aboutsummaryrefslogtreecommitdiffstats
path: root/security/integrity/integrity.h
diff options
context:
space:
mode:
authorEric Snowberg <eric.snowberg@oracle.com>2022-01-25 21:58:33 -0500
committerJarkko Sakkinen <jarkko@kernel.org>2022-03-08 13:55:52 +0200
commit74f5e30051399d60dbce4296dbfd833212df13f1 (patch)
tree76231062b60ea35b4b2cbe6cb5890b844ad54681 /security/integrity/integrity.h
parentefi/mokvar: move up init order (diff)
downloadlinux-dev-74f5e30051399d60dbce4296dbfd833212df13f1.tar.xz
linux-dev-74f5e30051399d60dbce4296dbfd833212df13f1.zip
integrity: Trust MOK keys if MokListTrustedRT found
A new Machine Owner Key (MOK) variable called MokListTrustedRT has been introduced in shim. When this UEFI variable is set, it indicates the end-user has made the decision themselves that they wish to trust MOK keys within the Linux trust boundary. It is not an error if this variable does not exist. If it does not exist, the MOK keys should not be trusted within the kernel. Signed-off-by: Eric Snowberg <eric.snowberg@oracle.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Diffstat (limited to 'security/integrity/integrity.h')
0 files changed, 0 insertions, 0 deletions