trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 1 Nov 2024 04:23:37 +0000 (05:23 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 1 Nov 2024 04:23:37 +0000 (05:23 +0100)
commit39d5824bd89ee9c6d4190c437e3036e3b92084d7
treec53a4c04a638352da10799df1a510f1f03a2bdb8
parent1b7845307abeb2b4983283ff5b023508f87bfec4
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c