trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Thu, 1 Feb 2024 08:05:49 +0000 (09:05 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 1 Feb 2024 08:05:49 +0000 (09:05 +0100)
commit3eb67fa2c865a6d72ec42d4b2abdcd93935d7dbc
tree95a98d5a37e3b84eb1326082afdbab0c97650001
parentbe238e78da48929a7cbd634d5a0bf6f0877136e8
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c