Mozilla has revoked a cryptographic signing key used to verify Firefox and Thunderbird downloads for Linux. Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Private Repository LeakThe revocation means that software signed with the old key will no longer pass verification after users import the revocation information. On some systems, however, the update may fail and require the signing key to be replaced manually. Mozilla’s instructions include removing the existing key, importing the new signing key, and clearing the package manager’s cache before trying the update again. However, anyone who manually verifies Firefox or Thunderbird downloads or uses Mozilla’s RPM packages should check the signing key and update it if required.