Fix sec pref locations and enable HPKP checking by default.

Some prefs were incorrectly in all.js (ocsp and hpkp)
This commit is contained in:
wolfbeast 2018-05-29 17:27:27 +02:00 committed by Roy Tam
commit fdf7ba29b4
2 changed files with 11 additions and 10 deletions

View file

@ -2158,19 +2158,9 @@ pref("security.block_script_with_wrong_mime", true);
// Block images of wrong MIME for XCTO: nosniff.
pref("security.xcto_nosniff_block_images", false);
// OCSP must-staple
pref("security.ssl.enable_ocsp_must_staple", true);
// Insecure Form Field Warning
pref("security.insecure_field_warning.contextual.enabled", false);
// Disable pinning checks by default.
pref("security.cert_pinning.enforcement_level", 0);
// Do not process hpkp headers rooted by not built in roots by default.
// This is to prevent accidental pinning from MITM devices and is used
// for tests.
pref("security.cert_pinning.process_headers_from_non_builtin_roots", false);
// If set to true, allow view-source URIs to be opened from URIs that share
// their protocol with the inner URI of the view-source URI
pref("security.view-source.reachable-from-inner-protocol", false);

View file

@ -111,6 +111,17 @@ pref("security.ssl.errorReporting.enabled", true);
pref("security.ssl.errorReporting.url", "https://incoming.telemetry.mozilla.org/submit/sslreports/");
pref("security.ssl.errorReporting.automatic", false);
// OCSP must-staple
pref("security.ssl.enable_ocsp_must_staple", true);
// HPKP settings
// Enable pinning checks by default.
pref("security.cert_pinning.enforcement_level", 2);
// Do not process hpkp headers rooted by not built in roots by default.
// This is to prevent accidental pinning from MITM devices and is used
// for tests.
pref("security.cert_pinning.process_headers_from_non_builtin_roots", false);
// Impose a maximum age on HPKP headers, to avoid sites getting permanently
// blacking themselves out by setting a bad pin. (60 days by default)
// https://tools.ietf.org/html/rfc7469#section-4.1