ekkoBSD 2.1 amd64 verified PXE boot tree

Point DHCP option 67 (boot-file-name) at pxeboot and serve this directory as
the TFTP root. This bundle boots the signed installer/rescue environment.

When no installation media is mounted, the installer defaults to the signed
release sets at
https://mirror.ekkobsd.org/releases/2.1/amd64/sets/. Interactive and unattended
installs may instead select a custom HTTPS, FTP, SCP, or local source. Every
source must provide SHA256 and SHA256.sig; each selected object is verified
before storage is modified. SCP also requires a pre-provisioned host key and
non-interactive public-key authentication.
