trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 22 Nov 2024 22:27:23 +0000 (23:27 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 22 Nov 2024 22:27:23 +0000 (23:27 +0100)
commitc8daad6f4014470fb530408ffde3a05d763337c6
treef8a242cb8fa17892dcc829425ef248c7078bd751
parentba12d53af98b7cb2f858d40462fe836a193f0752
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c