trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 21 Jun 2024 03:59:28 +0000 (05:59 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 21 Jun 2024 03:59:28 +0000 (05:59 +0200)
commit9f95491df0de731f6cd2af0b4fbcefdd1ac5a78a
tree227c2bc22bdf87198e5be81481cd459dbb08226f
parentfa89cedd8feba075f8aab7f1a5c834375b4ebc8d
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c