Since last year, the situation has changed:
welcome to uhura (and they are listed in the official mcc McCoy )
uhura -k signature.key yourextension.xpi http:
An additional advantage is that you can create, create backups, move your own cryptographic keys without having to bind to the mozilla database. The only drawback is: Perl (how hard it is to fix missing dependencies, with or without CPAN)
As a side note, I almost started writing my own python-based script, but couldn't find signatures with RDF support; or, in fact, even the XML signatures of libs are shit for python (but hey, XML-DSig is inherently evil , isn't it). Why did Mozilla choose RDF for the extension manifest?
Stefano
source share