summaryrefslogtreecommitdiff
path: root/Cryptlib/OpenSSL/crypto/objects/obj_xref.c
diff options
context:
space:
mode:
authorEric Snowberg <eric.snowberg@oracle.com>2022-02-17 18:29:58 -0500
committerPeter Jones <pjones@redhat.com>2022-05-04 14:58:23 -0400
commit2670c6a17edb239949152c471445fc533d8525aa (patch)
tree02f664be337bf7da50d405077f8e96b2adb7056d /Cryptlib/OpenSSL/crypto/objects/obj_xref.c
parent6aac5959bbb6adbe5f061a7f95139ab794bcfda7 (diff)
downloadefi-boot-shim-2670c6a17edb239949152c471445fc533d8525aa.tar.gz
efi-boot-shim-2670c6a17edb239949152c471445fc533d8525aa.zip
Allow MokListTrusted to be enabled by default
Within previous versions of shim the MokListTrusted var did not exist. The user had to opt in to using the feature. Change the default behavior to an opt out model. Since old shims will not have the BS MokListTrusted set, use inverse logic that sets the MokListTrustedRT to 1 when the boot service variable is missing. Many Linux distros carry out of tree patches to trust the mok keys by default. These out of tree patches can be dropped when using a Linux kernel that supports MokListTrustedRT. Signed-off-by: Eric Snowberg <eric.snowberg@oracle.com>
Diffstat (limited to 'Cryptlib/OpenSSL/crypto/objects/obj_xref.c')
0 files changed, 0 insertions, 0 deletions