trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 25 Apr 2025 19:51:43 +0000 (21:51 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 25 Apr 2025 19:51:43 +0000 (21:51 +0200)
commit09ae18edad13d4f1890cf2577ee2b85babdb2dd3
tree2d0b91c2022ce24be888f6eb00a673a4393c111e
parent5cdb2f3816ca43f08ae74f068d9a15ecf9728fd1
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c