Closed Bug 1471185 Opened 6 years ago Closed 6 years ago

Implement COSE XPI signing in Autograph

Categories

(Cloud Services :: Security, enhancement)

enhancement
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: jvehent, Assigned: u581815)

References

(Blocks 1 open bug)

Details

Attachments

(2 files)

53 bytes, text/x-github-pull-request
Details | Review
4.30 MB, application/x-compressed-tar
Details
Add support for COSE signatures in the XPI signer, in parallel of PKCS7 signatures, then tell AMO to use it.
https://github.com/mozilla-services/autograph/pull/76
Blocks: 1471186
Attached file xpi-cose-signing PR
Attached file autograph-714ba248.tgz
tarball of 10 signed XPIs for commit 714ba24847bfdc0dff0ec879f18969ae05e72099 of the PR from running the build_test_xpis.sh against the stage and prod autograph configs will post QA results in the PR
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Is manual testing required on this bug? If yes, please provide some STR and the proper extension(if required) or set the “qe-verify -“ flag.

Thanks!
Flags: needinfo?(gguthe)
(In reply to CosminB from comment #3)
> Is manual testing required on this bug? If yes, please provide some STR and
> the proper extension(if required) or set the “qe-verify -“ flag.
> 
> Thanks!

I ran through the QA myself and I'm looking to automate this eventually, but I'll keep that in mind.
Flags: needinfo?(gguthe)
Flags: qe-verify-
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: