Patch Set 5:
If we are going with https and security way, what about IMAGE_TRUST_CMD? It may allow verifying images downloaded by http/https. Although I don't know whether it is enabled by default.
I already created a dedicated Patch for this. See https://review.coreboot.org/c/coreboot/+/31087
To view, visit change 31086. To unsubscribe, or for help writing mail filters, visit settings.