Lines Matching full:uefi
17 * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot
42 * Look to see if a UEFI variable called MokIgnoreDB exists and return true if
45 * This UEFI variable is set by the shim if a user tells the shim to not use
46 * the certs/hashes in the UEFI db variable for verification purposes. If it
98 * Load the certs contained in the UEFI MokListRT database into the
102 * that fails, this routine uses the MokListRT ordinary UEFI variable.
121 rc = parse_efi_signature_list("UEFI:MokListRT (MOKvar table)", in load_moklist_certs()
138 rc = parse_efi_signature_list("UEFI:MokListRT", in load_moklist_certs()
148 pr_info("Couldn't get UEFI MokListRT\n"); in load_moklist_certs()
153 * load_uefi_certs() - Load certs from UEFI sources
155 * Load the certs contained in the UEFI databases into the platform trusted
156 * keyring and the UEFI blacklisted X.509 cert SHA256 hashes into the blacklist
171 pr_err("Reading UEFI Secure Boot Certs is not supported on T2 Macs.\n"); in load_uefi_certs()
187 pr_err("MODSIGN: Couldn't get UEFI db list\n"); in load_uefi_certs()
189 rc = parse_efi_signature_list("UEFI:db", in load_uefi_certs()
203 pr_info("Couldn't get UEFI dbx list\n"); in load_uefi_certs()
205 rc = parse_efi_signature_list("UEFI:dbx", in load_uefi_certs()
224 rc = parse_efi_signature_list("UEFI:MokListXRT", in load_uefi_certs()