Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-223177 | DTBF235 | SV-223177r612236_rule | Medium |
Description |
---|
A weak cipher is defined as an encryption/decryption algorithm that uses a key of insufficient length. Using an insufficient length for a key in an encryption/decryption algorithm opens up the possibility (or probability) that the encryption scheme could be broken. |
STIG | Date |
---|---|
Mozilla Firefox Security Technical Implementation Guide | 2021-06-09 |
Check Text ( C-24850r531348_chk ) |
---|
Type "about:config" in the address bar, verify that the preference name “security.ssl3.rsa_des_ede3_sha" is set to “false” and locked. Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding. |
Fix Text (F-24838r531349_fix) |
---|
Ensure the preference “security.ssl3.rsa_des_ede3_sha" is set and locked to the value of “false”. |