DTBF030 - Firefox must be configured to allow only TLS - security.tls.version.max

Information

Use of versions prior to TLS 1.1 are not permitted. SSL 2.0 and SSL 3.0 contain a number of security flaws. These versions must be disabled in compliance with the Network Infrastructure and Secure Remote Computing STIGs.

Solution

Configure the following parameters using the Mozilla.cfg file:

LockPref 'security.tls.version.min' is set to '2'.
LockPref 'security.tls.version.max' is set to '4'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V5R2_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-001453, Rule-ID|SV-223152r612236_rule, STIG-ID|DTBF030, STIG-Legacy|SV-16925, STIG-Legacy|V-15983, Vuln-ID|V-223152

Plugin: Unix

Control ID: 8ec114764e3de54b080faa8a689b3d0b506f4b8c9987d9a2d7b90a76b7cdca3d