Closed
Bug 833836
Opened 13 years ago
Closed 13 years ago
Witness the root key ceremony for production packaged app signing key
Categories
(Security Assurance :: General, task)
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: rtilder, Assigned: kang)
Details
No description provided.
| Assignee | ||
Comment 1•13 years ago
|
||
As bug 822944 has been fixed I believe the current certs (production and reviewers) are valid and live.
I have witnessed the production and reviewer root CAs (so, 2 CAs total) on 2013-02-26 in Mozilla's Mountain View offices, server room.
Details about the process are documented here: https://mana.mozilla.org/wiki/display/SECURITY/HSM+Policy#HSMPolicy-Keyceremonyprocess
In particular, the ceremony was filmed, and a paper has been signed from the witnesses.
This paper is currently stored in Opsec's safe in MTV offices. This document (as in a scan of this document) and the video will be saved and backed up. The locations will be documented in the aforementionned process documentation.
This documentation can, to the best of my knowledge, be used in order to receive a certification from an authorized external auditor, that the key ceremony has been properly performed, in an honest, objective and secure way.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Updated•10 years ago
|
Component: Operations Security (OpSec): General → General
Product: mozilla.org → Enterprise Information Security
You need to log in
before you can comment on or make changes to this bug.
Description
•