1.1.38 (L1) Ensure 'Minimum SSL version enabled' is set to 'Enabled: TLS 1.2'

Information

This setting sets the minimum protocol version that may be used when negotiating TLS/SSL sessions.

The recommended state for this setting is: Enabled:TLS 1.2

Setting TLS 1.2 as the minimum protocol version mitigates the risk of negotiating an insecure protocol, such as TSL 1.0 or SSL 2.0.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:TLS 1.2 :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Minimum SSL version enabled

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Communications that require an older version of TLS/SSL will be blocked.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: ea11acb4e01439716f2a01fc7c15996e298308aecad4e699d3e150a81e5b5cec