File: trust-machine-keyring-by-default.patch

package info (click to toggle)
linux 6.1.153-1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm-proposed-updates
  • size: 1,496,348 kB
  • sloc: ansic: 23,476,872; asm: 266,650; sh: 110,570; makefile: 49,899; python: 36,950; perl: 36,836; cpp: 6,055; yacc: 4,908; lex: 2,725; awk: 1,440; ruby: 25; sed: 5
file content (16 lines) | stat: -rw-r--r-- 537 bytes parent folder | download | duplicates (7)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Author: Luca Boccassi <bluca@debian.org>
Description: trust machine keyring (MoK) by default
 Debian always trusted keys in MoK by default. Upstream made it conditional on
 a new EFI variable being set. To keep backward compatibility skip this check.
--- a/security/integrity/platform_certs/machine_keyring.c
+++ b/security/integrity/platform_certs/machine_keyring.c
@@ -69,8 +69,7 @@
 	if (!initialized) {
 		initialized = true;
 
-		if (uefi_check_trust_mok_keys())
-			trust_mok = true;
+		trust_mok = true;
 	}
 
 	return trust_mok;