trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sat, 22 Apr 2023 18:48:02 +0000 (19:48 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 22 Apr 2023 18:48:02 +0000 (19:48 +0100)
commitb2f92be57d28f6acf0209d75a3912a7910f9d99b
tree693e12d13ccfe56727885a3599aedab85f93520b
parent5731385eb579757f563ab11693b6a8196b720053
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c