From 39d5824bd89ee9c6d4190c437e3036e3b92084d7 Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Fri, 1 Nov 2024 05:23:37 +0100 Subject: [PATCH] trust machine keyring (MoK) by default Debian always trusted keys in MoK by default. Upstream made it conditional on a new EFI variable being set. To keep backward compatibility skip this check. Gbp-Pq: Topic features/all/db-mok-keyring Gbp-Pq: Name trust-machine-keyring-by-default.patch --- security/integrity/platform_certs/machine_keyring.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/integrity/platform_certs/machine_keyring.c b/security/integrity/platform_certs/machine_keyring.c index 7aaed7950b6..416da7b788a 100644 --- a/security/integrity/platform_certs/machine_keyring.c +++ b/security/integrity/platform_certs/machine_keyring.c @@ -69,8 +69,7 @@ bool __init trust_moklist(void) if (!initialized) { initialized = true; - if (uefi_check_trust_mok_keys()) - trust_mok = true; + trust_mok = true; } return trust_mok; -- 2.30.2