trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sat, 7 Jan 2023 13:53:00 +0000 (13:53 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 7 Jan 2023 13:53:00 +0000 (13:53 +0000)
commit612551645e1b703e6799e36e616de59d4ab80d22
treed633eac0f0561c60fadd4f47ad63c18e0332b40e
parent550d7e2e206d567e2da1898e59200f8959da7f66
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c