trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 3 May 2024 12:36:41 +0000 (14:36 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 3 May 2024 12:36:41 +0000 (14:36 +0200)
commit2aaaa295f3a82a1be00fdcd1ff126c4f6d34b8f5
treee935d4a6cf2c02faf96a7acdb15e1666bb73f90f
parent717ba77db1dae016d605893c74f44d2edcbb2bdb
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c