trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Thu, 22 May 2025 18:32:07 +0000 (20:32 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 22 May 2025 18:32:07 +0000 (20:32 +0200)
commit8eba7dd188c655595ea1075c2ab2c3bac1aec280
treeafc751a477570afa65c9e14baadea5466581804c
parentf002594631c37951e9ecdee235bc1a1e9e1967a4
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c