- Sources: primary, discussion
- Summary: Mozilla rotated the GPG subkey used to sign certain Firefox and Thunderbird artifacts, namely Linux tarballs, RPM packages, and checksums files, after an unencrypted copy of it reached a private repository. Mozilla states its audit records show no evidence that the key was accessed by an unauthorized party, that repository access was limited to people who already held the key, and that for most users no action is required. Releases signed with the previous key stop verifying once the revocation is imported.
- Why it matters: Firefox RPM users on Fedora 42 and older, RHEL, Rocky, AlmaLinux, and openSUSE must remove the old key by hand before importing the new one, or updates fail with a key mismatch, while Fedora 43 and later need no manual step.
send feedback on this story