enforce kernel module software signature verification [module signing] / disallow kernel module loading by default

Therefore re-enabled only allowing loading signed modules: