Skip to content

Bug 41059: Update keyring/torbrowser.gpg with updated key

boklm requested to merge boklm/tor-browser-build:bug_41059 into main

Merge Info

Related Issues

Backporting

Timeline

  • Immediate: patchset needed as soon as possible
  • Next Minor Stable Release: patchset that needs to be verified in nightly before backport
  • Eventually: patchset that needs to be verified in alpha before backport
  • No Backport (preferred): patchset for the next major stable

(Optional) Justification

  • Emergency security update: patchset fixes CVEs, 0-days, etc
  • Censorship event: patchset enables censorship circumvention
  • Critical bug-fix: patchset fixes a bug in core-functionality
  • Consistency: patchset which would make development easier if it were in both the alpha and release branches; developer tools, build system changes, etc
  • Sponsor required: patchset required for sponsor
  • Other: please explain

Issue Tracking

Review

Request Reviewer

  • Request review from an applications developer depending on modified system:
    • NOTE: if the MR modifies multiple areas, please /cc all the relevant reviewers (since gitlab only allows 1 reviewer)
    • accessibility : henry
    • android : clairehurst, dan
    • build system : boklm
    • extensions : ma1
    • firefox internals (XUL/JS/XPCOM) : ma1
    • fonts : pierov
    • frontend (implementation) : henry
    • frontend (review) : donuts, richard
    • localization : henry, pierov
    • macos : clairehurst, dan
    • nightly builds : boklm
    • rebases/release-prep : boklm, dan, ma1, pierov, richard
    • security : ma1
    • signing : boklm, richard
    • updater : pierov
    • misc/other : pierov, richard

Change Description

Tor Browser gpg key has been updated with a new expiration date on its current subkey.

How Tested

Running ./tools/keyring/list-all-keyrings before and after the change:

--- /tmp/1.txt	2024-01-10 10:11:10.053000000 +0100
+++ /tmp/2.txt	2024-01-10 10:19:55.023000000 +0100
@@ -216,7 +216,7 @@
 sub   rsa4096/2E1AC68ED40814E0 2014-12-15 [S] [expired: 2017-08-25]
 sub   rsa4096/2D000988589839A3 2014-12-15 [S] [revoked: 2015-08-26]
 sub   rsa4096/D1483FA6C3C07136 2016-08-24 [S] [expired: 2018-08-24]
-sub   rsa4096/E53D989A9E2D47BF 2021-09-17 [S] [expires: 2024-02-19]
+sub   rsa4096/E53D989A9E2D47BF 2021-09-17 [S] [expires: 2024-08-23]
 
 ./keyring/ubuntu.gpg
 --------------------

Also the output from file is still the same:

$ file keyring/torbrowser.gpg
keyring/torbrowser.gpg: PGP/GPG key public ring (v4) created Mon Dec 15 10:54:02 2014 RSA (Encrypt or Sign) 4096 bits MPI=0xd032cf90e5c02c85...
Edited by boklm

Merge request reports