trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 3 Nov 2023 04:15:32 +0000 (05:15 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 3 Nov 2023 04:15:32 +0000 (05:15 +0100)
commitbb390f73050757d261dbcff17b409d75e462da9d
tree1992e710b4747b90fb95260f18b5f307be5ca193
parent1366e310a1be483acf6a5a366184b832c36e23df
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c