Use upstream code for module verification via MoK

Drop out-of-tree patches and use new facilities from kernel 5.18 to load MoK certs. Only two patches remain, one for blocklisting and one to avoid needing to set an EFI boolean variable to load MoK certs, given it would break backward compatibility. Maybe we can ship a NEWS entry telling users to run mokutil --trust-mok and then drop the patch in Trixie?

Edited by Luca Boccassi

Merge request reports

Loading