Skip to content

Firefox must be configured to not delete data upon shutdown.

An XCCDF Rule

Description

The default certificate to present may be configured by setting multiple options under SanitizeOnShutdown key.

  • Cache = false

Rationale

For diagnostic purposes, data must remain behind when the browser is closed. This is required to meet non-repudiation controls.

ID
xccdf_org.ssgproject.content_rule_firefox_policy-no_sanitize_on_shutdown
Severity
Medium
References
Updated



Remediation - Shell Script


firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644