Re: [PATCH v2 6/7] efi: Allow the "db" UEFI variable to be suppressed

From: James Morris
Date: Tue Dec 11 2018 - 13:49:31 EST


On Sun, 9 Dec 2018, Nayna Jain wrote:

> From: Josh Boyer <jwboyer@xxxxxxxxxxxxxxxxx>
>
> If a user tells shim to not use the certs/hashes in the UEFI db variable
> for verification purposes, shim will set a UEFI variable called
> MokIgnoreDB. Have the uefi import code look for this and ignore the db
> variable if it is found.
>
> Signed-off-by: Josh Boyer <jwboyer@xxxxxxxxxxxxxxxxx>
> Signed-off-by: David Howells <dhowells@xxxxxxxxxx>
> Acked-by: Nayna Jain <nayna@xxxxxxxxxxxxx>
> Acked-by: Serge Hallyn <serge@xxxxxxxxxx>


Reviewed-by: James Morris <james.morris@xxxxxxxxxxxxx>


--
James Morris
<jmorris@xxxxxxxxx>