5 ms·
Does anyone know how to disable TLS 1.0 in Firefox 26.0 (on Linux)? I found this article: http://www.spotht.com/2010/06/how-to-enabledisable-ssl-30-and-tls-10
by fexl 13y ago
Does anyone know how to disable TLS 1.0 in Firefox 26.0 (on Linux)? I found this article:
http://www.spotht.com/2010/06/how-to-enabledisable-ssl-30-and-tls-10.html http://www.spotht.com/2010/06/how-to-enabledisable-ssl-30-an...
However, the Options in my browser do not include a tab called "Encryption", as the article discusses.
- ecaron 13y agoYou want to use about:config. More details on it are at https://support.mozilla.org/en-US/questions/967266 https://support.mozilla.org/en-US/questions/967266
- Spittie 13y agoI think you should look at security.tls.version.min (in about:config): http://kb.mozillazine.org/Security.tls.version.* http://kb.mozillazine.org/Security.tls.version.*
- hundchenkatze 13y agochange security.tls.version.min to 2 in about:config 0 = SSLv3 1 = TLSv1.0 2 = TLSv1.1 3 = TLSv1.2 For reference: http://kb.mozillazine.org/Security.tls.version.* http://kb.mozillazine.org/Security.tls.version.*
- logn 13y agoAnd change security.tls.version.max to 3 (to enable TLS 1.2). Also about:config will let you disable security.ssl3.rsa_fips_des_ede3_sha Making those changes gives me "Probably Okay" rating on howsmyssl.com
- agwa 13y agoQuite a few servers (for example, any server using the version of OpenSSL in Debian Squeeze) do not support anything newer than TLS 1.0, so you'll get quite a bit of breakage if you disable it. TLS 1.0 in Firefox 26.0 should be secure; it implements 1/n-1 record splitting, so it's safe against BEAST even though this website reports otherwise.
- gcb0 13y agoHear this. This site is mostly FUD. http://security.stackexchange.com/questions/32817/why-dont-major-browsers-currently-support-tls-above-version-1-0 http://security.stackexchange.com/questions/32817/why-dont-m...
- agwa 13y agoThe site is mostly OK. It just needs to properly test for the BEAST vulnerability (ideally it would check for a 1 byte record, but a whitelist of user agents known to implement 1/n-1 record splitting would suffice in the interim), instead of assuming anyone with TLSv1.0 is vulnerable. And it should rate TLSv1.0 (with record splitting) as "Improvable" rather than "Bad". But yes, being faced with a huge "Your SSL client is Bad" banner when visiting from up-to-date Firefox is FUD.