Mozilla Automation TeamBen Hearsum4 min readintro
Updated GPG key for signing Firefox and Thunderbird Releases
Summary
Mozilla rotated its GPG signing subkey for Firefox and Thunderbird after the previous subkey was accidentally exposed. Users must import the new key (and revocation) and, on older RPM‑based systems, manually replace the old key to keep updates working.
- New signing subkey fingerprint is 827E658608679618CD349F93678E455D7676AA3, expires 2028‑08‑05; old key revoked.
- If you verify signatures, import the new public key and the revocation for the old key.
- RPM users on Fedora 42/RHEL/AlmaLinux/Rocky and openSUSE must manually remove the old gpg‑pubkey and import the new one before updates succeed.
- Fedora 43+ will auto‑import the new key on the next dnf update; no manual steps required.
Package maintainers and security‑conscious users need to update the GPG key to verify Firefox/Thunderbird releases and avoid broken updates.
5/10


