Guide to the Secure Configuration of Firefox
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Disable JavaScript's Moving Or Resizing Windows Capability
JavaScript can configure and make changes to the web browser's appearance by specifically moving and resizing browser windows. This can be disabled by setting <code>dom.disable_window_move_resize</...Rule Medium Severity -
Disable Firefox network prediction
Firefox has a feature where it predicts and caches DNS requests. This can be disabled by settingNetworkPrediction
totrue
in the policy file.Rule Medium Severity -
The Default Firefox Home Page
The default home page for Firefox users.Value -
Firefox must be configured to disable the installation of extensions.
Addon installation may be disabled in an administrative policy by setting theInstallAddonsPermission
key underpolicies
tofalse
.Rule Medium Severity -
Firefox autoplay must be disabled.
Audio/Video autoplay may be disabled in an administrative policy by setting theDefault
key underPermissions
,Autoplay
to"block-audio-video"
.Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules