Updated GPG Key for Signing Firefox and Thunderbird Releases
Mozilla has updated its GPG signing subkey for Firefox and Thunderbird after a previous key was inadvertently exposed in a private repository. Users on certain Linux distributions may need to manually remove the old key to ensure continued update functionality.
Why it matters
This is a critical security maintenance update that ensures the integrity of software updates for millions of users.
Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.
Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means.
We have revoked the previous signing key and added safeguards to prevent similar issues in the future.
There are two cases where you may need to take action:
Thunderbird does not provide official RPM packages, so there is no RPM-specific action required.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in