Thank you Nelson for your response and help. > You're not running signtool while FireFox is running, right?
Not any more. I have learned my lesson. In the beginning I did that and my key3.db became corrupted. Btw, it would be really nice if multiple apps could access key3.db and cert8.db at the same time. :) > "security authorization" means "getting your password". > That's what this error code was originally about. I don't have password on my key3.db and I don't specify it while signing my .xpi file. Is that OK? Should I specify blank ("") password? > reimported from a pkcs12 file? (or pfx file) ? > or from some other kind of file? > Only a PKCS12 file (.p12 or .pfx) can restore your private key. Yes, I imported my code signing cert from .pfx file. > Does your key3.db file now contain the private key for your cert? Sure. > Is your cert an object signing cert? Or merely code signing? I am very surprised that there are "object" and "code" signing. I thought only "code signing" existed. I have never heard for "object signing" before. What is it? Mine cert is marked as "code signing". This is my command line signtool.exe -d "C:\Docum...8mp7m.default" -k "CodeSign" -Z "My.xpi" ff _______________________________________________ dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto