trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Mon, 15 Jul 2024 07:42:59 +0000 (09:42 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Mon, 15 Jul 2024 07:42:59 +0000 (09:42 +0200)
commit4163976069ceb63f1bea9602fbdfb4441fcbb586
tree355c31d659b48fbe2f8b03eaa2067194c265af15
parentd5630ec2fc1da5de1e4f6c079b3805cafc4ca80a
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c