Select any old version/release of this SCAP to view the previous requirements
Set the value of "security.default_personal_cert" to "Ask Every Time". Use the Mozilla.cfg file to lock the preference so users cannot change it.
Procedure: Set the value of "network.protocol-handler.external.shell" to "false" and lock using the Mozilla.cfg file.
Ensure the following extensions are not automatically opened by Firefox without user confirmation. Do not use plugins and add-ons to open these files. Use the "plugin.disable_full_page_plugin_for_types" preference to set and lock the following extensions so that an external application, rather than an add-on or plugin, will not be used: PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT, PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP.
Ensure the preference “browser.formfill.enable" is set and locked to the value of “false”.
Ensure the preference "signon.autofillForms" is set and locked to the value of “false”.
Ensure the preference “signon.rememberSignons“ is set and locked to the value of “false”.
Ensure the preference "dom.disable_window_open_feature.status " is set and locked to the value of “true”.
Ensure the preference "dom.disable_window_move_resize" is set and locked to the value of “true”.
Configure the following parameters using the Mozilla.cfg file: LockPref "security.tls.version.min" is set to "2". LockPref "security.tls.version.max" is set to "4".
Ensure the preference "dom.disable_window_flip" is set and locked to the value of “true”.
Ensure the preferences "dom.event.contextmenu.enabled" is set and locked to "false".
Set the preference “extensions.update.enabled” value to "false" and lock using the Mozilla.cfg file.
Ensure the required settings in "about:config" are locked using the "mozilla.cfg" file.
Ensure the preference "browser.search.update" is set and locked to the value of “False”.
Set the preference “xpinstall.enabled” to “false” and lock using the “mozilla.cfg” file. The “mozilla.cfg” file may need to be created if it does not already exist.
Ensure the preferences "datareporting.policy.dataSubmissionEnabled" is set and locked to "false".