Technical Details on the Recent Firefox Add-On Outage
The result is that the add-on is independently verifiable as long as you know the root certificate, which is configured into Firefox at build time. Important for this case, they can add new certificates to the certificate database that Firefox uses to verify add-ons. OK, so now we’ve got a plan: issue a new certificate to replace the old one, build a system add-on to install it on Firefox, and deploy it via Normandy.
Source: hacks.mozilla.org