Skip to content

Guide to the Secure Configuration of Firefox

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Disable Firefox deprecated ciphers

    Pocket may be disabled by setting <code>TLS_RSA_WITH_3DES_EDE_CBC_SHA</code> to <code>true</code> under <code>DisabledCiphers</code> in the policie...
    Rule Medium Severity
  • Firefox must be configured to disable form fill assistance.

    The update check may be disabled in an administrative policy by setting the <code>DisableFormHistory</code> key under <code>policies</code> to <cod...
    Rule Medium Severity
  • Disable Firefox Pocket

    Pocket may be disabled by setting DisablePocket to true in the policies file.
    Rule Medium Severity
  • Disable Firefox Studies

    Pocket may be disabled by setting DisableFirefoxStudies to true in the policies file.
    Rule Medium Severity
  • Firefox must be configured to not delete data upon shutdown.

    The default certificate to present may be configured by setting multiple options under <code>SanitizeOnShutdown</code> key. <ul><li> <code>Cache</c...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules