trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Mon, 8 May 2023 20:16:50 +0000 (21:16 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Mon, 8 May 2023 20:16:50 +0000 (21:16 +0100)
commit21d59c80a2a530976d23554115e6a98129e06c56
treed36dd7fdabf757a869ddd616c9531f0aa44497de
parent745cef688fab18fd0d672757bb268101668816cb
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c