trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Mon, 26 Aug 2024 19:47:39 +0000 (21:47 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Mon, 26 Aug 2024 19:47:39 +0000 (21:47 +0200)
commit0790400486ea0427b1fdbcbd9ff472a52c4adf0d
treedc1ec3bc21b2e2adab79aa768afed11471a04d88
parentcae83c99def7c0ae94c978d584ca971aad1c7724
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c