started · updated
Mozilla rotates Firefox and Thunderbird signing keys
Mozilla has rotated a GPG signing subkey used for certain Firefox and Thunderbird software artifacts after an unencrypted copy of the key was inadvertently committed to a private GitHub repository. The affected artifacts include Linux tarballs, RPM packages, and checksum files.
Mozilla stated that an audit of its records showed no evidence that an unauthorized party accessed the key. Access to the private repository was restricted to a small group of employees who already possessed authorized access to the key through other means. Despite the lack of evidence of misuse, the organization revoked the exposed subkey and implemented additional safeguards to prevent future occurrences.
For most users, no action is required. However, users who manually verify GPG signatures or those using specific Linux distributions may need to intervene. Fedora 43 and later versions should handle the update automatically. Users on Fedora 42 and earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE-based distributions may need to manually remove the old key before importing the new one to ensure successful updates.
Entities
Firefox · GitHub · Mozilla · Thunderbird