Mozilla宣布更新用于签署Firefox和Thunderbird发行版的GPG签名子密钥[1]。此举源于之前的子密钥未加密副本被意外提交到私有GitHub仓库[1]。Mozilla审查后未发现密钥被未授权方访问的证据,已撤销旧密钥并采取防护措施[1]。
旧GPG签名子密钥指纹为14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353,新密钥指纹为827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3,新签名子密钥过期日期为2028-08-05[1]。
对大多数用户而言无需采取行动[1]。使用Firefox RPM包的用户需视系统版本而定采取相应步骤:Fedora 43及更高版本无需特殊操作,而Fedora 42及更早版本、RHEL、Rocky和Almalinux用户需手动删除旧密钥后导入新密钥;openSUSE和SUSE发行版用户同样需执行手动删除和导入操作[1]。仅手动验证GPG签名的用户需更新密钥信息[1]。Thunderbird不提供官方RPM包,无需RPM特定操作[1]。
Mozilla has announced an update to the GPG signing subkey used for Firefox and Thunderbird releases [1]. The change was prompted by the accidental commitment of an unencrypted copy of the previous subkey to a private GitHub repository [1]. Following a security review, Mozilla found no evidence that unauthorized parties accessed the key and has revoked the old key while implementing protective measures [1].
The old GPG signing subkey fingerprint is 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353, and the new one is 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3, with an expiration date of August 5, 2028 [1]. For most users, no action is required [1]. However, those manually verifying GPG signatures and users of Firefox RPM packages on specific Linux distributions will need to take steps [1]. Fedora 43 and later versions require no special action, while Fedora 42 and earlier versions, as well as RHEL, Rocky, and Almalinux systems, must manually remove the old key before importing the new one [1]. Users of openSUSE and SUSE distributions face the same requirement [1]. Thunderbird does not provide official RPM packages, so no RPM-specific actions are necessary for that application [1].