STIGQter STIGQter: STIG Summary: Mozilla Firefox Security Technical Implementation Guide Version: 6 Release: 8 Benchmark Date: 01 Jul 2026:

Firefox must have the DOD root certificates installed.

DISA Rule

SV-251560r1067559_rule

Vulnerability Number

V-251560

Group Title

SRG-APP-000175

Rule Version

FFOX-00-000016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install the DOD root certificates. Other AO-approved certificates may also be used. Certificates designed for SIPRNet may be used as appropriate.

On Windows, import certificates from the operating system by using Certificates >> Import Enterprise Roots (Certificates) via policy or Group Policy Object (GPO).

Check Contents

Type "about:preferences#privacy" in the browser window.

Scroll down to the bottom and select "View Certificates...".

In the Certificate Manager window, select the "Authorities" tab.

Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5.

If there are entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5, select them individually.

Click "View".

Verify the issuer name is "US Government".

If there are no entries for the appropriate DOD root certificates, this is a finding. If other AO-approved certificates are used, this is not a finding. If SIPRNet-specific certificates are used, this is not a finding.

Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store. This is not a finding. It can also be set via the policy Certificates >> ImportEnterpriseRoots, which can be verified via "about:policies".

Vulnerability Number

V-251560

Documentable

False

Rule Version

FFOX-00-000016

Severity Override Guidance

Type "about:preferences#privacy" in the browser window.

Scroll down to the bottom and select "View Certificates...".

In the Certificate Manager window, select the "Authorities" tab.

Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5.

If there are entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5, select them individually.

Click "View".

Verify the issuer name is "US Government".

If there are no entries for the appropriate DOD root certificates, this is a finding. If other AO-approved certificates are used, this is not a finding. If SIPRNet-specific certificates are used, this is not a finding.

Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store. This is not a finding. It can also be set via the policy Certificates >> ImportEnterpriseRoots, which can be verified via "about:policies".

Check Content Reference

M

Target Key

5446