Closed Bug 1546399 Opened 6 years ago Closed 6 years ago

resign listed webexts with COSE

Categories

(Cloud Services :: Operations: Autograph, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: u581815, Unassigned)

References

(Blocks 1 open bug)

Details

Splitting this out from bug 1545109. We might want to move this to the AMO component too.

This is for resigning addons listed on AMO with COSE (and whatever autograph needs to do to support that).

Waiting for people to resign unlisted addons to will take longer, but getting the listed addons resigned is a necessary step towards require COSE signatures in Fx nightly and beta.

Blocks: autograph

step towards require COSE signatures in Fx nightly and beta.

Is there a timeline when the resigning should be happening at the latest?

(In reply to Christopher Grebs [:cgrebs] from comment #1)

step towards require COSE signatures in Fx nightly and beta.

Is there a timeline when the resigning should be happening at the latest?

I originally said we could do end of April, but that doesn't seem feasible. I thought we had previously done a similar resigning.

Not sure which Fx and ESR releases we're targeting, but my understanding is:

  • we want to leave a window of at least six months for unlisted addons to resign
  • the sooner we resign listed addons the sooner we can start testing Fx nightly and beta

Adding Shell and Dan (I had mentioned bug 1545109 in the email thread but we split this one out)

From my last conversations with Jorge this work is currently planned to start at the beginning of Q3. My understanding is we're targetting FF70. This would mean 70 would be in nightly at the beginning of July which is also the start of Q3.

If there's a way to run it early than July we will, but since we have a lot of work already underway and Q2 is a short quarter with the all-hands, I'd be hesitant to commit to anything earlier than July.

Closing since armagaddon 2.0 motivated rethinking XPI signing in general.

Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.