trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 29 Sep 2023 04:15:31 +0000 (05:15 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 29 Sep 2023 04:15:31 +0000 (05:15 +0100)
commit81741b226da1e50bd933a93f949c294f4987c733
treeaacf95d5a71ab82bef5a6cdd5e1ef94dcfb2a944
parentb65cc5fd10ac3d102d8c7114a8acf18236666a51
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c