trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sat, 9 Dec 2023 15:48:39 +0000 (16:48 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 9 Dec 2023 15:48:39 +0000 (16:48 +0100)
commit601097e619a95f4c9a1fbc2421df76161d981111
tree2404af9d5e9d34cfdfc422710a49e4aaf1e8a71e
parent55556848258e06f92c8a8fb5a47d3d2bc196f45c
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c