1.1.2.1 (L1) Ensure 'NTLM' is set to 'Disabled'

Information

This policy setting controls the use of NT Lan Manager (NTLM) v1 protocol. This protocol is used for authentication to resources.

The recommended state for this setting is: Disabled

NTLM v1 contains cryptographic weaknesses that can be easily exploited to obtain user credentials.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Authentication\NTLM

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|16.5

Plugin: Windows

Control ID: 771c96e45f0ba79b64f37d5fe054d87f346597c0d9cf520596c238806bd358fc