Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15982 | DTBF010 | SV-16924r1_rule | ECSC-1 | Medium |
Description |
---|
Use of versions prior to TLS 1.0 are not permitted because these versions are non-standard. SSL 2.0 and SSL 3.0 contain a number of security flaws. These versions must be disabled in compliance with the Network Infrastructure and Secure Remote Computing STIGs. SSL 2.0 setting does not appear in the Options dialog and must be disabled using About:Config. |
STIG | Date |
---|---|
Mozilla FireFox | 2013-04-08 |
Check Text ( C-16609r1_chk ) |
---|
Open a browser window, type "about:config" in the address bar, then navigate to the setting for Preference Name "security.enable_ssl2" and verify the value is set to "false". Criteria: If the parameter is set incorrectly, then this is a finding. If the value is not locked this is a finding. |
Fix Text (F-15983r1_fix) |
---|
Ensure the preference "security.enable_ssl2" is set to "false". |