UCF STIG Viewer Logo

Deprecated ciphers must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223177 DTBF235 SV-223177r612236_rule Medium
Description
A weak cipher is defined as an encryption/decryption algorithm that uses a key of insufficient length. Using an insufficient length for a key in an encryption/decryption algorithm opens up the possibility (or probability) that the encryption scheme could be broken.
STIG Date
Mozilla Firefox Security Technical Implementation Guide 2020-12-10

Details

Check Text ( C-24850r531348_chk )
Type "about:config" in the address bar, verify that the preference name “security.ssl3.rsa_des_ede3_sha" is set to “false” and locked.

Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding.
Fix Text (F-24838r531349_fix)
Ensure the preference “security.ssl3.rsa_des_ede3_sha" is set and locked to the value of “false”.