4.4 Set Security TLS Version Maximum

Information

This setting sets the maximum required protocol version for the Transport Layer Security (TLS).

Rationale:

Setting TLS 1.2 as the maximum authorized protocol version mitigates the risk of using an insecure connection.

Solution

To establish the recommended configuration, set security.tls.version.max to 3:

Type about:config in the address bar

Type security.tls.version.max in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('security.tls.version.max', 3);

Default Value:

4

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: e95b95561ffde130dcc055e88ab20b773a4cffb11ea84098bc5bc5f4c3830de2