1.1.7.1 (L1) Ensure 'TLS_RSA_WITH_3DES_EDE_CBC_SHA ' is set to 'Enabled'

Information

This policy settings controls the use of the TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher suite. Cipher suites are a group of algorithms that help secure network connections.

The recommended state for this setting is: Enabled

The Triple Data Encryption Algorithm (TDEA) also known as Triple DES (3DES) was deprecated in 2019 by NIST. 3DES is now considered an insecure cipher suite and should not be used.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Disabled Ciphers\TLS_RSA_WITH_3DES_EDE_CBC_SHA

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Some legacy software and hardware might be affected by disabling this cipher suite.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 2a7d34c4d5a9523d2727e60636701340d99b3019528e51ceaa2aed435a9703eb