[tor-bugs] #26536 [Applications/Tor Browser]: Create APK signing keys

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun May 19 00:59:05 UTC 2019


#26536: Create APK signing keys
-------------------------------------------------+-------------------------
 Reporter:  sysrqb                               |          Owner:  tbb-
                                                 |  team
     Type:  task                                 |         Status:
                                                 |  reopened
 Priority:  Medium                               |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tbb-mobile, TBA-a3, tbb-8.5-must,    |  Actual Points:
  TorBrowserTeam201905                           |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
                                                 |  Sponsor8
-------------------------------------------------+-------------------------

Comment (by sysrqb):

 I created a new certificate that expires in 5475 days (using the same key
 material). Now it's valid until `May 14 21:58:42 2034 GMT`.

 {{{
 -----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA512

 $ pkcs15-tool -r 3 | openssl x509 -noout -text -fingerprint
 Using reader with a card: Nitrokey Nitrokey Pro (000039610000000000000000)
 00 00
 Certificate:
     Data:
         Version: 3 (0x2)
         Serial Number:
             ba:2d:f6:13:08:4d:2b:fd
     Signature Algorithm: sha256WithRSAEncryption
         Issuer: CN = Tor Browser, O = The Tor Project, L = Seattle, ST =
 WA, C = US
         Validity
             Not Before: May 18 21:58:42 2019 GMT
             Not After : May 14 21:58:42 2034 GMT
         Subject: CN = Tor Browser, O = The Tor Project, L = Seattle, ST =
 WA, C = US
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
                 Public-Key: (4096 bit)
                 Modulus:
                     00:f3:ee:23:1d:69:ce:43:5f:32:4a:d4:aa:39:8a:
                     ef:31:31:87:6a:e7:45:63:42:8b:61:f6:ad:8c:65:
                     c5:22:fd:df:6e:dc:c2:4f:6e:61:5a:d9:78:59:8f:
                     8c:59:5c:63:2f:2d:51:df:82:25:ec:26:74:2a:f7:
                     47:9d:8b:45:ee:a3:79:ac:7c:21:e8:66:5b:df:b2:
                     ac:8f:00:08:c0:b4:7a:2b:a8:9c:aa:39:c5:81:c0:
                     82:7d:35:59:9d:a3:d6:e0:fd:40:45:dd:4e:bd:ee:
                     de:39:79:0b:e6:dd:63:0b:6b:a7:90:8b:eb:39:e2:
                     0e:aa:9c:42:db:cc:5b:b7:b4:f7:a4:3f:0e:2f:9d:
                     d9:1e:07:6e:2c:7c:dc:c2:f8:f9:b6:26:62:8f:36:
                     68:31:eb:91:7d:2e:54:de:f8:59:df:04:20:84:46:
                     0a:ad:cb:1d:53:ff:81:14:f8:d6:66:49:49:92:b2:
                     60:af:2b:7f:4c:dd:80:b7:73:32:96:b7:9e:88:31:
                     cb:c8:ba:54:b0:28:cf:32:02:df:da:84:85:55:40:
                     56:7c:62:ae:d8:13:f3:2b:ae:e1:37:ce:3f:c1:49:
                     a1:09:b0:a3:6e:32:fc:b2:8a:2a:8d:2e:7c:2f:67:
                     d9:b1:89:ff:d2:e5:3f:ff:8e:dd:ad:e9:d0:5d:3e:
                     33:56:0e:73:ec:bf:1f:8c:58:20:77:27:2a:e7:b5:
                     e9:d1:6e:03:76:a0:ab:39:60:6b:20:89:e7:8c:bc:
                     4a:37:da:4d:85:f5:96:5d:b4:20:cb:6d:77:71:73:
                     48:a2:1b:49:35:8f:0c:34:74:2d:a7:4b:69:f6:74:
                     6a:29:88:eb:81:5e:29:10:a7:f4:92:f5:2e:14:dc:
                     c1:74:14:be:73:55:94:e6:b6:ad:62:bf:0a:70:1d:
                     3a:3d:d2:74:57:05:01:01:e5:68:cf:32:53:6a:4e:
                     7f:d0:69:90:8b:ac:cf:21:97:bb:9c:4c:25:85:44:
                     6d:f2:bd:a2:3c:4e:dd:a6:71:cf:1a:88:18:03:95:
                     99:51:07:1f:8d:03:ac:8d:ff:38:ab:00:ab:f8:8c:
                     87:cd:37:83:81:50:32:f9:28:81:69:19:4e:ad:8e:
                     a0:a2:8a:51:8c:d8:ec:0a:0c:d5:c6:08:00:de:16:
                     83:a0:43:6b:09:a0:26:52:4a:be:df:f9:4e:0d:7a:
                     c6:ef:3e:06:f8:86:5c:78:0b:c1:81:8c:64:13:43:
                     89:ff:30:d4:33:10:53:ea:25:91:d6:58:08:21:5c:
                     68:78:d1:fb:3e:4f:e7:62:7b:92:6f:b9:c1:03:1a:
                     77:8f:6f:fe:87:bb:fe:35:14:1b:36:f2:71:b0:50:
                     75:e7:5f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints:
                 CA:FALSE
             X509v3 Key Usage:
                 Digital Signature
             X509v3 Subject Key Identifier:
 6D:96:FB:E7:BE:D0:BD:62:CB:B0:C2:60:7B:6E:DA:93:ED:B6:94:55
             X509v3 Authority Key Identifier:
 keyid:6D:96:FB:E7:BE:D0:BD:62:CB:B0:C2:60:7B:6E:DA:93:ED:B6:94:55

     Signature Algorithm: sha256WithRSAEncryption
          27:c7:e9:40:53:3a:85:4a:ef:ce:95:54:38:a5:34:4b:d3:66:
          cd:2d:d8:c2:4e:8d:dc:99:0d:31:d3:ad:5c:53:31:ea:bc:b2:
          f0:1e:d5:51:7a:19:cc:5a:d5:43:9d:d8:19:3f:94:d5:47:4d:
          76:13:17:62:64:7d:ae:91:ed:b5:9e:e9:0a:84:ce:c2:df:c6:
          1d:da:eb:12:b8:8b:cc:58:ed:67:36:aa:65:0a:e0:db:72:37:
          2b:c7:0e:26:51:02:9d:24:0d:89:93:a1:84:82:b8:88:81:92:
          0f:d5:0e:02:3f:7f:fd:e7:05:b7:23:ce:b6:f5:e6:af:a9:69:
          a9:6b:1c:95:31:c9:44:36:94:bf:e5:04:61:0e:20:8c:85:2e:
          7c:0b:2c:cd:06:3e:39:dd:5c:ca:83:b3:e9:01:b1:a3:37:2d:
          a5:5e:4c:85:46:07:d4:c3:56:73:34:8a:51:1b:59:29:b8:25:
          bf:05:8f:8b:d3:ab:a2:96:1c:4c:27:3a:a1:24:d2:41:44:d9:
          a2:49:61:a6:13:5b:3b:b8:cd:e2:29:0a:54:27:1b:ec:e0:2e:
          0c:ba:f6:ab:d4:af:13:ff:1d:7c:4a:51:92:cf:57:7a:1d:e4:
          7a:51:03:03:08:94:0f:90:0b:fb:ac:ac:ab:85:f0:d0:8b:06:
          06:36:44:15:07:0c:f8:51:e6:30:c8:51:66:56:e8:32:4b:86:
          da:ac:f4:82:d5:71:c1:fd:38:65:26:4e:09:1d:18:9d:07:17:
          16:95:e4:24:e7:8f:e9:1a:bd:25:a9:93:b6:01:4c:5a:97:64:
          7c:c9:63:c2:a2:60:26:32:29:9c:47:1c:8e:29:31:25:92:cd:
          bc:84:e6:dd:27:5e:8f:00:86:51:19:2f:19:7b:96:97:01:a2:
          76:da:f0:67:2f:cd:3b:5d:73:43:28:d5:3b:91:0f:09:31:fa:
          11:a1:76:ec:00:ea:b7:3c:81:3f:30:c3:3b:f4:e2:e3:47:f1:
          5b:fd:30:70:1f:bb:03:53:41:0f:99:1a:e2:c5:b4:49:2e:51:
          e0:c4:39:f5:17:f4:f3:47:91:d4:ce:d1:a3:62:f3:d1:fb:47:
          ad:3e:de:2b:41:c1:d0:38:a2:dd:79:b2:ab:34:4b:2f:1c:7b:
          ef:3e:33:9b:a6:dc:ed:49:46:1e:f7:df:58:b1:80:90:fc:1a:
          50:df:a3:f6:f0:58:f5:61:b2:c9:09:f6:1f:0f:bb:35:1b:79:
          ab:ff:d7:55:3d:14:b5:68:28:4a:86:3b:5c:d3:73:f0:f6:9c:
          23:db:81:45:6f:3f:2f:9d:ce:ad:de:55:67:0e:9d:04:d8:70:
          e5:a0:6b:ec:2b:ca:ee:5d
 SHA1
 Fingerprint=6E:9D:89:0D:CF:0D:5C:A0:D7:C8:F2:8C:82:2E:D2:28:DA:5F:34:90

 $ pkcs15-tool -r 3 | openssl x509 -noout -pubkey
 Using reader with a card: Nitrokey Nitrokey Pro (000039610000000000000000)
 00 00
 - -----BEGIN PUBLIC KEY-----
 MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA8+4jHWnOQ18yStSqOYrv
 MTGHaudFY0KLYfatjGXFIv3fbtzCT25hWtl4WY+MWVxjLy1R34Il7CZ0KvdHnYtF
 7qN5rHwh6GZb37KsjwAIwLR6K6icqjnFgcCCfTVZnaPW4P1ARd1Ove7eOXkL5t1j
 C2unkIvrOeIOqpxC28xbt7T3pD8OL53ZHgduLHzcwvj5tiZijzZoMeuRfS5U3vhZ
 3wQghEYKrcsdU/+BFPjWZklJkrJgryt/TN2At3MylreeiDHLyLpUsCjPMgLf2oSF
 VUBWfGKu2BPzK67hN84/wUmhCbCjbjL8sooqjS58L2fZsYn/0uU//47drenQXT4z
 Vg5z7L8fjFggdycq57Xp0W4DdqCrOWBrIInnjLxKN9pNhfWWXbQgy213cXNIohtJ
 NY8MNHQtp0tp9nRqKYjrgV4pEKf0kvUuFNzBdBS+c1WU5ratYr8KcB06PdJ0VwUB
 AeVozzJTak5/0GmQi6zPIZe7nEwlhURt8r2iPE7dpnHPGogYA5WZUQcfjQOsjf84
 qwCr+IyHzTeDgVAy+SiBaRlOrY6goopRjNjsCgzVxggA3haDoENrCaAmUkq+3/lO
 DXrG7z4G+IZceAvBgYxkE0OJ/zDUMxBT6iWR1lgIIVxoeNH7Pk/nYnuSb7nBAxp3
 j2/+h7v+NRQbNvJxsFB1518CAwEAAQ==
 - -----END PUBLIC KEY-----

 Signed for trac ticket #26536 at Sun May 19 00:51:20 UTC 2019
 -----BEGIN PGP SIGNATURE-----

 iQIzBAEBCgAdFiEEmQpn3DVLpEMbqGYohK8DqE7aGAAFAlzgqLsACgkQhK8DqE7a
 GABnKw//S6vlTMAB9u09HRPx39lFj5y7BOK2J4W32fTRgTQaYLJlZIgkGZPgpodJ
 BXSvYSpS21nTIqGPRjRvp8GWMfn0pWiGmTCbe+OiTt6EOQhv/vrjFs1ZBg5FL53F
 rid69U+2xjrNPGELOmbtYcywDF3sXl/SM1bIuOl9x+BmRNmkbLk11CpFRZ3AbrQn
 CegxPzDOY/FAGAkAyEsRof7xkcBGa630ATwyIWUk9/sLj2RTVa+uEfB+SCXpTB/4
 AidK5kaBP44SD5dNEd9hvc+c5SvHhh+lm5x2sqsrtLmQI8MYAodRwLyRM1bCrd46
 heAPc5v64/GfzsyCj6fSRbjfoyeKfqjuAjVbc9Px7bQ/VtAxZzb06y1LL/mIcLrF
 Tq/oR4qPeSLKNUYD0et/wVUBi012CG86JMg8R0/LHHQ+BgpI+UtxisqUJc4fkJnb
 CJ1Q6aEgKBuA2s+1NG6boiZQEFqbD6FR52fNiXIbPXLSfXsHELQKNU10G7H+LwRl
 q0hD7U7XPjAGq8XKtAdx9eJYG1eLbS1jJnsERxz4A4UWxkDoUaMkdMpXhr+4ITgJ
 4ZFY+rmvk67RA/mMXYvd+Qbt4BdVauZsBBkwx9pGcpDbCMBKSrYW0S5sKGWnh3mV
 LpNe4P9Y993hHgsNjKLJeC7Ep+6m0xeCG/N2OBYBI/rarOguqtc=
 =p5Oz
 -----END PGP SIGNATURE-----
 }}}

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/26536#comment:24>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list