Skip to main content
CUI

Vulnerability V-251560

Back

V-251560

CAT II

Firefox must have the DOD root certificates installed.

Ships Affected
1
Total Findings
4
Open
0
Closed
4

Check Text

Type "about:preferences#privacy" in the browser window. Scroll down to the bottom and select "View Certificates...". In the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5. If there are entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5, select them individually. Click "View". Verify the issuer name is "US Government". If there are no entries for the appropriate DOD root certificates, this is a finding. If other AO-approved certificates are used, this is not a finding. If SIPRNet-specific certificates are used, this is not a finding. Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store. This is not a finding. It can also be set via the policy Certificates >> ImportEnterpriseRoots, which can be verified via "about:policies".

Fix Text

Install the DOD root certificates. Other AO-approved certificates may also be used. Certificates designed for SIPRNet may be used as appropriate. On Windows, import certificates from the operating system by using Certificates >> Import Enterprise Roots (Certificates) via policy or Group Policy Object (GPO).

STIG Reference

STIG
Mozilla Firefox Security Technical Implementation Guide
Version
6
Release
7
Rule ID
SV-251560r1067559_rule

All Occurrences

This vulnerability appears on 1 ship(s)

Ship Hull # Source File Status Assigned To Scan Date Actions
USNS MONTFORD POINT T-ESD-1 MONT-SW-89134_Firefox_V6R6_20251217-201244.ckl
Unassigned 2026-03-04T15:25:41.899130 View in Context
USNS MONTFORD POINT T-ESD-1 MONT-SW-89108_Firefox_V6R6_20251217-203042.ckl
Unassigned 2026-03-04T15:25:15.868210 View in Context
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-WS-92010/Checklist/MONT-WS-92010_Firefox_V6R6_20251023-141154.ckl
Unassigned 2026-01-14T12:57:27.870047 View in Context
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-WS-92040/Checklist/MONT-WS-92040_Firefox_V6R6_20251023-142444.ckl
Unassigned 2026-01-14T12:57:25.596878 View in Context
CUI