Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #34121

Closed (moved)
(moved)
Open
Created May 05, 2020 by Matthew Finkel@sysrqb

Create a Tor Browser Nightly signing machine

Recently, Tor Browser began providing automatic nightly updates (#18867 (moved)), and those are now hosted on nightlies.tbb.torproject.org (#32800 (moved)). All of the building and signing machines are currently hosted externally. This ticket is for moving the signing operation onto a TPA maintained server.

It will need about 40 GB of disk space, memory requirement should be small (1 or 2 GB, should be more than enough).

As the end result, every day this server will receive files from an external server (pushed or pulled, whichever makes the most sense), sign them, and then copy them to nightlies.tbb.torproject.org for serving.

The server will hold a passphrase-protected OpenPGP private key and a passphrase-protected NSS DB containing a private signing key.

This server should be as network-access-restricted as possible, while still being usable.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking