIgo=\"\n  }\n}\n```\n\nView the Audit Log\n\n```text\n$ docker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body --user my-admin@example.com:my-secret -H \"Accept:application/yang-data+json\" http://bootstrap:7080/restconf/ds/ietf-datastores:operational/wn-sztpd-1:audit-log\n\nHTTP/1.1 200 OK\nContent-Type: application/yang-data+json; charset=utf-8\nContent-Length: 648\nDate: Wed, 17 Aug 2022 19:35:34 GMT\nServer: \u003credacted\u003e\n\n{\n  \"wn-sztpd-1:audit-log\": {\n    \"log-entry\": [\n      {\n        \"timestamp\": \"2022-08-17T19:35:22Z\",\n        \"source-ip\": \"10.127.127.3\",\n        \"host\": \"bootstrap:9090\",\n        \"method\": \"POST\",\n        \"path\": \"/restconf/operations/ietf-sztp-bootstrap-server:get-bootstrapping-data\",\n        \"outcome\": \"success\"\n      }\n    ]\n  }\n}\n```\n\nView the Bootstrapping Log\n\n```text\n$ docker run --rm --network sztp_opi docker.io/curlimages/curl:8.5.0 --silent --fail-with-body --user my-admin@example.com:my-secret -H \"Accept:application/yang-data+json\" http://bootstrap:7080/restconf/ds/ietf-datastores:operational/wn-sztpd-1:devices/device=third-serial-number/bootstrapping-log\nHTTP/1.1 200 OK\nContent-Type: application/yang-data+json; charset=utf-8\nContent-Length: 1034\nDate: Wed, 24 Aug 2022 18:48:48 GMT\nServer: \u003credacted\u003e\n\n{\n  \"wn-sztpd-1:bootstrapping-log\": {\n    \"log-entry\": [\n      {\n        \"timestamp\": \"2022-08-24T18:47:54Z\",\n        \"source-ip\": \"10.127.127.3\",\n        \"method\": \"POST\",\n        \"path\": \"/restconf/operations/ietf-sztp-bootstrap-server:get-bootstrapping-data\",\n        \"return-code\": 200,\n        \"event-details\": {\n          \"get-bootstrapping-data-event\": {\n            \"passed-input\": {\n              \"hw-model\": \"model-x\",\n              \"os-name\": \"vendor-os\",\n              \"os-version\": \"17.3R2.1\",\n              \"signed-data-preferred\": [\n                null\n              ],\n              \"nonce\": \"BASE64VALUE=\"\n            },\n            \"selected-response\": \"catch-all-response\",\n            \"response-details\": {\n              \"managed-response\": {\n                \"conveyed-information\": {\n                  \"onboarding-information\": {\n                    \"referenced-definition\": \"my-onboarding-information\"\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    ]\n  }\n}\n```\n\nDownload the image and scripts\n\n```text\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"configuration\\\" /tmp/post_rpc_fixed.json | base64 --decode\n\u003ctop xmlns=\"https:/example.com/config\"\u003e\n  \u003cany-xml-content-okay/\u003e\n\u003c/top\u003e\n\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"pre-configuration-script\\\" /tmp/post_rpc_fixed.json | base64 --decode\n#!/bin/bash\necho \"inside the pre-configuration-script...\"\n\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"post-configuration-script\\\" /tmp/post_rpc_fixed.json | base64 --decode\n#!/bin/bash\necho \"inside the post-configuration-script...\"\n\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"boot-image\\\".\\\"download-uri\\\"[] /tmp/post_rpc_fixed.json\nhttps://web:443/my-boot-image.img\nftps://web:990/my-boot-image.img\n\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"boot-image\\\".\\\"image-verification\\\"[] /tmp/post_rpc_fixed.json\n{\n  \"hash-algorithm\": \"ietf-sztp-conveyed-info:sha-256\",\n  \"hash-value\": \"7b:ca:e6:ac:23:06:d8:79:06:8c:ac:03:80:e2:16:44:7e:40:6a:65:fa:d4:69:61:6e:05:ce:f5:87:dc:2b:97\"\n}\n\n$ URL=$(jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"boot-image\\\".\\\"download-uri\\\"[] /tmp/post_rpc_fixed.json)\n$ docker-compose run --rm -v /tmp:/tmp agent curl --output /tmp/$(basename ${URL}) --fail ${URL}\nCreating sztp_agent_run ... done\n  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current\n                                 Dload  Upload   Total   Spent    Left  Speed\n100 65536  100 65536    0     0  31.2M      0 --:--:-- --:--:-- --:--:-- 31.2M\n\n$ openssl dgst -sha256 -c /tmp/$(basename ${URL})\nSHA256(/tmp/my-boot-image.img)= 7b:ca:e6:ac:23:06:d8:79:06:8c:ac:03:80:e2:16:44:7e:40:6a:65:fa:d4:69:61:6e:05:ce:f5:87:dc:2b:97\n\n# Validate signature\n\n$ SIGNATURE=$(openssl dgst -sha256 -c /tmp/$(basename ${URL}) | awk '{print $2}')\n$ jq -r .\\\"ietf-sztp-conveyed-info:onboarding-information\\\".\\\"boot-image\\\".\\\"image-verification\\\"[] /tmp/post_rpc_fixed.json | grep $SIGNATURE\n  \"hash-value\": \"7b:ca:e6:ac:23:06:d8:79:06:8c:ac:03:80:e2:16:44:7e:40:6a:65:fa:d4:69:61:6e:05:ce:f5:87:dc:2b:97\"\n```\n\n## Run DHCP server only\n\n```text\ndocker-compose up --build dhcp\n```\n\n## Test DHCP server with NMAP\n\n```text\n$ docker-compose run --rm -T nmap\nCreating sztp_nmap_run ... done\nStarting Nmap 7.92 ( https://nmap.org ) at 2022-08-15 19:13 UTC\nPre-scan script results:\n| broadcast-dhcp-discover:\n|   Response 1 of 1:\n|     Interface: eth0\n|     IP Offered: 10.127.127.101\n|     DHCP Message Type: DHCPOFFER\n|     Server Identifier: 10.127.127.2\n|     IP Address Lease Time: 10m00s\n|     Subnet Mask: 255.255.255.0\n|     Bootfile Name: test.cfg\n|_    TFTP Server Name: w.x.y.z\nWARNING: No targets were specified, so 0 hosts scanned.\nNmap done: 0 IP addresses (0 hosts up) scanned in 10.25 seconds\n```\n\n## Test DHCP server with DHCP client\n\n```text\n$ docker-compose run --rm -T client\nCreating sztp_client_run ... done\nInternet Systems Consortium DHCP Client 4.4.3\nCopyright 2004-2022 Internet Systems Consortium.\nAll rights reserved.\nFor info, please visit https://www.isc.org/software/dhcp/\n\nRTNETLINK answers: Operation not permitted\nListening on LPF/eth0/02:42:0a:7f:7f:03\nSending on   LPF/eth0/02:42:0a:7f:7f:03\nSending on   Socket/fallback\nDHCPDISCOVER on eth0 to 255.255.255.255 port 67 interval 8 (xid=0xb3f32238)\nDHCPOFFER of 10.127.127.102 from 10.127.127.2\nDHCPREQUEST for 10.127.127.102 on eth0 to 255.255.255.255 port 67 (xid=0xb3f32238)\nDHCPACK of 10.127.127.102 from 10.127.127.2 (xid=0xb3f32238)\nRTNETLINK answers: Operation not permitted\nbound to 10.127.127.102 -- renewal in 263 seconds.\n```\n\nsee result\n\n```text\n$ docker-compose exec client cat /var/lib/dhclient/dhclient.leases\nlease {\n  interface \"eth0\";\n  fixed-address 10.127.127.100;\n  filename \"grubx64.efi\";\n  option subnet-mask 255.255.255.0;\n  option sztp-redirect-urls \"https://bootstrap:9090/restconf/operations/ietf-sztp-bootstrap-server:get-bootstrapping-data\";\n  option dhcp-lease-time 600;\n  option tftp-server-name \"w.x.y.z\";\n  option bootfile-name \"test.cfg\";\n  option dhcp-message-type 5;\n  option dhcp-server-identifier 10.127.127.2;\n  renew 1 2022/08/15 19:16:40;\n  rebind 1 2022/08/15 19:20:50;\n  expire 1 2022/08/15 19:22:05;\n}\n```\n\n## Test mDNS server with NMAP\n\n```text\n$ docker-compose run --rm -T nmapmdnsclient\nStarting Nmap 7.93 ( https://nmap.org ) at 2022-10-27 21:14 UTC\nNmap scan report for avahi (10.127.127.4)\nHost is up (0.000082s latency).\nrDNS record for 10.127.127.4: sztp-avahi-1.sztp_opi\n\nPORT     STATE  SERVICE\n5353/tcp closed mdns\nMAC Address: 02:42:0A:7F:7F:04 (Unknown)\n\nNmap done: 1 IP address (1 host up) scanned in 0.34 seconds\n```\n\n## Run HTTPs server only\n\n```text\ndocker-compose up --build web\n```\n\n## Test HTTPs server only\n\n```text\ndocker run --rm --user 0 --network sztp_opi -v sztp_client-certs:/certs docker.io/curlimages/curl:8.5.0 --insecure --fail-with-body --key /certs/third_private_key.pem --cert /certs/third_my_cert.pem --cacert /certs/opi.pem --output /tmp/third-boot-image.tst \"https://web:443/third-boot-image.img\"\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopiproject%2Fsztp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fopiproject%2Fsztp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopiproject%2Fsztp/lists"}