trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 14 Jul 2023 03:46:44 +0000 (04:46 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 14 Jul 2023 03:46:44 +0000 (04:46 +0100)
commit988c8c4ad9a3cb77019e9301627beeaa7bc97911
tree8cd393c615a0c3031b273fb657068ab55ef01421
parentcf57df6bffcbcc31cb4a95cb8cfa310a828091f5
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c