trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Thu, 2 Jan 2025 13:31:22 +0000 (14:31 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 2 Jan 2025 13:31:22 +0000 (14:31 +0100)
commita26a8148429f3479fd00e01d9ea8b0c81fec2664
treeac60c5d6ee78c52d3df43f09dbcc899d82505ac0
parent59b545a000a44d546324d2a0e6fef7c6d9c269f3
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c