trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Fri, 7 Feb 2025 09:43:47 +0000 (10:43 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 7 Feb 2025 09:43:47 +0000 (10:43 +0100)
commit865486fdd772eacfe13f5293078bbc57902cb753
tree8253c826adf75871ce5412324ed4cf905d9215b0
parent0f87cb8e9056268fa65b9bb720c95db49046bb2d
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c