trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Wed, 15 Feb 2023 05:56:21 +0000 (05:56 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Wed, 15 Feb 2023 05:56:21 +0000 (05:56 +0000)
commit2d2ab9631b20be4972dfc6f1d5edfa43738f1687
tree3bfcc0e85ce0acfbec73322023e710e5a659688e
parentfdd5f0ca89fd4ef088058035031aad72ea20c415
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c