Closed Bug 833836 Opened 13 years ago Closed 13 years ago

Witness the root key ceremony for production packaged app signing key

Categories

(Security Assurance :: General, task)

Other
Other
task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: rtilder, Assigned: kang)

Details

No description provided.
As bug 822944 has been fixed I believe the current certs (production and reviewers) are valid and live. I have witnessed the production and reviewer root CAs (so, 2 CAs total) on 2013-02-26 in Mozilla's Mountain View offices, server room. Details about the process are documented here: https://mana.mozilla.org/wiki/display/SECURITY/HSM+Policy#HSMPolicy-Keyceremonyprocess In particular, the ceremony was filmed, and a paper has been signed from the witnesses. This paper is currently stored in Opsec's safe in MTV offices. This document (as in a scan of this document) and the video will be saved and backed up. The locations will be documented in the aforementionned process documentation. This documentation can, to the best of my knowledge, be used in order to receive a certification from an authorized external auditor, that the key ceremony has been properly performed, in an honest, objective and secure way.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Component: Operations Security (OpSec): General → General
Product: mozilla.org → Enterprise Information Security
You need to log in before you can comment on or make changes to this bug.