trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Thu, 7 Sep 2023 07:39:52 +0000 (08:39 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 7 Sep 2023 07:39:52 +0000 (08:39 +0100)
commit7c8d8cfdd55b76245c982a4f2154e6cab1a98932
treef3ac6f2dfaf7564b2b6785e81c528c57c8cd681c
parentef24d1b3163cdab6339d572c7c521329565d15b0
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c