trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Wed, 13 Sep 2023 20:20:48 +0000 (21:20 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Wed, 13 Sep 2023 20:20:48 +0000 (21:20 +0100)
commit4bc778e02aa23773577217fc7d1f5afebe64d6a3
treeb52faba80f5a587ed6850d10c736964d04f9a729
parent81b4fdb276bed92a2f37d26ac91f63a5d97c30c5
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c