Skip to content

Commit

Permalink
fixup! Firefox preference overrides.
Browse files Browse the repository at this point in the history
MB361: Disable only cyphersuites using SH1 for signing (ECDSA).
  • Loading branch information
hackademix committed Oct 7, 2024
1 parent 0fe417b commit 1a766e2
Showing 1 changed file with 5 additions and 8 deletions.
13 changes: 5 additions & 8 deletions browser/app/profile/001-base-profile.js
Original file line number Diff line number Diff line change
Expand Up @@ -121,16 +121,13 @@ pref("network.http.referer.hideOnionSource", true);
// [4] https://www.ssllabs.com/ssl-pulse/
pref("security.ssl.require_safe_negotiation", true);

// Bug 40183: Disable TLS ciphersuites using SHA-1
// https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40183
// mullvad-browser#361: Disable TLS cyphersuites using SHA1 for signing (ECDSA)
// see https://bugzilla.mozilla.org/show_bug.cgi?id=1600437
pref("security.ssl3.ecdhe_ecdsa_aes_256_sha", false);
pref("security.ssl3.ecdhe_ecdsa_aes_128_sha", false);
// lock those disabled by https://bugzilla.mozilla.org/show_bug.cgi?id=1036765
pref("security.ssl3.dhe_rsa_aes_128_sha", false, locked);
pref("security.ssl3.dhe_rsa_aes_256_sha", false, locked);
pref("security.ssl3.ecdhe_ecdsa_aes_256_sha", false, locked);
pref("security.ssl3.ecdhe_ecdsa_aes_128_sha", false, locked);
pref("security.ssl3.ecdhe_rsa_aes_128_sha", false, locked);
pref("security.ssl3.ecdhe_rsa_aes_256_sha", false, locked);
pref("security.ssl3.rsa_aes_128_sha", false, locked);
pref("security.ssl3.rsa_aes_256_sha", false, locked);

// Wrapping a static pref to lock it and prevent changing.
// See tor-browser#40565.
Expand Down

0 comments on commit 1a766e2

Please sign in to comment.