trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sun, 5 Mar 2023 15:33:00 +0000 (15:33 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sun, 5 Mar 2023 15:33:00 +0000 (15:33 +0000)
commit60e33dfedd328fbe8afd9401b9ad4b04c09e84b8
tree21d8bd255536e17396c5eff9bc3bf9ce72b1c6aa
parent806f1f1e1623e11f83527b023ff67b5259ca4c4d
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c