trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sun, 29 Jan 2023 12:33:36 +0000 (12:33 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sun, 29 Jan 2023 12:33:36 +0000 (12:33 +0000)
commitac33cbe770a2f162671e806b32169bb1663aaff5
treeb4044965558c693c533e0e4cdc33476a6b74fa2c
parent343917b97cb78bb645a5372fa654826462861694
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c