UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Deprecated ciphers must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223177 DTBF235 SV-223177r612236_rule Medium
Description
A weak cipher is defined as an encryption/decryption algorithm that uses a key of insufficient length. Using an insufficient length for a key in an encryption/decryption algorithm opens up the possibility (or probability) that the encryption scheme could be broken.
STIG Date
Mozilla Firefox Security Technical Implementation Guide 2020-12-10

Details

Check Text ( C-24850r531348_chk )
Type "about:config" in the address bar, verify that the preference name “security.ssl3.rsa_des_ede3_sha" is set to “false” and locked.

Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding.
Fix Text (F-24838r531349_fix)
Ensure the preference “security.ssl3.rsa_des_ede3_sha" is set and locked to the value of “false”.