From 9a899fbc65e3cbd7a6382493b98076ee5f58c159 Mon Sep 17 00:00:00 2001 From: "kaie%kuix.de" Date: Wed, 22 Feb 2006 12:40:17 +0000 Subject: [PATCH] bug 236933, Disable SSL2 and other weak ciphers by default This checkin changes the default prefs only r=darin --- netwerk/base/public/security-prefs.js | 30 +++++++++++++-------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/netwerk/base/public/security-prefs.js b/netwerk/base/public/security-prefs.js index 7538785fbaf..1ee0e04868f 100644 --- a/netwerk/base/public/security-prefs.js +++ b/netwerk/base/public/security-prefs.js @@ -1,25 +1,25 @@ pref("general.useragent.security", "U"); -pref("security.enable_ssl2", true); +pref("security.enable_ssl2", false); pref("security.enable_ssl3", true); pref("security.enable_tls", true); -pref("security.ssl2.rc4_128", true); -pref("security.ssl2.rc2_128", true); -pref("security.ssl2.des_ede3_192", true); -pref("security.ssl2.des_64", true); -pref("security.ssl2.rc4_40", true); -pref("security.ssl2.rc2_40", true); +pref("security.ssl2.rc4_128", false); +pref("security.ssl2.rc2_128", false); +pref("security.ssl2.des_ede3_192", false); +pref("security.ssl2.des_64", false); +pref("security.ssl2.rc4_40", false); +pref("security.ssl2.rc2_40", false); pref("security.ssl3.rsa_rc4_128_md5", true); pref("security.ssl3.rsa_rc4_128_sha", true); pref("security.ssl3.rsa_fips_des_ede3_sha", true); pref("security.ssl3.rsa_des_ede3_sha", true); -pref("security.ssl3.rsa_fips_des_sha", true); -pref("security.ssl3.rsa_des_sha", true); -pref("security.ssl3.rsa_1024_rc4_56_sha", true); -pref("security.ssl3.rsa_1024_des_cbc_sha", true); -pref("security.ssl3.rsa_rc4_40_md5", true); -pref("security.ssl3.rsa_rc2_40_md5", true); +pref("security.ssl3.rsa_fips_des_sha", false); +pref("security.ssl3.rsa_des_sha", false); +pref("security.ssl3.rsa_1024_rc4_56_sha", false); +pref("security.ssl3.rsa_1024_des_cbc_sha", false); +pref("security.ssl3.rsa_rc4_40_md5", false); +pref("security.ssl3.rsa_rc2_40_md5", false); pref("security.ssl3.dhe_rsa_aes_256_sha", true); pref("security.ssl3.dhe_dss_aes_256_sha", true); pref("security.ssl3.rsa_aes_256_sha", true); @@ -28,8 +28,8 @@ pref("security.ssl3.dhe_dss_aes_128_sha", true); pref("security.ssl3.rsa_aes_128_sha", true); pref("security.ssl3.dhe_rsa_des_ede3_sha", true); pref("security.ssl3.dhe_dss_des_ede3_sha", true); -pref("security.ssl3.dhe_rsa_des_sha", true); -pref("security.ssl3.dhe_dss_des_sha", true); +pref("security.ssl3.dhe_rsa_des_sha", false); +pref("security.ssl3.dhe_dss_des_sha", false); pref("security.ssl3.rsa_null_sha", false); pref("security.ssl3.rsa_null_md5", false);