Issue #1831 - Add an option to enable TLS 1.3 "compatibility" mode.

Critical note: this potentially reduces the strength of TLS 1.3 and
should only be enabled if absolutely necessary to access a site.
A browser restart is required for the pref change to take effect as it
is set on NSS initialization.

Resolves #1831
This commit is contained in:
Moonchild 2021-10-11 22:16:04 +00:00 committed by roytam1
commit ca93d4b42d
2 changed files with 12 additions and 0 deletions

View file

@ -112,6 +112,12 @@ pref("security.webauth.u2f_enable_usbtoken", false);
// OCSP must-staple
pref("security.ssl.enable_ocsp_must_staple", true);
// Enable TLS 1.3 compatmode version for bad middleware boxes?
// This is a holdover from the later draft specs and SHOULD NOT be enabled by
// default. ONLY use this when you explicitly need it. You have been warned!
// Restart required.
pref("security.ssl.enable_tls13_compat_mode", false);
// If a request is mixed-content, send an HSTS priming request to attempt to
// see if it is available over HTTPS.
pref("security.mixed_content.send_hsts_priming", true);