trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Thu, 31 Aug 2023 20:24:51 +0000 (21:24 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 31 Aug 2023 20:24:51 +0000 (21:24 +0100)
commit8d87a79f6819c51c0159b957ef410351c44afda8
treeb0a77c8daddd6ec8cb70ed252c3b998bd59cf7a1
parentea1d407aa36f96d51bd040cdb26a646fd5985454
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c