trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Sat, 2 Aug 2025 13:13:02 +0000 (15:13 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 2 Aug 2025 13:13:02 +0000 (15:13 +0200)
commit381453e49dc5707b1fa70221112909e9cabef506
tree823bbc8975666e81cfd6f8832443cb010cbc295f
parenteadc02c8ca309d6844d2e1b619d46ca0c4d31af3
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c