����JFIFXX�����    $.' ",#(7),01444'9=82<.342  2!!22222222222222222222222222222222222222222222222222����"��4�� ���,�PG"Z_�4�˷����kjز�Z�,F+��_z�,�© �����zh6�٨�ic�fu���#ډb���_�N�?��wQ���5-�~�I���8����TK<5o�Iv-�����k�_U_�����~b�M��d����Ӝ�U�Hh��?]��E�w��Q���k�{��_}qFW7HTՑ��Y��F�?_�'ϔ��_�Ջt��=||I ��6�έ"�����D���/[�k�9���Y�8ds|\���Ҿp6�Ҵ���]��.����6�z<�v��@]�i%��$j��~�g��J>��no����pM[me�i$[����s�o�ᘨ�˸ nɜG-�ĨU�ycP�3.DB�li�;��hj���x7Z^�N�h������N3u{�:j�x�힞��#M&��jL P@_���� P��&��o8������9�����@Sz6�t7#O�ߋ �s}Yf�T���lmr����Z)'N��k�۞p����w\�Tȯ?�8`�O��i{wﭹW�[�r�� ��Q4F�׊���3m&L�=��h3����z~��#�\�l :�F,j@�� ʱ�wQT����8�"kJO���6�֚l����}���R�>ډK���]��y����&����p�}b��;N�1�m�r$�|��7�>e�@B�TM*-iH��g�D�)� E�m�|�ؘbҗ�a��Ҿ����t4���o���G��*oCN�rP���Q��@z,|?W[0�����:�n,jWiE��W��$~/�hp\��?��{(�0���+�Y8rΟ�+����>S-S����VN;�}�s?.����� w�9��˟<���Mq4�Wv'��{)0�1mB��V����W[�����8�/<� �%���wT^�5���b��)iM� pg�N�&ݝ��VO~�q���u���9� ����!��J27����$O-���! �:�%H��� ـ����y�ΠM=t{!S�� oK8������t<����è:a������[�����ա�H���~��w��Qz`�po�^ ����Q��n� �,uu�C�$ ^���,������8�#��:�6��e�|~���!�3�3.�\0��q��o�4`.|� ����y�Q�`~;�d�ׯ,��O�Zw�������`73�v�܋�<���Ȏ�� ـ4k��5�K�a�u�=9Yd��$>x�A�&�� j0� ���vF��� Y�|�y��� ~�6�@c��1vOp�Ig����4��l�OD���L����� R���c���j�_�uX6��3?nk��Wy�f;^*B� ��@�~a�`��Eu������+���6�L��.ü>��}y���}_�O�6�͐�:�YrG�X��kG�����l^w���~㒶sy��Iu�!� W ��X��N�7BV��O��!X�2����wvG�R�f�T#�����t�/?���%8�^�W�aT��G�cL�M���I��(J����1~�8�?aT ���]����AS�E��(��*E}� 2��#I/�׍qz��^t�̔���b�Yz4x���t�){ OH��+(E��A&�N�������XT��o��"�XC��'���)}�J�z�p� ��~5�}�^����+�6����w��c��Q�|Lp�d�H��}�(�.|����k��c4^�"�����Z?ȕ ��a<�L�!039C� �Eu�C�F�Ew�ç ;�n?�*o���B�8�bʝ���'#Rqf���M}7����]����s2tcS{�\icTx;�\��7K���P���ʇ Z O-��~��c>"��?�������P��E��O�8��@�8��G��Q�g�a�Վ���󁶠�䧘��_%#r�>�1�z�a��eb��qcPѵ��n���#L��� =��׀t� L�7�`��V���A{�C:�g���e@�w1 Xp3�c3�ġ����p��M"'-�@n4���fG��B3�DJ�8[Jo�ߐ���gK)ƛ��$���� ���8�3�����+���� �����6�ʻ���� ���S�kI�*KZlT _`���?��K����QK�d����B`�s}�>���`��*�>��,*@J�d�oF*����弝��O}�k��s��]��y�ߘ��c1G�V���<=�7��7����6�q�PT��tXԀ�!9*4�4Tހ3XΛex�46���Y��D ����� �BdemDa����\�_l,��G�/���֌7���Y�](�xTt^%�GE�����4�}bT���ڹ�����;Y)���B�Q��u��>J/J �⮶.�XԄ��j�ݳ�+E��d ��r�5�_D�1 ��o�� �B�x�΢�#���<��W�����8���R6�@g�M�.��� dr�D��>(otU��@x=��~v���2� ӣ�d�oBd��3�eO�6�㣷�����ݜ6��6Y��Qz`��S��{���\P�~z m5{J/L��1������<�e�ͅPu�b�]�ϔ���'������f�b� Zpw��c`"��i���BD@:)ִ�:�]��hv�E�w���T�l��P���"Ju�}��وV J��G6��. J/�Qgl߭�e�����@�z�Zev2u�)]կ�����7x���s�M�-<ɯ�c��r�v�����@��$�ޮ}lk���a���'����>x��O\�ZFu>�����ck#��&:��`�$�ai�>2Δ����l���oF[h��lE�ܺ�Πk:)���`�� $[6�����9�����kOw�\|���8}������ބ:��񶐕��I�A1/�=�2[�,�!��.}gN#�u����b��� ~��݊��}34q����d�E��Lc��$��"�[q�U�硬g^��%B �z���r�pJ�ru%v\h1Y�ne`ǥ:g���pQM~�^�Xi� ��`S�:V29.�P���V�?B�k�� AEvw%�_�9C�Q����wKekPؠ�\�;Io d�{ ߞo�c1eP����\� `����E=���@K<�Y���eڼ�J���w����{av�F�'�M�@/J��+9p���|]�����Iw &`��8���&M�hg��[�{��Xj��%��Ӓ�$��(����ʹN���<>�I���RY���K2�NPlL�ɀ)��&e����B+ь����( � �JTx���_?EZ� }@ 6�U���뙢ط�z��dWI�n` D����噥�[��uV��"�G&Ú����2g�}&m��?ċ�"����Om#��������� ��{�ON��"S�X��Ne��ysQ���@Fn��Vg���dX�~nj�]J�<�K]:��FW��b�������62�=��5f����JKw��bf�X�55��~J �%^����:�-�QIE��P��v�nZum� z � ~ə ���� ���ة����;�f��\v���g�8�1��f24;�V���ǔ�)����9���1\��c��v�/'Ƞ�w�������$�4�R-��t���� e�6�/�ġ �̕Ecy�J���u�B���<�W�ַ~�w[B1L۲�-JS΂�{���΃������A��20�c#��@ 0!1@AP"#2Q`$3V�%45a6�FRUq��� ����^7ׅ,$n�������+��F�`��2X'��0vM��p�L=������5��8������u�p~���.�`r�����\���O��,ư�0oS ��_�M�����l���4�kv\JSd���x���SW�<��Ae�IX����������$I���w�:S���y���›R��9�Q[���,�5�;�@]�%���u�@ *ro�lbI �� ��+���%m:�͇ZV�����u�̉����θau<�fc�.����{�4Ա� �Q����*�Sm��8\ujqs]{kN���)qO�y�_*dJ�b�7���yQqI&9�ԌK!�M}�R�;������S�T���1���i[U�ɵz�]��U)V�S6���3$K{�ߊ<�(� E]Զ[ǼENg�����'�\?#)Dkf��J���o��v���'�%ƞ�&K�u�!��b�35LX�Ϸ��63$K�a�;�9>,R��W��3�3� d�JeTYE.Mϧ��-�o�j3+y��y^�c�������VO�9NV\nd�1 ��!͕_)a�v;����թ�M�lWR1��)El��P;��yوÏ�u 3�k�5Pr6<�⒲l�!˞*��u־�n�!�l:����UNW ��%��Chx8vL'��X�@��*��)���̮��ˍ��� ���D-M�+J�U�kvK����+�x8��cY������?�Ԡ��~3mo��|�u@[XeY�C�\Kp�x8�oC�C�&����N�~3-H���� ��MX�s�u<`���~"WL��$8ξ��3���a�)|:@�m�\���^�`�@ҷ)�5p+��6���p�%i)P M���ngc�����#0Aruz���RL+xSS?���ʮ}()#�t��mˇ!��0}}y����<�e� �-ή�Ԩ��X������ MF���ԙ~l L.3���}�V뽺�v�����멬��Nl�)�2����^�Iq��a��M��qG��T�����c3#������3U�Ǎ���}��לS�|qa��ڃ�+���-��2�f����/��bz��ڐ�� �ݼ[2�ç����k�X�2�* �Z�d���J�G����M*9W���s{��w���T��x��y,�in�O�v��]���n����P�$�JB@=4�OTI�n��e�22a\����q�d���%�$��(���:���: /*�K[PR�fr\nڙdN���F�n�$�4�[�� U�zƶ����� �mʋ���,�ao�u 3�z� �x��Kn����\[��VFmbE;�_U��&V�Gg�]L�۪&#n%�$ɯ�dG���D�TI=�%+AB�Ru#��b4�1�»x�cs�YzڙJG��f��Il��d�eF'T� iA��T���uC�$����Y��H?����[!G`}���ͪ� �纤Hv\������j�Ex�K���!���OiƸ�Yj�+u-<���'q����uN�*�r\��+�]���<�wOZ.fp�ێ��,-*)V?j-kÊ#�`�r��dV����(�ݽBk�����G�ƛk�QmUڗe��Z���f}|����8�8��a���i��3'J�����~G_�^���d�8w������ R�`(�~�.��u���l�s+g�bv���W���lGc}��u���afE~1�Ue������Z�0�8�=e�� f@/�jqEKQQ�J��oN��J���W5~M>$6�Lt�;$ʳ{���^��6�{����v6���ķܰg�V�cnn �~z�x�«�,2�u�?cE+Ș�H؎�%�Za�)���X>uW�Tz�Nyo����s���FQƤ��$��*�&�LLXL)�1�" L��eO��ɟ�9=���:t��Z���c��Ž���Y?�ӭV�wv�~,Y��r�ۗ�|�y��GaF�����C�����.�+� ���v1���fήJ�����]�S��T��B��n5sW}y�$��~z�'�c ��8 ��� ,! �p��VN�S��N�N�q��y8z˱�A��4��*��'������2n<�s���^ǧ˭P�Jޮɏ�U�G�L�J�*#��<�V��t7�8����TĜ>��i}K%,���)[��z�21z ?�N�i�n1?T�I�R#��m-�����������������1����lA�`��fT5+��ܐ�c�q՝��ʐ��,���3�f2U�եmab��#ŠdQ�y>\��)�SLY����w#��.���ʑ�f��� ,"+�w�~�N�'�c�O�3F�������N<���)j��&��,-� �љ���֊�_�zS���TǦ����w�>��?�������n��U仆�V���e�����0���$�C�d���rP �m�׈e�Xm�Vu� �L��.�bֹ��� �[Դaզ���*��\y�8�Է:�Ez\�0�Kq�C b��̘��cө���Q��=0Y��s�N��S.���3.���O�o:���#���v7�[#߫ ��5�܎�L���Er4���9n��COWlG�^��0k�%<���ZB���aB_���������'=��{i�v�l�$�uC���mƎҝ{�c㱼�y]���W�i ��ߧc��m�H� m�"�"�����;Y�ߝ�Z�Ǔ�����:S#��|}�y�,/k�Ld� TA�(�AI$+I3��;Y*���Z��}|��ӧO��d�v��..#:n��f>�>���ȶI�TX��� 8��y����"d�R�|�)0���=���n4��6ⲑ�+��r<�O�܂~zh�z����7ܓ�HH�Ga롏���nCo�>������a ���~]���R���̲c?�6(�q�;5%� |�uj�~z8R=X��I�V=�|{v�Gj\gc��q����z�؋%M�ߍ����1y��#��@f^���^�>N�����#x#۹��6�Y~�?�dfPO��{��P�4��V��u1E1J �*|���%���JN��`eWu�zk M6���q t[�� ��g�G���v��WIG��u_ft����5�j�"�Y�:T��ɐ���*�;� e5���4����q$C��2d�}���� _S�L#m�Yp��O�.�C�;��c����Hi#֩%+) �Ӎ��ƲV���SYź��g |���tj��3�8���r|���V��1#;.SQ�A[���S������#���`n�+���$��$I �P\[�@�s��(�ED�z���P��])8�G#��0B��[ى��X�II�q<��9�~[Z멜�Z�⊔IWU&A>�P~�#��dp<�?����7���c��'~���5 ��+$���lx@�M�dm��n<=e�dyX��?{�|Aef ,|n3�<~z�ƃ�uۧ�����P��Y,�ӥQ�*g�#먙R�\���;T��i,��[9Qi歉����c>]9�� ��"�c��P�� �Md?٥��If�ت�u��k��/����F��9�c*9��Ǎ:�ØF���z�n*�@|I�ށ9����N3{'��[�'ͬ�Ҳ4��#}��!�V� Fu��,�,mTIk���v C�7v���B�6k�T9��1�*l� '~��ƞF��lU��'�M ����][ΩũJ_�{�i�I�n��$���L�� j��O�dx�����kza۪��#�E��Cl����x˘�o�����V���ɞ�ljr��)�/,�߬h�L��#��^��L�ф�,íMƁe�̩�NB�L�����iL����q�}��(��q��6IçJ$�W�E$��:������=#����(�K�B����zђ <��K(�N�۫K�w��^O{!����)�H���>x�������lx�?>Պ�+�>�W���,Ly!_�D���Ō�l���Q�!�[ �S����J��1��Ɛ�Y}��b,+�Lo�x�ɓ)����=�y�oh�@�꥟/��I��ѭ=��P�y9��� �ۍYӘ�e+�p�Jnϱ?V\SO%�(�t� ���=?MR�[Ș�����d�/ ��n�l��B�7j� ��!�;ӥ�/�[-���A�>�dN�sLj ��,ɪv��=1c�.SQ�O3�U���ƀ�ܽ�E����������̻��9G�ϷD�7(�}��Ävӌ\�y�_0[w ���<΍>����a_��[0+�L��F.�޺��f�>oN�T����q;���y\��bՃ��y�jH�<|q-eɏ�_?_9+P���Hp$�����[ux�K w�Mw��N�ی'$Y2�=��q���KB��P��~������Yul:�[<����F1�2�O���5=d����]Y�sw:���Ϯ���E��j,_Q��X��z`H1,#II ��d�wr��P˂@�ZJV����y$�\y�{}��^~���[:N����ߌ�U�������O��d�����ؾe��${p>G��3c���Ė�lʌ�� ת��[��`ϱ�-W����dg�I��ig2��� ��}s ��ؤ(%#sS@���~���3�X�nRG�~\jc3�v��ӍL��M[JB�T��s3}��j�Nʖ��W����;7��ç?=X�F=-�=����q�ߚ���#���='�c��7���ڑW�I(O+=:uxq�������������e2�zi+�kuG�R��������0�&e�n���iT^J����~\jy���p'dtG��s����O��3����9* �b#Ɋ�� p������[Bws�T�>d4�ۧs���nv�n���U���_�~,�v����ƜJ1��s�� �QIz��)�(lv8M���U=�;����56��G���s#�K���MP�=��LvyGd��}�VwWBF�'�à �?MH�U�g2�� ����!�p�7Q��j��ڴ����=��j�u��� Jn�A s���uM������e��Ɔ�Ҕ�!)'��8Ϣ�ٔ��ޝ(��Vp���צ֖d=�IC�J�Ǡ{q������kԭ�߸���i��@K����u�|�p=..�*+����x�����z[Aqġ#s2a�Ɗ���RR�)*HRsi�~�a &f��M��P����-K�L@��Z��Xy�'x�{}��Zm+���:�)�) IJ�-i�u���� ���ܒH��'�L(7�y�GӜq���� j��� 6ߌg1�g�o���,kر���tY�?W,���p���e���f�OQS��!K�۟cҒA�|ս�j�>��=⬒��˧L[�� �߿2JaB~R��u�:��Q�] �0H~���]�7��Ƽ�I���(}��cq '�ήET���q�?f�ab���ӥvr� �)o��-Q��_'����ᴎo��K������;��V���o��%���~OK ����*��b�f:���-ťIR��`B�5!RB@���ï�� �u �̯e\�_U�_������� g�ES��3�������QT��a����x����U<~�c?�*�#]�MW,[8O�a�x��]�1bC|踤�P��lw5V%�)�{t�<��d��5���0i�XSU��m:��Z�┵�i�"��1�^B�-��P�hJ��&)O��*�D��c�W��vM��)����}���P��ܗ-q����\mmζZ-l@�}��a��E�6��F�@��&Sg@���ݚ�M����� ȹ 4����#p�\H����dYDo�H���"��\��..R�B�H�z_�/5˘����6��KhJR��P�mƶi�m���3�,#c�co��q�a)*Pt����R�m�k�7x�D�E�\Y�閣_X�<���~�)���c[[�BP����6�Yq���S��0����%_����;��Àv�~�| VS؇ ��'O0��F0��\���U�-�d@�����7�SJ*z��3n��y��P����O���������m�~�P�3|Y��ʉr#�C�<�G~�.,! ���bqx���h~0=��!ǫ�jy����l�O,�[B��~��|9��ٱ����Xly�#�i�B��g%�S��������tˋ���e���ې��\[d�t)��.+u�|1 ������#�~Oj����hS�%��i.�~X���I�H�m��0n���c�1uE�q��cF�RF�o���7� �O�ꮧ� ���ۛ{��ʛi5�rw?׌#Qn�TW��~?y$��m\�\o����%W� ?=>S�N@�� �Ʈ���R����N�)�r"C�:��:����� �����#��qb��Y�. �6[��2K����2u�Ǧ�HYR��Q�MV��� �G�$��Q+.>�����nNH��q�^��� ����q��mM��V��D�+�-�#*�U�̒ ���p욳��u:�������IB���m���PV@O���r[b= �� ��1U�E��_Nm�yKbN�O���U�}�the�`�|6֮P>�\2�P�V���I�D�i�P�O;�9�r�mAHG�W�S]��J*�_�G��+kP�2����Ka�Z���H�'K�x�W�MZ%�O�YD�Rc+o��?�q��Ghm��d�S�oh�\�D�|:W������UA�Qc yT�q������~^�H��/��#p�CZ���T�I�1�ӏT����4��"�ČZ�����}��`w�#�*,ʹ�� ��0�i��課�Om�*�da��^gJ݅{���l�e9uF#T�ֲ��̲�ٞC"�q���ߍ ոޑ�o#�XZTp����@ o�8��(jd��xw�]�,f���`~�|,s��^����f�1���t��|��m�򸄭/ctr��5s��7�9Q�4�H1꠲BB@l9@���C�����+�wp�xu�£Yc�9��?`@#�o�mH�s2��)�=��2�.�l����jg�9$�Y�S�%*L������R�Y������7Z���,*=�䷘$�������arm�o�ϰ���UW.|�r�uf����IGw�t����Zwo��~5 ��YյhO+=8fF�)�W�7�L9lM�̘·Y���֘YLf�큹�pRF���99.A �"wz��=E\Z���'a� 2��Ǚ�#;�'}�G���*��l��^"q��+2FQ� hj��kŦ��${���ޮ-�T�٭cf�|�3#~�RJ����t��$b�(R��(����r���dx� >U b�&9,>���%E\� Ά�e�$��'�q't��*�א���ެ�b��-|d���SB�O�O��$�R+�H�)�܎�K��1m`;�J�2�Y~9��O�g8=vqD`K[�F)k�[���1m޼c��n���]s�k�z$@��)!I �x՝"v��9=�ZA=`Ɠi �:�E��)`7��vI��}d�YI�_ �o�:ob���o ���3Q��&D&�2=�� �Ά��;>�h����y.*ⅥS������Ӭ�+q&����j|UƧ����}���J0��WW< ۋS�)jQR�j���Ư��rN)�Gű�4Ѷ(�S)Ǣ�8��i��W52���No˓� ۍ%�5brOn�L�;�n��\G����=�^U�dI���8$�&���h��'���+�(������cȁ߫k�l��S^���cƗjԌE�ꭔ��gF���Ȓ��@���}O���*;e�v�WV���YJ\�]X'5��ղ�k�F��b 6R�o՜m��i N�i����>J����?��lPm�U��}>_Z&�KK��q�r��I�D�Չ~�q�3fL�:S�e>���E���-G���{L�6p�e,8��������QI��h��a�Xa��U�A'���ʂ���s�+טIjP�-��y�8ۈZ?J$��W�P� ��R�s�]��|�l(�ԓ��sƊi��o(��S0��Y� 8�T97.�����WiL��c�~�dxc�E|�2!�X�K�Ƙਫ਼�$((�6�~|d9u+�qd�^3�89��Y�6L�.I�����?���iI�q���9�)O/뚅����O���X��X�V��ZF[�یgQ�L��K1���RҖr@v�#��X�l��F���Нy�S�8�7�kF!A��sM���^rkp�jP�DyS$N���q��nxҍ!U�f�!eh�i�2�m���`�Y�I�9r�6� �TF���C}/�y�^���Η���5d�'��9A-��J��>{�_l+�`��A���[�'��յ�ϛ#w:݅�%��X�}�&�PSt�Q�"�-��\縵�/����$Ɨh�Xb�*�y��BS����;W�ջ_mc�����vt?2}1�;qS�d�d~u:2k5�2�R�~�z+|HE!)�Ǟl��7`��0�<�,�2*���Hl-��x�^����'_TV�gZA�'j� ^�2Ϊ��N7t�����?w�� �x1��f��Iz�C-Ȗ��K�^q�;���-W�DvT�7��8�Z�������� hK�(P:��Q- �8�n�Z���܃e貾�<�1�YT<�,�����"�6{/ �?�͟��|1�:�#g��W�>$����d��J��d�B��=��jf[��%rE^��il:��B���x���Sּ�1հ��,�=��*�7 fcG��#q� �eh?��2�7�����,�!7x��6�n�LC�4x��},Geǝ�tC.��vS �F�43��zz\��;QYC,6����~;RYS/6���|2���5���v��T��i����������mlv��������&� �nRh^ejR�LG�f���? �ۉҬܦƩ��|��Ȱ����>3����!v��i�ʯ�>�v��オ�X3e���_1z�Kȗ\<������!�8���V��]��?b�k41�Re��T�q��mz��TiOʦ�Z��Xq���L������q"+���2ۨ��8}�&N7XU7Ap�d�X��~�׿��&4e�o�F��� �H����O���č�c�� 懴�6���͉��+)��v;j��ݷ�� �UV�� i��� j���Y9GdÒJ1��詞�����V?h��l����l�cGs�ځ�������y�Ac�����\V3�? �� ܙg�>qH�S,�E�W�[�㺨�uch�⍸�O�}���a��>�q�6�n6����N6�q������N ! 1AQaq�0@����"2BRb�#Pr���3C`��Scst���$4D���%Td�� ?���N����a��3��m���C���w��������xA�m�q�m���m������$����4n淿t'��C"w��zU=D�\R+w�p+Y�T�&�պ@��ƃ��3ޯ?�Aﶂ��aŘ���@-�����Q�=���9D��ռ�ѻ@��M�V��P��܅�G5�f�Y<�u=,EC)�<�Fy'�"�&�չ�X~f��l�KԆV��?�� �W�N����=(� �;���{�r����ٌ�Y���h{�١������jW����P���Tc�����X�K�r��}���w�R��%��?���E��m�� �Y�q|����\lEE4���r���}�lsI�Y������f�$�=�d�yO����p�����yBj8jU�o�/�S��?�U��*������ˍ�0������u�q�m [�?f����a�� )Q�>����6#������� ?����0UQ����,IX���(6ڵ[�DI�MNލ�c&���υ�j\��X�R|,4��� j������T�hA�e��^���d���b<����n�� �즇�=!���3�^�`j�h�ȓr��jẕ�c�,ٞX����-����a�ﶔ���#�$��]w�O��Ӫ�1y%��L�Y<�wg#�ǝ�̗`�x�xa�t�w��»1���o7o5��>�m뭛C���Uƃߜ}�C���y1Xνm�F8�jI���]����H���ۺиE@I�i;r�8ӭ����V�F�Շ| ��&?�3|x�B�MuS�Ge�=Ӕ�#BE5G�����Y!z��_e��q�р/W>|-�Ci߇�t�1ޯќd�R3�u��g�=0 5��[?�#͏��q�cf���H��{ ?u�=?�?ǯ���}Z��z���hmΔ�BFTW�����<�q�(v� ��!��z���iW]*�J�V�z��gX֧A�q�&��/w���u�gYӘa���; �i=����g:��?2�dž6�ى�k�4�>�Pxs����}������G�9��3 ���)gG�R<>r h�$��'nc�h�P��Bj��J�ҧH� -��N1���N��?��~��}-q!=��_2hc�M��l�vY%UE�@|�v����M2�.Y[|y�"Eï��K�ZF,�ɯ?,q�?v�M 80jx�"�;�9vk�����+ ֧�� �ȺU��?�%�vcV��mA�6��Qg^M����A}�3�nl� QRN�l8�kkn�'�����(��M�7m9و�q���%ޟ���*h$Zk"��$�9��: �?U8�Sl��,,|ɒ��xH(ѷ����Gn�/Q�4�P��G�%��Ա8�N��!� �&�7�;���eKM7�4��9R/%����l�c>�x;������>��C�:�����t��h?aKX�bhe�ᜋ^�$�Iհ �hr7%F$�E��Fd���t��5���+�(M6�t����Ü�UU|zW�=a�Ts�Tg������dqP�Q����b'�m���1{|Y����X�N��b �P~��F^F:����k6�"�j!�� �I�r�`��1&�-$�Bevk:y���#yw��I0��x��=D�4��tU���P�ZH��ڠ底taP��6����b>�xa����Q�#� WeF��ŮNj�p�J* mQ�N����*I�-*�ȩ�F�g�3 �5��V�ʊ�ɮ�a��5F���O@{���NX��?����H�]3��1�Ri_u��������ѕ�� ����0��� F��~��:60�p�͈�S��qX#a�5>���`�o&+�<2�D����: �������ڝ�$�nP���*)�N�|y�Ej�F�5ټ�e���ihy�Z �>���k�bH�a�v��h�-#���!�Po=@k̆IEN��@��}Ll?j�O������߭�ʞ���Q|A07x���wt!xf���I2?Z��<ץ�T���cU�j��]��陎Ltl �}5�ϓ��$�,��O�mˊ�;�@O��jE��j(�ا,��LX���LO���Ц�90�O �.����a��nA���7������j4 ��W��_ٓ���zW�jcB������y՗+EM�)d���N�g6�y1_x��p�$Lv:��9�"z��p���ʙ$��^��JԼ*�ϭ����o���=x�Lj�6�J��u82�A�H�3$�ٕ@�=Vv�]�'�qEz�;I˼��)��=��ɯ���x �/�W(V���p�����$ �m�������u�����񶤑Oqˎ�T����r��㠚x�sr�GC��byp�G��1ߠ�w e�8�$⿄����/�M{*}��W�]˷.�CK\�ުx���/$�WPw���r� |i���&�}�{�X� �>��$-��l���?-z���g����lΆ���(F���h�vS*���b���߲ڡn,|)mrH[���a�3�ר�[1��3o_�U�3�TC�$��(�=�)0�kgP���� ��u�^=��4 �WYCҸ:��vQ�ר�X�à��tk�m,�t*��^�,�}D*� �"(�I��9R����>`�`��[~Q]�#af��i6l��8���6�:,s�s�N6�j"�A4���IuQ��6E,�GnH��zS�HO�uk�5$�I�4��ؤ�Q9�@��C����wp�BGv[]�u�Ov���0I4���\��y�����Q�Ѹ��~>Z��8�T��a��q�ޣ;z��a���/��S��I:�ܫ_�|������>=Z����8:�S��U�I�J��"IY���8%b8���H��:�QO�6�;7�I�S��J��ҌAά3��>c���E+&jf$eC+�z�;��V����� �r���ʺ������my�e���aQ�f&��6�ND��.:��NT�vm�<- u���ǝ\MvZY�N�NT��-A�>jr!S��n�O 1�3�Ns�%�3D@���`������ܟ 1�^c<���� �a�ɽ�̲�Xë#�w�|y�cW�=�9I*H8�p�^(4���՗�k��arOcW�tO�\�ƍR��8����'�K���I�Q�����?5�>[�}��yU�ײ -h��=��% q�ThG�2�)���"ו3]�!kB��*p�FDl�A���,�eEi�H�f�Ps�����5�H:�Փ~�H�0Dت�D�I����h�F3�������c��2���E��9�H��5�zԑ�ʚ�i�X�=:m�xg�hd(�v����׊�9iS��O��d@0ڽ���:�p�5�h-��t�&���X�q�ӕ,��ie�|���7A�2���O%P��E��htj��Y1��w�Ѓ!����  ���� ࢽ��My�7�\�a�@�ţ�J �4�Ȼ�F�@o�̒?4�wx��)��]�P��~�����u�����5�����7X ��9��^ܩ�U;Iꭆ 5 �������eK2�7(�{|��Y׎ �V��\"���Z�1� Z�����}��(�Ǝ"�1S���_�vE30>���p;� ΝD��%x�W�?W?v����o�^V�i�d��r[��/&>�~`�9Wh��y�;���R��� ;;ɮT��?����r$�g1�K����A��C��c��K��l:�'��3 c�ﳯ*"t8�~l��)���m��+U,z��`(�>yJ�?����h>��]��v��ЍG*�{`��;y]��I�T� ;c��NU�fo¾h���/$���|NS���1�S�"�H��V���T���4��uhǜ�]�v;���5�͠x��'C\�SBpl���h}�N����� A�Bx���%��ޭ�l��/����T��w�ʽ]D�=����K���ž�r㻠l4�S�O?=�k �M:� ��c�C�a�#ha���)�ѐxc�s���gP�iG��{+���x���Q���I= �� z��ԫ+ �8"�k�ñ�j=|����c ��y��CF��/��*9ж�h{ �?4�o� ��k�m�Q�N�x��;�Y��4膚�a�w?�6�>e]�����Q�r�:����g�,i"�����ԩA�*M�<�G��b�if��l^M��5� �Ҩ�{����6J��ZJ�����P�*�����Y���ݛu�_4�9�I8�7���������,^ToR���m4�H��?�N�S�ѕw��/S��甍�@�9H�S�T��t�ƻ���ʒU��*{Xs�@����f�����֒Li�K{H�w^���������Ϥm�tq���s� ���ք��f:��o~s��g�r��ט� �S�ѱC�e]�x���a��) ���(b-$(�j>�7q�B?ӕ�F��hV25r[7 Y� }L�R��}����*sg+��x�r�2�U=�*'WS��ZDW]�WǞ�<��叓���{�$�9Ou4��y�90-�1�'*D`�c�^o?(�9��u���ݐ��'PI&� f�Jݮ�������:wS����jfP1F:X �H�9dԯ���˝[�_54 �}*;@�ܨ�� ð�yn�T���?�ןd�#���4rG�ͨ��H�1�|-#���Mr�S3��G�3�����)�.᧏3v�z֑��r����$G"�`j �1t��x0<Ɔ�Wh6�y�6��,œ�Ga��gA����y��b��)��h�D��ß�_�m��ü �gG;��e�v��ݝ�nQ� ��C����-�*��o���y�a��M��I�>�<���]obD��"�:���G�A��-\%LT�8���c�)��+y76���o�Q�#*{�(F�⽕�y����=���rW�\p���۩�c���A���^e6��K������ʐ�cVf5$�'->���ՉN"���F�"�UQ@�f��Gb~��#�&�M=��8�ט�JNu9��D��[̤�s�o�~������ G��9T�tW^g5y$b��Y'��س�Ǵ�=��U-2 #�MC�t(�i� �lj�@Q 5�̣i�*�O����s�x�K�f��}\��M{E�V�{�υ��Ƈ�����);�H����I��fe�Lȣr�2��>��W�I�Ȃ6������i��k�� �5�YOxȺ����>��Y�f5'��|��H+��98pj�n�.O�y�������jY��~��i�w'������l�;�s�2��Y��:'lg�ꥴ)o#'Sa�a�K��Z� �m��}�`169�n���"���x��I ��*+� }F<��cГ���F�P�������ֹ*�PqX�x۩��,� ��N�� �4<-����%����:��7����W���u�`����� $�?�I��&����o��o��`v�>��P��"��l���4��5'�Z�gE���8���?��[�X�7(��.Q�-��*���ތL@̲����v��.5���[��=�t\+�CNܛ��,g�SQnH����}*F�G16���&:�t��4ُ"A��̣��$�b �|����#rs��a�����T�� ]�<�j��BS�('$�ɻ� �wP;�/�n��?�ݜ��x�F��yUn�~mL*-�������Xf�wd^�a�}��f�,=t�׵i�.2/wpN�Ep8�OР���•��R�FJ� 55TZ��T �ɭ�<��]��/�0�r�@�f��V��V����Nz�G��^���7hZi����k��3�,kN�e|�vg�1{9]_i��X5y7� 8e]�U����'�-2,���e"����]ot�I��Y_��n�(JҼ��1�O ]bXc���Nu�No��pS���Q_���_�?i�~�x h5d'�(qw52] ��'ޤ�q��o1�R!���`ywy�A4u���h<קy���\[~�4�\ X�Wt/� 6�����n�F�a8��f���z �3$�t(���q��q�x��^�XWeN'p<-v�!�{�(>ӽDP7��ո0�y)�e$ٕv�Ih'Q�EA�m*�H��RI��=:��� ���4牢) �%_iN�ݧ�l]� �Nt���G��H�L��� ɱ�g<���1V�,�J~�ٹ�"K��Q�� 9�HS�9�?@��k����r�;we݁�]I�!{ �@�G�[�"��`���J:�n]�{�cA�E����V��ʆ���#��U9�6����j�#Y�m\��q�e4h�B�7��C�������d<�?J����1g:ٳ���=Y���D�p�ц� ׈ǔ��1�]26؜oS�'��9�V�FVu�P�h�9�xc�oq�X��p�o�5��Ա5$�9W�V(�[Ak�aY錎qf;�'�[�|���b�6�Ck��)��#a#a˙��8���=äh�4��2��C��4tm^ �n'c���]GQ$[Wҿ��i���vN�{Fu ��1�gx��1┷���N�m��{j-,��x�� Ūm�ЧS�[�s���Gna���䑴�� x�p 8<������97�Q���ϴ�v�aϚG��Rt�Һ׈�f^\r��WH�JU�7Z���y)�vg=����n��4�_)y��D'y�6�]�c�5̪�\� �PF�k����&�c;��cq�$~T�7j ���nç]�<�g ":�to�t}�159�<�/�8������m�b�K#g'I'.W�����6��I/��>v��\�MN��g���m�A�yQL�4u�Lj�j9��#44�t��l^�}L����n��R��!��t��±]��r��h6ٍ>�yҏ�N��fU�� ���� Fm@�8}�/u��jb9������he:A�y�ծw��GpΧh�5����l}�3p468��)U��d��c����;Us/�֔�YX�1�O2��uq�s��`hwg�r~�{ R��mhN��؎*q 42�*th��>�#���E����#��Hv�O����q�}�����6�e��\�,Wk�#���X��b>��p}�դ��3���T5��†��6��[��@�P�y*n��|'f�֧>�lư΂�̺����SU�'*�q�p�_S�����M�� '��c�6�����m�� ySʨ;M��r���Ƌ�m�Kxo,���Gm�P��A�G�:��i��w�9�}M(�^�V��$ǒ�ѽ�9���|���� �a����J�SQ�a���r�B;����}���ٻ֢�2�%U���c�#�g���N�a�ݕ�'�v�[�OY'��3L�3�;,p�]@�S��{ls��X�'���c�jw�k'a�.��}�}&�� �dP�*�bK=ɍ!����;3n�gΊU�ߴmt�'*{,=SzfD� A��ko~�G�aoq�_mi}#�m�������P�Xhύ����mxǍ�΂���巿zf��Q���c���|kc�����?���W��Y�$���_Lv����l߶��c���`?����l�j�ݲˏ!V��6����U�Ђ(A���4y)H���p�Z_�x��>���e��R��$�/�`^'3qˏ�-&Q�=?��CFVR �D�fV�9��{�8g�������n�h�(P"��6�[�D���< E�����~0<@�`�G�6����Hг�cc�� �c�K.5��D��d�B���`?�XQ��2��ٿyqo&+�1^� DW�0�ꊩ���G�#��Q�nL3��c���������/��x ��1�1[y�x�პCW��C�c�UĨ80�m�e�4.{�m��u���I=��f�����0QRls9���f���������9���~f�����Ǩ��a�"@�8���ȁ�Q����#c�ic������G��$���G���r/$W�(��W���V�"��m�7�[m�A�m����bo��D� j����۳� l���^�k�h׽����� ��#� iXn�v��eT�k�a�^Y�4�BN��ĕ��0 !01@Q"2AaPq3BR������?���@4�Q�����T3,���㺠�W�[=JK�Ϟ���2�r^7��vc�:�9 �E�ߴ�w�S#d���Ix��u��:��Hp��9E!�� V 2;73|F��9Y���*ʬ�F��D����u&���y؟��^EA��A��(ɩ���^��GV:ݜDy�`��Jr29ܾ�㝉��[���E;Fzx��YG��U�e�Y�C���� ����v-tx����I�sם�Ę�q��Eb�+P\ :>�i�C'�;�����k|z�رn�y]�#ǿb��Q��������w�����(�r|ӹs��[�D��2v-%��@;�8<a���[\o[ϧw��I!��*0�krs)�[�J9^��ʜ��p1)� "��/_>��o��<1����A�E�y^�C��`�x1'ܣn�p��s`l���fQ��):�l����b>�Me�jH^?�kl3(�z:���1ŠK&?Q�~�{�ٺ�h�y���/�[��V�|6��}�KbX����mn[-��7�5q�94�������dm���c^���h� X��5��<�eޘ>G���-�}�دB�ޟ� ��|�rt�M��V+�]�c?�-#ڛ��^ǂ}���Lkr���O��u�>�-D�ry� D?:ޞ�U��ǜ�7�V��?瓮�"�#���r��չģVR;�n���/_� ؉v�ݶe5d�b9��/O��009�G���5n�W����JpA�*�r9�>�1��.[t���s�F���nQ� V 77R�]�ɫ8����_0<՜�IF�u(v��4��F�k�3��E)��N:��yڮe��P�`�1}�$WS��J�SQ�N�j�ٺ��޵�#l���ј(�5=��5�lǏmoW�v-�1����v,W�mn��߀$x�<����v�j(����c]��@#��1������Ǔ���o'��u+����;G�#�޸��v-lη��/(`i⣍Pm^���ԯ̾9Z��F��������n��1��� ��]�[��)�'������:�֪�W��FC����� �B9،!?���]��V��A�Վ�M��b�w��G F>_DȬ0¤�#�QR�[V��kz���m�w�"��9ZG�7'[��=�Q����j8R?�zf�\a�=��O�U����*oB�A�|G���2�54 �p��.w7� �� ��&������ξxGHp� B%��$g�����t�Џ򤵍z���HN�u�Я�-�'4��0��;_��3 !01"@AQa2Pq#3BR������?��ʩca��en��^��8���<�u#��m*08r��y�N"�<�Ѳ0��@\�p��� �����Kv�D��J8�Fҽ� �f�Y��-m�ybX�NP����}�!*8t(�OqѢ��Q�wW�K��ZD��Δ^e��!� ��B�K��p~�����e*l}z#9ң�k���q#�Ft�o��S�R����-�w�!�S���Ӥß|M�l޶V��!eˈ�8Y���c�ЮM2��tk���� ������J�fS����Ö*i/2�����n]�k�\���|4yX�8��U�P.���Ы[���l��@"�t�<������5�lF���vU�����W��W��;�b�cД^6[#7@vU�xgZv��F�6��Q,K�v��� �+Ъ��n��Ǣ��Ft���8��0��c�@�!�Zq s�v�t�;#](B��-�nῃ~���3g������5�J�%���O������n�kB�ĺ�.r��+���#�N$?�q�/�s�6��p��a����a��J/��M�8��6�ܰ"�*������ɗud"\w���aT(����[��F��U՛����RT�b���n�*��6���O��SJ�.�ij<�v�MT��R\c��5l�sZB>F��<7�;EA��{��E���Ö��1U/�#��d1�a�n.1ě����0�ʾR�h��|�R��Ao�3�m3 ��%�� ���28Q� ��y��φ���H�To�7�lW>����#i`�q���c����a��� �m,B�-j����݋�'mR1Ήt�>��V��p���s�0IbI�C.���1R�ea�����]H�6����������4B>��o��](��$B���m�����a�!=��?�B� K�Ǿ+�Ծ"�n���K��*��+��[T#�{E�J�S����Q�����s�5�:�U�\wĐ�f�3����܆&�)����I���Ԇw��E T�lrTf6Q|R�h:��[K�� �z��c֧�G�C��%\��_�a�84��HcO�bi��ؖV��7H �)*ģK~Xhչ0��4?�0��� �E<���}3���#���u�?�� ��|g�S�6ꊤ�|�I#Hڛ� �ա��w�X��9��7���Ŀ%�SL��y6č��|�F�a 8���b��$�sק�h���b9RAu7�˨p�Č�_\*w��묦��F ����4D~�f����|(�"m���NK��i�S�>�$d7SlA��/�²����SL��|6N�}���S�˯���g��]6��; �#�.��<���q'Q�1|KQ$�����񛩶"�$r�b:���N8�w@��8$�� �AjfG|~�9F ���Y��ʺ��Bwؒ������M:I岎�G��`s�YV5����6��A �b:�W���G�q%l�����F��H���7�������Fsv7��k�� 403WebShell
403Webshell
Server IP : 51.161.54.47  /  Your IP : 216.73.216.98
Web Server : Apache/2.4.68 (Unix) OpenSSL/1.1.1k
System : Linux host.ditinformatica.ar 4.18.0-553.153.1.el8_10.x86_64 #1 SMP Thu Aug 6 00:53:12 EDT 2026 x86_64
User : kalaycom ( 1021)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/share/xml/scap/ssg/content/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/share/xml/scap/ssg/content/ssg-firefox-ds-1.2.xml
<?xml version="1.0" encoding="utf-8"?>
<ds:data-stream-collection xmlns:cat="urn:oasis:names:tc:entity:xmlns:xml:catalog" xmlns:cpe-dict="http://cpe.mitre.org/dictionary/2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ds="http://scap.nist.gov/schema/scap/source/1.2" xmlns:html="http://www.w3.org/1999/xhtml" xmlns:ind="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ocil="http://scap.nist.gov/schema/ocil/2.0" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="scap_org.open-scap_collection_from_xccdf_ssg-firefox-xccdf.xml" schematron-version="1.3">
  <ds:data-stream id="scap_org.open-scap_datastream_from_xccdf_ssg-firefox-xccdf.xml" scap-version="1.3" timestamp="2026-06-15T09:08:53" use-case="OTHER">
    <ds:dictionaries>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-firefox-cpe-dictionary.xml" xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml">
        <cat:catalog>
          <cat:uri name="ssg-firefox-cpe-oval.xml" uri="#scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"/>
        </cat:catalog>
      </ds:component-ref>
    </ds:dictionaries>
    <ds:checklists>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-firefox-xccdf.xml" xlink:href="#scap_org.open-scap_comp_ssg-firefox-xccdf.xml">
        <cat:catalog>
          <cat:uri name="ssg-firefox-oval.xml" uri="#scap_org.open-scap_cref_ssg-firefox-oval.xml"/>
          <cat:uri name="ssg-firefox-ocil.xml" uri="#scap_org.open-scap_cref_ssg-firefox-ocil.xml"/>
          <cat:uri name="ssg-firefox-cpe-oval.xml" uri="#scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"/>
        </cat:catalog>
      </ds:component-ref>
    </ds:checklists>
    <ds:checks>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-firefox-oval.xml" xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-firefox-ocil.xml" xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml" xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
    </ds:checks>
  </ds:data-stream>
  <ds:component id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml" timestamp="2026-06-15T09:08:53">
    <cpe-dict:cpe-list xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <cpe-dict:cpe-item name="cpe:/a:mozilla:firefox">
        <cpe-dict:title xml:lang="en-us">Mozilla Firefox</cpe-dict:title>
        <cpe-dict:check href="ssg-firefox-cpe-oval.xml" system="http://oval.mitre.org/XMLSchema/oval-definitions-5">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
      </cpe-dict:cpe-item>
    </cpe-dict:cpe-list>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml" timestamp="2026-06-15T09:08:53">
    <xccdf-1.2:Benchmark id="xccdf_org.ssgproject.content_benchmark_FIREFOX" resolved="true" style="SCAP_1.2" xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2 xccdf-1.2.xsd" xml:lang="en-US">
      <xccdf-1.2:status date="2026-06-15">draft</xccdf-1.2:status>
      <xccdf-1.2:title>Guide to the Secure Configuration of Firefox</xccdf-1.2:title>
      <xccdf-1.2:description>This guide presents a catalog of security-relevant
configuration settings for Firefox. It is a rendering of
content structured in the eXtensible Configuration Checklist Description Format (XCCDF)
in order to support security automation.  The SCAP content is
is available in the <html:code>scap-security-guide</html:code> package which is developed at

    <html:a href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>.
<html:br/><html:br/>
Providing system administrators with such guidance informs them how to securely
configure systems under their control in a variety of network roles. Policy
makers and baseline creators can use this catalog of settings, with its
associated references to higher-level security control catalogs, in order to
assist them in security baseline creation. This guide is a <html:em>catalog, not a
checklist</html:em>, and satisfaction of every item is not likely to be possible or
sensible in many operational scenarios. However, the XCCDF format enables
granular selection and adjustment of settings, and their association with OVAL
and OCIL content provides an automated checking capability. Transformations of
this document, and its associated automated checking content, are capable of
providing baselines that meet a diverse set of policy objectives. Some example
XCCDF <html:em>Profiles</html:em>, which are selections of items that form checklists and
can be used as baselines, are available with this guide. They can be
processed, in an automated fashion, with tools that support the Security
Content Automation Protocol (SCAP). The DISA STIG for Firefox,
which provides required settings for US Department of Defense systems, is
one example of a baseline created from this guidance.
</xccdf-1.2:description>
      <xccdf-1.2:notice id="terms_of_use">Do not attempt to implement any of the settings in
this guide without first testing them in a non-operational environment. The
creators of this guidance assume no responsibility whatsoever for its use by
other parties, and makes no guarantees, expressed or implied, about its
quality, reliability, or any other characteristic.
</xccdf-1.2:notice>
      <xccdf-1.2:front-matter>The SCAP Security Guide Project<html:br/>

    <html:a href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
</xccdf-1.2:front-matter>
      <xccdf-1.2:rear-matter>Red Hat and Red Hat Enterprise Linux are either registered
trademarks or trademarks of Red Hat, Inc. in the United States and other
countries. All other names are registered trademarks or trademarks of their
respective companies.
</xccdf-1.2:rear-matter>
      <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">anssi</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers">app-srg</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">app-srg-ctr</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">bsi</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">cis-csc</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">cjis</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">cobit5</xccdf-1.2:reference>
      <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">cui</xccdf-1.2:reference>
      <xccdf-1.2:reference href="not_officially_available">dcid</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/cci/">disa</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">hipaa</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">isa-62443-2009</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">isa-62443-2013</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">ism</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">iso27001-2013</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">nerc-cip</xccdf-1.2:reference>
      <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">nist</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">nist-csf</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
      <xccdf-1.2:platform idref="cpe:/a:mozilla:firefox"/>
      <xccdf-1.2:version update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.81</xccdf-1.2:version>
      <xccdf-1.2:metadata>
        <dc:publisher>SCAP Security Guide Project</dc:publisher>
        <dc:creator>SCAP Security Guide Project</dc:creator>
        <dc:contributor>Frank J Cameron (CAM1244) &lt;cameron@ctc.com&gt;</dc:contributor>
        <dc:contributor>0x66656c6978 &lt;0x66656c6978@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Håvard F. Aasen &lt;havard.f.aasen@pfft.no&gt;</dc:contributor>
        <dc:contributor>Armando Acosta &lt;armando.acosta@oracle.com&gt;</dc:contributor>
        <dc:contributor>Jack Adolph &lt;jack.adolph@gmail.com&gt;</dc:contributor>
        <dc:contributor>Edgar Aguilar &lt;edgar.aguilar@oracle.com&gt;</dc:contributor>
        <dc:contributor>akuster &lt;akuster808@gmail.com&gt;</dc:contributor>
        <dc:contributor>Gabe Alford &lt;redhatrises@gmail.com&gt;</dc:contributor>
        <dc:contributor>Firas AlShafei &lt;firas.alshafei@us.abb.com&gt;</dc:contributor>
        <dc:contributor>Rodrigo Alvares &lt;ralvares@redhat.com&gt;</dc:contributor>
        <dc:contributor>am-tux &lt;andrew.miller11@gmail.com&gt;</dc:contributor>
        <dc:contributor>Christopher Anderson &lt;cba@fedoraproject.org&gt;</dc:contributor>
        <dc:contributor>Craig Andrews &lt;candrews@integralblue.com&gt;</dc:contributor>
        <dc:contributor>angystardust &lt;angystardust@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>anivan-suse &lt;anastasija.ivanovic@suse.com&gt;</dc:contributor>
        <dc:contributor>anixon-rh &lt;55244503+anixon-rh@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Anna-Koudelkova &lt;akoudelk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Arden97 &lt;arden2545@gmail.com&gt;</dc:contributor>
        <dc:contributor>Steve Arnold &lt;sarnold@vctlabs.com&gt;</dc:contributor>
        <dc:contributor>Ikko Ashimine &lt;eltociear@gmail.com&gt;</dc:contributor>
        <dc:contributor>Chuck Atkins &lt;chuck.atkins@kitware.com&gt;</dc:contributor>
        <dc:contributor>axuan &lt;axuan@redhat.com&gt;</dc:contributor>
        <dc:contributor>Bharath B &lt;bhb@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ryan Ballanger &lt;root@rballang-admin-2.fastenal.com&gt;</dc:contributor>
        <dc:contributor>Alex Baranowski &lt;alex@euro-linux.com&gt;</dc:contributor>
        <dc:contributor>Eduardo Barretto &lt;eduardo.barretto@canonical.com&gt;</dc:contributor>
        <dc:contributor>Paul Bastide &lt;pbastide@us.ibm.com&gt;</dc:contributor>
        <dc:contributor>Molly Jo Bault &lt;Molly.Jo.Bault@ballardtech.com&gt;</dc:contributor>
        <dc:contributor>Andrew Becker &lt;A-Beck@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gabriel Becker &lt;ggasparb@redhat.com&gt;</dc:contributor>
        <dc:contributor>BenGui &lt;benoit.guillon1@etu.unilim.fr&gt;</dc:contributor>
        <dc:contributor>Alexander Bergmann &lt;abergmann@suse.com&gt;</dc:contributor>
        <dc:contributor>Eric Berry &lt;eric@approvedworkman.com&gt;</dc:contributor>
        <dc:contributor>Dale Bewley &lt;dale@bewley.net&gt;</dc:contributor>
        <dc:contributor>Jose Luis BG &lt;bgjoseluis@gmail.com&gt;</dc:contributor>
        <dc:contributor>binyanling &lt;binyanling@uniontech.com&gt;</dc:contributor>
        <dc:contributor>Joseph Bisch &lt;joseph.bisch@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jeff Blank &lt;blank@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Olivier Bonhomme &lt;ptitoliv@ptitoliv.net&gt;</dc:contributor>
        <dc:contributor>bontreger &lt;bontreger@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Lance Bragstad &lt;lbragstad@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vickey Brown &lt;vibrown@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ted Brunell &lt;tbrunell@redhat.com&gt;</dc:contributor>
        <dc:contributor>Marcus Burghardt &lt;maburgha@redhat.com&gt;</dc:contributor>
        <dc:contributor>Matthew Burket &lt;mburket@redhat.com&gt;</dc:contributor>
        <dc:contributor>Blake Burkhart &lt;blake.burkhart@us.af.mil&gt;</dc:contributor>
        <dc:contributor>Patrick Callahan &lt;pmc@patrickcallahan.com&gt;</dc:contributor>
        <dc:contributor>George Campbell &lt;gcampbell@palantir.com&gt;</dc:contributor>
        <dc:contributor>Nick Carboni &lt;ncarboni@redhat.com&gt;</dc:contributor>
        <dc:contributor>Carlos &lt;64919342+carlosmmatos@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>James Cassell &lt;james.cassell@ll.mit.edu&gt;</dc:contributor>
        <dc:contributor>Frank Caviggia &lt;fcaviggia@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sinong Chen &lt;costinchen@tencent.com&gt;</dc:contributor>
        <dc:contributor>Eric Christensen &lt;echriste@redhat.com&gt;</dc:contributor>
        <dc:contributor>Dan Clark &lt;danclark@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jayson Cofell &lt;1051437+70k10@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>David du Colombier &lt;djc@datadoghq.com&gt;</dc:contributor>
        <dc:contributor>Commandcracker &lt;lukas.fricke.dev@gmail.com&gt;</dc:contributor>
        <dc:contributor>Caleb Cooper &lt;coopercd@ornl.gov&gt;</dc:contributor>
        <dc:contributor>CoreyCook8 &lt;129206271+CoreyCook8@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>cortesana &lt;acortes@redhat.com&gt;</dc:contributor>
        <dc:contributor>Richard Maciel Costa &lt;richard.maciel.costa@canonical.com&gt;</dc:contributor>
        <dc:contributor>Xavier Coulon &lt;xavier.coulon@suse.com&gt;</dc:contributor>
        <dc:contributor>Deric Crago &lt;deric.crago@gmail.com&gt;</dc:contributor>
        <dc:contributor>crleekwc &lt;crleekwc@gmail.com&gt;</dc:contributor>
        <dc:contributor>cueball23 &lt;christoph.alms@westnetz.de&gt;</dc:contributor>
        <dc:contributor>cyarbrough76 &lt;42849651+cyarbrough76@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Maura Dailey &lt;maura@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Harold Dean &lt;hdean3@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Benjamin Deering &lt;ben_deering@jeepingben.net&gt;</dc:contributor>
        <dc:contributor>Shane Dell &lt;shanedell100@gmail.com&gt;</dc:contributor>
        <dc:contributor>Klaas Demter &lt;demter@atix.de&gt;</dc:contributor>
        <dc:contributor>denknorr &lt;dennis.knorr@suse.com&gt;</dc:contributor>
        <dc:contributor>dhanushkar-wso2 &lt;dhanushkar@wso2.com&gt;</dc:contributor>
        <dc:contributor>Andrew DiPrinzio &lt;andrew.diprinzio@jhuapl.edu&gt;</dc:contributor>
        <dc:contributor>dom &lt;dominique.blaze@devinci.fr&gt;</dc:contributor>
        <dc:contributor>Jean-Baptiste Donnette &lt;jean-baptiste.donnette@epita.fr&gt;</dc:contributor>
        <dc:contributor>Marco De Donno &lt;mdedonno1337@gmail.com&gt;</dc:contributor>
        <dc:contributor>dperrone &lt;dperrone@redhat.com&gt;</dc:contributor>
        <dc:contributor>drax &lt;applezip@gmail.com&gt;</dc:contributor>
        <dc:contributor>Qingmin Duanmu &lt;qduanmu@redhat.com&gt;</dc:contributor>
        <dc:contributor>Sebastian Dunne &lt;sdunne@redhat.com&gt;</dc:contributor>
        <dc:contributor>François Duthilleul &lt;francoisduthilleul@gmail.com&gt;</dc:contributor>
        <dc:contributor>Greg Elin &lt;gregelin@gitmachines.com&gt;</dc:contributor>
        <dc:contributor>eradot4027 &lt;jrtonmac@gmail.com&gt;</dc:contributor>
        <dc:contributor>ericeberry &lt;ericeberry@gmail.com&gt;</dc:contributor>
        <dc:contributor>ermeratos &lt;manuel.ermer@eviden.net&gt;</dc:contributor>
        <dc:contributor>Evelyn &lt;evansvevelyn@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alexis Facques &lt;alexis.facques@mythalesgroup.io&gt;</dc:contributor>
        <dc:contributor>Jan Fader &lt;jan.fader@web.de&gt;</dc:contributor>
        <dc:contributor>felixmarch &lt;felixmarch@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Asser Schrøder Femø &lt;asser@asser.org&gt;</dc:contributor>
        <dc:contributor>Henry Finucane &lt;hfinucane@zscaler.com&gt;</dc:contributor>
        <dc:contributor>Leah Fisher &lt;lfisher047@gmail.com&gt;</dc:contributor>
        <dc:contributor>Marco Fortina &lt;marco_fortina@hotmail.it&gt;</dc:contributor>
        <dc:contributor>Yavor Georgiev &lt;strandjata@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alijohn Ghassemlouei &lt;alijohn@secureagc.com&gt;</dc:contributor>
        <dc:contributor>Swarup Ghosh &lt;swghosh@redhat.com&gt;</dc:contributor>
        <dc:contributor>ghylock &lt;ghylock@gmail.com&gt;</dc:contributor>
        <dc:contributor>Andrew Gilmore &lt;agilmore2@gmail.com&gt;</dc:contributor>
        <dc:contributor>Joshua Glemza &lt;jglemza@nasa.gov&gt;</dc:contributor>
        <dc:contributor>Nick Gompper &lt;forestgomp@yahoo.com&gt;</dc:contributor>
        <dc:contributor>David Fernandez Gonzalez &lt;david.fernandezgonzalez@canonical.com&gt;</dc:contributor>
        <dc:contributor>Loren Gordon &lt;lorengordon@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gene Gotimer &lt;otherdevopsgene@portinfo.com&gt;</dc:contributor>
        <dc:contributor>Patrik Greco &lt;sikevux@sikevux.se&gt;</dc:contributor>
        <dc:contributor>Steve Grubb &lt;sgrubb@redhat.com&gt;</dc:contributor>
        <dc:contributor>guangyee &lt;gyee@suse.com&gt;</dc:contributor>
        <dc:contributor>Bhargavi Gudi &lt;bgudi@bgudi-thinkpadt14sgen2i.remote.csb&gt;</dc:contributor>
        <dc:contributor>Christian Hagenest &lt;christian.hagenest@suse.com&gt;</dc:contributor>
        <dc:contributor>Marek Haicman &lt;mhaicman@redhat.com&gt;</dc:contributor>
        <dc:contributor>Sun, Haoxiang &lt;haoxiang.sun@intel.com&gt;</dc:contributor>
        <dc:contributor>Vern Hart &lt;vern.hart@canonical.com&gt;</dc:contributor>
        <dc:contributor>Alex Haydock &lt;alex@alexhaydock.co.uk&gt;</dc:contributor>
        <dc:contributor>Rebekah Hayes &lt;rhayes@corp.rivierautilities.com&gt;</dc:contributor>
        <dc:contributor>hazerre &lt;kotadouglas2@gmail.com&gt;</dc:contributor>
        <dc:contributor>Trey Henefield &lt;thenefield@gmail.com&gt;</dc:contributor>
        <dc:contributor>Henning Henkel &lt;henning.henkel@helvetia.ch&gt;</dc:contributor>
        <dc:contributor>hex2a &lt;hex2a@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>hipponix &lt;mirco.santori@gmail.com&gt;</dc:contributor>
        <dc:contributor>John Hooks &lt;jhooks@starscream.pa.jhbcomputers.com&gt;</dc:contributor>
        <dc:contributor>Jakub Hrozek &lt;jhrozek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Donald Hunter &lt;donald.hunter@gmail.com&gt;</dc:contributor>
        <dc:contributor>De Huo &lt;De.Huo@windriver.com&gt;</dc:contributor>
        <dc:contributor>Robin Price II &lt;robin@redhat.com&gt;</dc:contributor>
        <dc:contributor>Yasir Imam &lt;yimam@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jiri Jaburek &lt;jjaburek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Keith Jackson &lt;keithkjackson@gmail.com&gt;</dc:contributor>
        <dc:contributor>Marc Jadoul &lt;mgjadoul@laptomatic.auth-o-matic.corp&gt;</dc:contributor>
        <dc:contributor>Jeremiah Jahn &lt;jeremiah@goodinassociates.com&gt;</dc:contributor>
        <dc:contributor>Jakub Jelen &lt;jjelen@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jessicahfy &lt;Jessicahfy@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Stephan Joerrens &lt;Stephan.Joerrens@fiduciagad.de&gt;</dc:contributor>
        <dc:contributor>Simon John &lt;sjohn@tuxcare.com&gt;</dc:contributor>
        <dc:contributor>Hunter Jones &lt;hjones2199@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jono &lt;jono@ubuntu-18.localdomain&gt;</dc:contributor>
        <dc:contributor>julius.ish &lt;julius.ish@zetier.com&gt;</dc:contributor>
        <dc:contributor>justchris1 &lt;justchris1@justchris1.email&gt;</dc:contributor>
        <dc:contributor>Kacper &lt;kacper@kacper.se&gt;</dc:contributor>
        <dc:contributor>Kai Kang &lt;kai.kang@windriver.com&gt;</dc:contributor>
        <dc:contributor>Charles Kernstock &lt;charles.kernstock@ultra-ats.com&gt;</dc:contributor>
        <dc:contributor>Yuli Khodorkovskiy &lt;ykhodorkovskiy@tresys.com&gt;</dc:contributor>
        <dc:contributor>Sherine Khoury &lt;skhoury@redhat.com&gt;</dc:contributor>
        <dc:contributor>Nathan Kinder &lt;nkinder@redhat.com&gt;</dc:contributor>
        <dc:contributor>Lee Kinser &lt;lee.kinser@gmail.com&gt;</dc:contributor>
        <dc:contributor>Evgeny Kolesnikov &lt;ekolesni@redhat.com&gt;</dc:contributor>
        <dc:contributor>Peter 'Pessoft' Kolínek &lt;github@pessoft.com&gt;</dc:contributor>
        <dc:contributor>Luke Kordell &lt;luke.t.kordell@lmco.com&gt;</dc:contributor>
        <dc:contributor>Malte Kraus &lt;malte.kraus@suse.com&gt;</dc:contributor>
        <dc:contributor>Seth Kress &lt;seth.kress@dsainc.com&gt;</dc:contributor>
        <dc:contributor>Felix Krohn &lt;felix.krohn@helvetia.ch&gt;</dc:contributor>
        <dc:contributor>kspargur &lt;kspargur@kspargur.csb&gt;</dc:contributor>
        <dc:contributor>Amit Kumar &lt;amitkuma@redhat.com&gt;</dc:contributor>
        <dc:contributor>Fen Labalme &lt;fen@civicactions.com&gt;</dc:contributor>
        <dc:contributor>Dexter Le &lt;dexter.le@sap.com&gt;</dc:contributor>
        <dc:contributor>Dimitri John Ledkov &lt;dimitri.ledkov@surgut.co.uk&gt;</dc:contributor>
        <dc:contributor>Ade Lee &lt;alee@redhat.com&gt;</dc:contributor>
        <dc:contributor>Christopher Lee &lt;Crleekwc@gmail.com&gt;</dc:contributor>
        <dc:contributor>Ian Lee &lt;lee1001@llnl.gov&gt;</dc:contributor>
        <dc:contributor>Jarrett Lee &lt;jarrettl@umd.edu&gt;</dc:contributor>
        <dc:contributor>Joseph Lenox &lt;joseph.lenox@collins.com&gt;</dc:contributor>
        <dc:contributor>Stefano Libero &lt;stefano.libero@nozominetworks.com&gt;</dc:contributor>
        <dc:contributor>lichtblaugue &lt;guenther.lichtblau@eviden.com&gt;</dc:contributor>
        <dc:contributor>Jan Lieskovsky &lt;jlieskov@redhat.com&gt;</dc:contributor>
        <dc:contributor>Markus Linnala &lt;Markus.Linnala@knowit.fi&gt;</dc:contributor>
        <dc:contributor>Flos Lonicerae &lt;lonicerae@gmail.com&gt;</dc:contributor>
        <dc:contributor>Simon Lukasik &lt;slukasik@redhat.com&gt;</dc:contributor>
        <dc:contributor>Andrew Lukoshko &lt;andrew.lukoshko@gmail.com&gt;</dc:contributor>
        <dc:contributor>Milan Lysonek &lt;mlysonek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Fredrik Lysén &lt;fredrik@pipemore.se&gt;</dc:contributor>
        <dc:contributor>Mackemania &lt;8738793+Mackemania@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Peter Macko &lt;pmacko@redhat.com&gt;</dc:contributor>
        <dc:contributor>Caitlin Macleod &lt;caitelatte@gmail.com&gt;</dc:contributor>
        <dc:contributor>Dmitry Makovey &lt;dmakovey@yahoo.com&gt;</dc:contributor>
        <dc:contributor>Nick Maludy &lt;nmaludy@gmail.com&gt;</dc:contributor>
        <dc:contributor>Lokesh Mandvekar &lt;lsm5@fedoraproject.org&gt;</dc:contributor>
        <dc:contributor>Matus Marhefka &lt;mmarhefk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jamie Lorwey Martin &lt;jlmartin@redhat.com&gt;</dc:contributor>
        <dc:contributor>Carlos Matos &lt;cmatos@redhat.com&gt;</dc:contributor>
        <dc:contributor>Robert McAllister &lt;rmcallis@redhat.com&gt;</dc:contributor>
        <dc:contributor>Karen McCarron &lt;kmccarro@redhat.com&gt;</dc:contributor>
        <dc:contributor>Michael McConachie &lt;michael@redhat.com&gt;</dc:contributor>
        <dc:contributor>Marcus Meissner &lt;meissner@suse.de&gt;</dc:contributor>
        <dc:contributor>Khary Mendez &lt;kmendez@redhat.com&gt;</dc:contributor>
        <dc:contributor>Rodney Mercer &lt;rmercer@harris.com&gt;</dc:contributor>
        <dc:contributor>Matt Micene &lt;nzwulfin@gmail.com&gt;</dc:contributor>
        <dc:contributor>Brian Millett &lt;bmillett@gmail.com&gt;</dc:contributor>
        <dc:contributor>Takuya Mishina &lt;tmishina@jp.ibm.com&gt;</dc:contributor>
        <dc:contributor>Mixer9 &lt;35545791+Mixer9@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>mmosel &lt;mmosel@kde.example.com&gt;</dc:contributor>
        <dc:contributor>Thomas Montague &lt;montague.thomas@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alan Moore &lt;alan.moore@canonical.com&gt;</dc:contributor>
        <dc:contributor>Zbynek Moravec &lt;zmoravec@redhat.com&gt;</dc:contributor>
        <dc:contributor>Kazuo Moriwaka &lt;moriwaka@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Michael Moseley &lt;michael@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Samir MOUHOUNE &lt;samir.mouhoune@nav-timing.safrangroup.com&gt;</dc:contributor>
        <dc:contributor>Nathan Moyer &lt;nmoyer@spectric.com&gt;</dc:contributor>
        <dc:contributor>Ross Murphy &lt;RossMurphy@ibm.com&gt;</dc:contributor>
        <dc:contributor>Renaud Métrich &lt;rmetrich@redhat.com&gt;</dc:contributor>
        <dc:contributor>Joe Nall &lt;joe@nall.com&gt;</dc:contributor>
        <dc:contributor>namoyer10 &lt;48189779+namoyer10@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Neiloy &lt;neiloy@redhat.com&gt;</dc:contributor>
        <dc:contributor>Axel Nennker &lt;axel@nennker.de&gt;</dc:contributor>
        <dc:contributor>Michele Newman &lt;mnewman@redhat.com&gt;</dc:contributor>
        <dc:contributor>nnerdmann &lt;128606223+nnerdmann@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sean O'Keeffe &lt;seanokeeffe797@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jiri Odehnal &lt;jodehnal@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ilya Okomin &lt;ilya.okomin@oracle.com&gt;</dc:contributor>
        <dc:contributor>Kaustubh Padegaonkar &lt;theTuxRacer@gmail.com&gt;</dc:contributor>
        <dc:contributor>Michael Palmiotto &lt;mpalmiotto@tresys.com&gt;</dc:contributor>
        <dc:contributor>Eryx Paredes &lt;eryxp@lyft.com&gt;</dc:contributor>
        <dc:contributor>Max R.D. Parmer &lt;maxp@trystero.is&gt;</dc:contributor>
        <dc:contributor>Arnaud Patard &lt;apatard@hupstream.com&gt;</dc:contributor>
        <dc:contributor>Jan Pazdziora &lt;jpazdziora@redhat.com&gt;</dc:contributor>
        <dc:contributor>pcactr &lt;paul.c.arnold4.ctr@mail.mil&gt;</dc:contributor>
        <dc:contributor>Kenneth Peeples &lt;kennethwpeeples@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nathan Peters &lt;Nathaniel.Peters@ca.com&gt;</dc:contributor>
        <dc:contributor>Frank Lin PIAT &lt;fpiat@klabs.be&gt;</dc:contributor>
        <dc:contributor>Stefan Pietsch &lt;mail.ipv4v6+gh@gmail.com&gt;</dc:contributor>
        <dc:contributor>piggyvenus &lt;piggyvenus@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vojtech Polasek &lt;vpolasek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Orion Poplawski &lt;orion@nwra.com&gt;</dc:contributor>
        <dc:contributor>Jennifer Power &lt;barnabei.jennifer@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nick Poyant &lt;npoyant@redhat.com&gt;</dc:contributor>
        <dc:contributor>Martin Preisler &lt;mpreisle@redhat.com&gt;</dc:contributor>
        <dc:contributor>Wesley Ceraso Prudencio &lt;wcerasop@redhat.com&gt;</dc:contributor>
        <dc:contributor>Raphael Sanchez Prudencio &lt;rsprudencio@redhat.com&gt;</dc:contributor>
        <dc:contributor>Miha Purg &lt;miha.purg@canonical.com&gt;</dc:contributor>
        <dc:contributor>T.O. Radzy Radzykewycz &lt;radzy@windriver.com&gt;</dc:contributor>
        <dc:contributor>rain-Qing &lt;yangyuqing6@qq.com&gt;</dc:contributor>
        <dc:contributor>Kenyon Ralph &lt;kenyon@kenyonralph.com&gt;</dc:contributor>
        <dc:contributor>Mike Ralph &lt;mralph@redhat.com&gt;</dc:contributor>
        <dc:contributor>Federico Ramirez &lt;federico.r.ramirez@oracle.com&gt;</dc:contributor>
        <dc:contributor>rchikov &lt;rumen.chikov@suse.com&gt;</dc:contributor>
        <dc:contributor>Rick Renshaw &lt;Richard_Renshaw@xtoenergy.com&gt;</dc:contributor>
        <dc:contributor>Paul Rensing &lt;prensing@cimetrics.com&gt;</dc:contributor>
        <dc:contributor>Chris Reynolds &lt;c.reynolds82@gmail.com&gt;</dc:contributor>
        <dc:contributor>rhayes &lt;rhayes@rivierautilities.com&gt;</dc:contributor>
        <dc:contributor>Pat Riehecky &lt;riehecky@fnal.gov&gt;</dc:contributor>
        <dc:contributor>rlucente-se-jboss &lt;rlucente@redhat.com&gt;</dc:contributor>
        <dc:contributor>Juan Antonio Osorio Robles &lt;juan.osoriorobles@eu.equinix.com&gt;</dc:contributor>
        <dc:contributor>Paul Roche &lt;paul.roche@menlosecurity.com&gt;</dc:contributor>
        <dc:contributor>Jan Rodak &lt;hony.com@seznam.cz&gt;</dc:contributor>
        <dc:contributor>Matt Rogers &lt;mrogers@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jesse Roland &lt;jesse.roland@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>Joshua Roys &lt;roysjosh@gmail.com&gt;</dc:contributor>
        <dc:contributor>rrenshaw &lt;bofh69@yahoo.com&gt;</dc:contributor>
        <dc:contributor>Daniel Ruf &lt;daniel@daniel-ruf.de&gt;</dc:contributor>
        <dc:contributor>Chris Ruffalo &lt;chris.ruffalo@gmail.com&gt;</dc:contributor>
        <dc:contributor>Benjamin Ruland &lt;benjamin.ruland@gmail.com&gt;</dc:contributor>
        <dc:contributor>rumch-se &lt;77793453+rumch-se@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Rutvik &lt;rutksh@gmail.com&gt;</dc:contributor>
        <dc:contributor>Ray Shaw (Cont ARL/CISD) rvshaw &lt;rvshaw@esme.arl.army.mil&gt;</dc:contributor>
        <dc:contributor>Nicolas SAID &lt;nicolas.said@atos.net&gt;</dc:contributor>
        <dc:contributor>Earl Sampson &lt;ESampson@suse.com&gt;</dc:contributor>
        <dc:contributor>sampsone &lt;esampson@suse.com&gt;</dc:contributor>
        <dc:contributor>Mirco Santori &lt;mirco.santori@roche.com&gt;</dc:contributor>
        <dc:contributor>Willy Santos &lt;wsantos@redhat.com&gt;</dc:contributor>
        <dc:contributor>Nagarjuna Sarvepalli &lt;snagarju@redhat.com&gt;</dc:contributor>
        <dc:contributor>Anderson Sasaki &lt;33833274+ansasaki@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gautam Satish &lt;gautams@hpe.com&gt;</dc:contributor>
        <dc:contributor>Watson Sato &lt;wsato@redhat.com&gt;</dc:contributor>
        <dc:contributor>Satoru SATOH &lt;satoru.satoh@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alexander Scheel &lt;alexander.m.scheel@gmail.com&gt;</dc:contributor>
        <dc:contributor>Bryan Schneiders &lt;pschneiders@trisept.com&gt;</dc:contributor>
        <dc:contributor>Robert Schweikert &lt;rjschwei@suse.com&gt;</dc:contributor>
        <dc:contributor>shaneboulden &lt;shane.boulden@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vincent Shen &lt;wenshen@redhat.com&gt;</dc:contributor>
        <dc:contributor>Dhriti Shikhar &lt;dhriti.shikhar.rokz@gmail.com&gt;</dc:contributor>
        <dc:contributor>Spencer Shimko &lt;sshimko@tresys.com&gt;</dc:contributor>
        <dc:contributor>Mark Shoger &lt;mshoger@redhat.com&gt;</dc:contributor>
        <dc:contributor>Shane Siebken &lt;shane.siebken@capellaspace.com&gt;</dc:contributor>
        <dc:contributor>THOBY Simon &lt;Simon.THOBY@viveris.fr&gt;</dc:contributor>
        <dc:contributor>Thomas Sjögren &lt;konstruktoid@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Jindrich Skacel &lt;102800748+jskacel@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Alexandre Skrzyniarz &lt;alexandre.skrzyniarz@laposte.net&gt;</dc:contributor>
        <dc:contributor>Francisco Slavin &lt;fslavin@tresys.com&gt;</dc:contributor>
        <dc:contributor>sluetze &lt;13255307+sluetze@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Dave Smith &lt;dsmith@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>David Smith &lt;dsmith@fornax.eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Kevin Spargur &lt;kspargur@redhat.com&gt;</dc:contributor>
        <dc:contributor>Kenneth Stailey &lt;kstailey.lists@gmail.com&gt;</dc:contributor>
        <dc:contributor>Leland Steinke &lt;leland.j.steinke.ctr@mail.mil&gt;</dc:contributor>
        <dc:contributor>Justin Stephenson &lt;jstephen@redhat.com&gt;</dc:contributor>
        <dc:contributor>steven.y.gui &lt;steven_ygui@163.com&gt;</dc:contributor>
        <dc:contributor>Brian Stinson &lt;brian@bstinson.com&gt;</dc:contributor>
        <dc:contributor>Jake Stookey &lt;jakestookey@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nathan Strahs &lt;135379779+nathanstrahs@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Jonathan Sturges &lt;jsturges@redhat.com&gt;</dc:contributor>
        <dc:contributor>svet-se &lt;svetlin.boychev@suse.com&gt;</dc:contributor>
        <dc:contributor>taimurhafeez &lt;taimurhafeez93@gmail.com&gt;</dc:contributor>
        <dc:contributor>Kaushik Talathi &lt;kaushik.talathi1@ibm.com&gt;</dc:contributor>
        <dc:contributor>teacup-on-rockingchair &lt;315160+teacup-on-rockingchair@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Ian Tewksbury &lt;itewk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Philippe Thierry &lt;phil@reseau-libre.net&gt;</dc:contributor>
        <dc:contributor>Simon THOBY &lt;git@nightmared.fr&gt;</dc:contributor>
        <dc:contributor>Derek Thurston &lt;thegrit@gmail.com&gt;</dc:contributor>
        <dc:contributor>tianzhenjia &lt;jiatianzhen@cmss.chinamobile.com&gt;</dc:contributor>
        <dc:contributor>Greg Tinsley &lt;gtinsley@redhat.com&gt;</dc:contributor>
        <dc:contributor>Paul Tittle &lt;ptittle@cmf.nrl.navy.mil&gt;</dc:contributor>
        <dc:contributor>tom &lt;tom@localhost.localdomain&gt;</dc:contributor>
        <dc:contributor>tomas.hudik &lt;tomas.hudik@embedit.cz&gt;</dc:contributor>
        <dc:contributor>Jeb Trayer &lt;jeb.d.trayer@uscg.mil&gt;</dc:contributor>
        <dc:contributor>TrilokGeer &lt;tgeer@redhat.com&gt;</dc:contributor>
        <dc:contributor>Viktors Trubovics &lt;viktors.trubovics@suse.com&gt;</dc:contributor>
        <dc:contributor>Nico Truzzolino &lt;nico.truzzolino@gmx.de&gt;</dc:contributor>
        <dc:contributor>Brian Turek &lt;brian.turek@gmail.com&gt;</dc:contributor>
        <dc:contributor>Matěj Týč &lt;matyc@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jörgen Uhr &lt;jorgen.uhr@sitevision.se&gt;</dc:contributor>
        <dc:contributor>VadimDor &lt;29509093+VadimDor@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Trevor Vaughan &lt;tvaughan@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>vtrubovics &lt;82443408+vtrubovics@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sophia Wang &lt;huiwang@redhat.com&gt;</dc:contributor>
        <dc:contributor>Samuel Warren &lt;swarren@redhat.com&gt;</dc:contributor>
        <dc:contributor>wcushen &lt;54533890+wcushen@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Shawn Wells &lt;shawn@redhat.com&gt;</dc:contributor>
        <dc:contributor>Whidix &lt;31294015+Whidix@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Daniel E. White &lt;linuxdan@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Bernhard M. Wiedemann &lt;bwiedemann@suse.de&gt;</dc:contributor>
        <dc:contributor>Roy Williams &lt;roywilli@roywilli.redhat.com&gt;</dc:contributor>
        <dc:contributor>Willumpie &lt;willumpie@xs4all.nl&gt;</dc:contributor>
        <dc:contributor>Rob Wilmoth &lt;rwilmoth@redhat.com&gt;</dc:contributor>
        <dc:contributor>win97pro &lt;win97pro@protonmail.com&gt;</dc:contributor>
        <dc:contributor>xcfxr &lt;xucee@qq.com&gt;</dc:contributor>
        <dc:contributor>Lucas Yamanishi &lt;lucas.yamanishi@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>Xirui Yang &lt;xirui.yang@oracle.com&gt;</dc:contributor>
        <dc:contributor>Yuqing Yang &lt;yyq01323329@alibaba-inc.com&gt;</dc:contributor>
        <dc:contributor>yarunachalam &lt;yarunachalam@suse.com&gt;</dc:contributor>
        <dc:contributor>Guang Yee &lt;guang.yee@suse.com&gt;</dc:contributor>
        <dc:contributor>Achilleas John Yfantis &lt;ayfantis@redhat.com&gt;</dc:contributor>
        <dc:contributor>YiLin.Li &lt;YiLin.Li@linux.alibaba.com&gt;</dc:contributor>
        <dc:contributor>yu410621 &lt;lihuanyu410621@gmail.com&gt;</dc:contributor>
        <dc:contributor>Xiaojie Yuan &lt;xiyuan@redhat.com&gt;</dc:contributor>
        <dc:contributor>yungcero &lt;133906218+yungcero@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>yunimoo &lt;yunimoo@nekocake.cafe&gt;</dc:contributor>
        <dc:contributor>YuQing &lt;yyq0391@163.com&gt;</dc:contributor>
        <dc:contributor>zhaoyun &lt;zhaoyun@kylinos.cn&gt;</dc:contributor>
        <dc:contributor>Kevin Zimmerman &lt;kevin.zimmerman@kitware.com&gt;</dc:contributor>
        <dc:contributor>Luigi Mario Zuccarelli &lt;luzuccar@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jan Černý &lt;jcerny@redhat.com&gt;</dc:contributor>
        <dc:contributor>Michal Šrubař &lt;msrubar@redhat.com&gt;</dc:contributor>
        <dc:source>https://github.com/ComplianceAsCode/content/releases/latest</dc:source>
      </xccdf-1.2:metadata>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cusp_firefox">
        <xccdf-1.2:title override="true">CUSP - Common User Security Profile for Mozilla Firefox</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains rules to harden Mozilla Firefox according to rule 6.1 in the Common User Security Guide for Fedora Workstation.</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-autoplay_video" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-content_blocker" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-cryptomining" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-enhanced_tracking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-fingerprinting_protection" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_changes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_resizing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-pop-up_windows" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-ssl_minimum_version" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firefox_preferences-dod_root_certificate" selected="false"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_stig">
        <xccdf-1.2:version>V6R3</xccdf-1.2:version>
        <xccdf-1.2:title override="true">Mozilla Firefox STIG</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile is developed under the DoD consensus model and DISA FSO Vendor STIG process,
serving as the upstream development environment for the Firefox STIG.

As a result of the upstream/downstream relationship between the SCAP Security Guide project
and the official DISA FSO STIG baseline, users should expect variance between SSG and DISA FSO content.
For official DISA FSO STIG content, refer to https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security%2Cbrowser-guidance.

While this profile is packaged by Red Hat as part of the SCAP Security Guide package, please note
that commercial support of this SCAP content is NOT available. This profile is provided as example
SCAP content with no endorsement for suitability or production readiness. Support for this
profile is provided by the upstream SCAP Security Guide community on a best-effort basis. The
upstream project homepage is https://www.open-scap.org/security-policies/scap-security-guide/.</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-addons_permission" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-autoplay_video" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-cryptomining" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-development_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-disable_deprecated_ciphers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-disable_form_history" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-disable_pocket" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-disable_studies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-dns_over_https" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-encrypted_media_extensions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-enhanced_tracking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-extension_recommendation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-extension_update" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-feedback_reporting" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-fingerprinting_protection" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-forget_button" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_changes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_resizing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-network_prediction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-no_sanitize_on_shutdown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-nonessential_capabilities" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-password_manager" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-pop-up_windows" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-private_browsing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-search_suggestion" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-search_update" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-ssl_minimum_version" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-sync" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-telemetry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-user_messaging" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_policy-verification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_preferences-auto-download_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firefox_preferences-dod_root_certificate_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_installed_firefox_version_supported" selected="true"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_default_home_page" selector="about_blank"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_firefox">
        <xccdf-1.2:title>Firefox</xccdf-1.2:title>
        <xccdf-1.2:description>Firefox is an open-source web browser and developed by Mozilla.
Web browsers such as Firefox are used for a number of reasons. This section
provides settings for configuring Firefox policies to meet compliance
settings for Firefox running on Red Hat Enterprise Linux systems.

<html:ul>Refer to <html:li><html:a href="http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries">http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries</html:a></html:li>
for a list of currently supported Firefox settings.</html:ul></xccdf-1.2:description>
        <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_default_home_page" type="string">
          <xccdf-1.2:title>The Default Firefox Home Page</xccdf-1.2:title>
          <xccdf-1.2:description>The default home page for Firefox users.</xccdf-1.2:description>
          <xccdf-1.2:value selector="about_blank">about:blank</xccdf-1.2:value>
          <xccdf-1.2:value>None</xccdf-1.2:value>
        </xccdf-1.2:Value>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-addons_permission" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to disable the installation of extensions.</xccdf-1.2:title>
          <xccdf-1.2:description>Addon installation may be disabled in an administrative policy by setting
the <html:code>InstallAddonsPermission</html:code> key under <html:code>policies</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000013</xccdf-1.2:reference>
          <xccdf-1.2:rationale>A browser extension is a program that has been installed into the browser to add functionality. Where a plug-in interacts only with a web page and usually a third-party external application (e.g., Flash, Adobe Reader), an extension interacts with the browser program itself. Extensions are not embedded in web pages and must be downloaded and installed in order to work. Extensions allow browsers to avoid restrictions that apply to web pages.
For example, an extension can be written to combine data from multiple domains and present it when a certain page is accessed, which can be considered cross-site scripting. If a browser is configured to allow unrestricted use of extensions, plug-ins can be loaded and installed from malicious sources and used on the browser.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-addons_permission" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'InstallAddonsPermission' in _tree['policies']:
   pass
else:
   _tree['policies']['InstallAddonsPermission'] = dict()

_tree['policies']['InstallAddonsPermission']['Default'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-addons_permission:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-autoplay_video" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox autoplay must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Audio/Video autoplay may be disabled in an administrative policy by setting
the <html:code>Default</html:code> key under <html:code>Permissions</html:code>, <html:code>Autoplay</html:code> to <html:code>"block-audio-video"</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000021</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Autoplay allows the user to control whether videos can play automatically (without user consent) with audio content. The user must be able to select content that is run within the browser window.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-autoplay_video" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Permissions' in _tree['policies']:
   pass
else:
   _tree['policies']['Permissions'] = dict()

if 'Autoplay' in _tree['policies']['Permissions']:
   pass
else:
   _tree['policies']['Permissions']['Autoplay'] = dict()

_tree['policies']['Permissions']['Autoplay']['Default'] = 'block-audio-video'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-autoplay_video:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-content_blocker" selected="false" severity="medium">
          <xccdf-1.2:title>Ensure the Content Blocker uBlock Origin is Installed</xccdf-1.2:title>
          <xccdf-1.2:description>The uBlock Origin will be installed automatically by configuring Firefox policy, and updates will be enabled. It can also be installed through the Mozilla Add-Ons store at https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/.</xccdf-1.2:description>
          <xccdf-1.2:rationale>The content blocking feature of uBlock Origin stops Firefox from loading content from malicious sites. The content might be a script or an image, for example. If a site is on one of the lists uBlock Origin uses, then the content will not be loaded from that site.
This may prevent malicious ads from confusing users and concealing the page contents, as well as the loading of content that may contain malware.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-content_blocker" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'ExtensionSettings' in _tree['policies']:
   pass
else:
   _tree['policies']['ExtensionSettings'] = dict()

if 'uBlock0@raymondhill.net' in _tree['policies']['ExtensionSettings']:
   pass
else:
   _tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net'] = dict()

_tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net']['installation_mode'] = 'normal_installed'


if 'ExtensionSettings' in _tree['policies']:
   pass
else:
   _tree['policies']['ExtensionSettings'] = dict()

if 'uBlock0@raymondhill.net' in _tree['policies']['ExtensionSettings']:
   pass
else:
   _tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net'] = dict()

_tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net']['install_url'] = 'https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi'


if 'ExtensionSettings' in _tree['policies']:
   pass
else:
   _tree['policies']['ExtensionSettings'] = dict()

if 'uBlock0@raymondhill.net' in _tree['policies']['ExtensionSettings']:
   pass
else:
   _tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net'] = dict()

_tree['policies']['ExtensionSettings']['uBlock0@raymondhill.net']['updates_disabled'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-content_blocker:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-cryptomining" selected="false" severity="medium">
          <xccdf-1.2:title>Enabled Firefox Cryptomining protection</xccdf-1.2:title>
          <xccdf-1.2:description>Cryptomining protection may be enabled by setting
<html:code>privacy.trackingprotection.cryptomining.enabled</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000024</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The Content Blocking/Tracking Protection feature stops Firefox from loading content from malicious sites. The content might be a script or an image, for example. If a site is on one of the tracker lists you set Firefox to use, then the fingerprinting script (or other tracking script/image) will not be loaded from that site.
Cryptomining scripts use your computer’s central processing unit (CPU) to invisibly mine cryptocurrency.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-cryptomining" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'EnableTrackingProtection' in _tree['policies']:
   pass
else:
   _tree['policies']['EnableTrackingProtection'] = dict()

_tree['policies']['EnableTrackingProtection']['Cryptomining'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-cryptomining:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-development_tools" selected="false" severity="low">
          <xccdf-1.2:title>Disable Firefox Development Tools</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox provides development tools which identify detailed information 
about the browser and its configuration. These details are often also 
recorded into a log file, giving an attacker the ability to capture 
detailed information about the system.
This can be disabled by setting <html:code>DisableDeveloperTools</html:code> to
<html:code>true</html:code> in <html:code>policies.json</html:code></xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-11 b</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000015</xccdf-1.2:reference>
          <xccdf-1.2:rationale>In order to protect privacy and sensitive data, Mozilla provides
the ability to configure Firefox so that development tools are prevented from being used.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-development_tools" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableDeveloperTools'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-development_tools:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-disable_deprecated_ciphers" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Firefox deprecated ciphers</xccdf-1.2:title>
          <xccdf-1.2:description>Pocket may be disabled by setting
<html:code>TLS_RSA_WITH_3DES_EDE_CBC_SHA</html:code> to <html:code>true</html:code> under <html:code>DisabledCiphers</html:code>
in the policies file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000027</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Weak ciphers are encryption/decryption algorithms that use keys of insufficient length. Using an insufficient length for a key increases
the probability that the encryption scheme could be broken.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-disable_deprecated_ciphers" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'DisabledCiphers' in _tree['policies']:
   pass
else:
   _tree['policies']['DisabledCiphers'] = dict()

_tree['policies']['DisabledCiphers']['TLS_RSA_WITH_3DES_EDE_CBC_SHA'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-disable_deprecated_ciphers:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-disable_form_history" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to disable form fill assistance.</xccdf-1.2:title>
          <xccdf-1.2:description>The update check may be disabled in an administrative policy by setting
the <html:code>DisableFormHistory</html:code> key under <html:code>policies</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000007</xccdf-1.2:reference>
          <xccdf-1.2:rationale>To protect privacy and sensitive data, Firefox provides the ability to configure the program so that data entered into forms is not saved. This mitigates the risk of a website gleaning private information from prefilled information.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-disable_form_history" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableFormHistory'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-disable_form_history:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-disable_pocket" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Firefox Pocket</xccdf-1.2:title>
          <xccdf-1.2:description>Pocket may be disabled by setting
<html:code>DisablePocket</html:code> to <html:code>true</html:code>
in the policies file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000038</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Pocket is a social bookmarking service for storing, sharing, and discovering web bookmarks.
Data gathering cloud services such as Pocket are generally disabled in some organizations such as the DoD.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-disable_pocket" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisablePocket'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-disable_pocket:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-disable_studies" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Firefox Studies</xccdf-1.2:title>
          <xccdf-1.2:description>Pocket may be disabled by setting
<html:code>DisableFirefoxStudies</html:code> to <html:code>true</html:code>
in the policies file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000039</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Studies try out different features and ideas prior to release to all Firefox users. Testing beta software is not in the profile user's mission.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-disable_studies" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableFirefoxStudies'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-disable_studies:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-dns_over_https" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured so that DNS over HTTPS is disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>DNS over HTTPS feature may be disabled via administrative policy by setting
<html:code>Enabled</html:code> under <html:code>DNSOverHTTPS</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000033</xccdf-1.2:reference>
          <xccdf-1.2:rationale>DNS over HTTPS has generally not been adopted in the DoD. DNS is tightly controlled.
It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors.
Applications are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions).
Examples of non-essential capabilities include but are not limited to advertising software or browser plug-ins that are not related to requirements or provide a wide array of functionality not required for every mission but that cannot be disabled.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-dns_over_https" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'DNSOverHTTPS' in _tree['policies']:
   pass
else:
   _tree['policies']['DNSOverHTTPS'] = dict()

_tree['policies']['DNSOverHTTPS']['Enabled'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-dns_over_https:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-encrypted_media_extensions" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox encrypted media extensions must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox's Encrypted Media Extensions support playback of media content that is subject to Digital Right Management.
These extensions may be disabled completely by setting
<html:ul><html:li><html:code>Enabled</html:code> under <html:code>EncryptedMediaExtensions</html:code> to <html:code>false</html:code></html:li><html:li><html:code>Locked</html:code> under <html:code>EncryptedMediaExtensions</html:code> to <html:code>true</html:code></html:li></html:ul>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000037</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Enable or disable Encrypted Media Extensions and optionally lock it.
If "Enabled" is set to "false", Firefox does not download encrypted media extensions (such as Widevine) unless the user consents to installing them.
If "Locked" is set to "true" and "Enabled" is set to "false", Firefox will not download encrypted media extensions (such as Widevine) or ask the user to install them.
It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors.
Applications are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions).
Examples of non-essential capabilities include but are not limited to advertising software or browser plug-ins that are not related to requirements or provide a wide array of functionality not required for every mission but that cannot be disabled.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-encrypted_media_extensions" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'EncryptedMediaExtensions' in _tree['policies']:
   pass
else:
   _tree['policies']['EncryptedMediaExtensions'] = dict()

_tree['policies']['EncryptedMediaExtensions']['Enabled'] = False


if 'EncryptedMediaExtensions' in _tree['policies']:
   pass
else:
   _tree['policies']['EncryptedMediaExtensions'] = dict()

_tree['policies']['EncryptedMediaExtensions']['Locked'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-encrypted_media_extensions:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-enhanced_tracking" selected="false" severity="medium">
          <xccdf-1.2:title>Enabled Firefox Enhanced Tracking Protection</xccdf-1.2:title>
          <xccdf-1.2:description>Enhanced Tracking Protection may be enabled by setting
<html:code>browser.contentblocking.category</html:code> to <html:code>strict</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000025</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Tracking generally refers to content, cookies, or scripts that can collect your browsing data across multiple sites.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-enhanced_tracking" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'browser.contentblocking.category' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['browser.contentblocking.category'] = dict()

_tree['policies']['Preferences']['browser.contentblocking.category']['Value'] = 'strict'


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'browser.contentblocking.category' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['browser.contentblocking.category'] = dict()

_tree['policies']['Preferences']['browser.contentblocking.category']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-enhanced_tracking:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-extension_recommendation" selected="false" severity="medium">
          <xccdf-1.2:title>Disabled Firefox Extension Recommendations</xccdf-1.2:title>
          <xccdf-1.2:description>Extension recommendations may be disabled by setting
<html:code>extensions.htmlaboutaddons.recommendations.enabled</html:code> to <html:code>false</html:code> in the policy file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000026</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The Recommended Extensions program will make it easier for users to discover extensions that have been reviewed for security, functionality, and user experience.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-extension_recommendation" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'extensions.htmlaboutaddons.recommendations.enabled' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['extensions.htmlaboutaddons.recommendations.enabled'] = dict()

_tree['policies']['Preferences']['extensions.htmlaboutaddons.recommendations.enabled']['Value'] = False


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'extensions.htmlaboutaddons.recommendations.enabled' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['extensions.htmlaboutaddons.recommendations.enabled'] = dict()

_tree['policies']['Preferences']['extensions.htmlaboutaddons.recommendations.enabled']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-extension_recommendation:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-extension_update" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to not automatically update installed add-ons and plugins.</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox has a feature to permit installed add-ons and plugins to automatically update. The check may be disabled in an
administrative policy by setting the <html:code>ExtensionUpdate</html:code> key under <html:code>policies</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000005</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Automatic updates from untrusted sites puts the entire enclave at risk and may override existing security settings.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-extension_update" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['ExtensionUpdate'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-extension_update:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-feedback_reporting" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox feedback reporting must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Feedback reporting feature may be disabled via administrative policy by setting
<html:code>DisableFeedbackCommands</html:code> under <html:code>policies</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000036</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Disable the menus for reporting sites (Submit Feedback, Report Deceptive Site). 
It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors.
Applications are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions).
Examples of non-essential capabilities include but are not limited to advertising software or browser plug-ins that are not related to requirements or provide a wide array of functionality not required for every mission but that cannot be disabled.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-feedback_reporting" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableFeedbackCommands'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-feedback_reporting:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-fingerprinting_protection" selected="false" severity="medium">
          <xccdf-1.2:title>Enabled Firefox Fingerprinting Protection</xccdf-1.2:title>
          <xccdf-1.2:description>Fingerprinting protection may be enabled by setting
<html:code>Fingerprinting</html:code> to <html:code>true</html:code> under <html:code>EnableTrackingProtection</html:code>
in the policies file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000023</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The Content Blocking/Tracking Protection feature stops Firefox from loading content from malicious sites. The content might be a script or an image, for example. If a site is on one of the tracker lists you set Firefox to use, then the fingerprinting script (or other tracking script/image) will not be loaded from that site.
Fingerprinting scripts collect information about your browser and device configuration, such as your operating system, screen resolution, and other settings. By compiling these pieces of data, fingerprinters create a unique profile of you that can be used to track you around the Web.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-fingerprinting_protection" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'EnableTrackingProtection' in _tree['policies']:
   pass
else:
   _tree['policies']['EnableTrackingProtection'] = dict()

_tree['policies']['EnableTrackingProtection']['Fingerprinting'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-fingerprinting_protection:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-forget_button" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must prevent the user from quickly deleting data.</xccdf-1.2:title>
          <xccdf-1.2:description>The update check may be disabled in an administrative policy by setting
the <html:code>DisableForgetButton</html:code> key under <html:code>policies</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-24(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000018</xccdf-1.2:reference>
          <xccdf-1.2:rationale>There should not be an option for a user to "forget" work they have done. This is required to meet non-repudiation controls.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-forget_button" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableForgetButton'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-forget_button:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_changes" selected="false" severity="medium">
          <xccdf-1.2:title>Disable JavaScript's Raise Or Lower Windows Capability</xccdf-1.2:title>
          <xccdf-1.2:description>JavaScript can configure and make changes to the web browser's appearance by
specifically raising and lowering windows. This can be disabled by
setting <html:code>dom.disable_window_flip</html:code> to <html:code>true</html:code> in the policy file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000011</xccdf-1.2:reference>
          <xccdf-1.2:rationale>JavaScript can make changes to the browser’s appearance. Allowing a website
to use JavaScript to raise and lower browser windows may disguise an attack.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-javascript_window_changes" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'dom.disable_window_flip' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['dom.disable_window_flip'] = dict()

_tree['policies']['Preferences']['dom.disable_window_flip']['Value'] = True


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'dom.disable_window_flip' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['dom.disable_window_flip'] = dict()

_tree['policies']['Preferences']['dom.disable_window_flip']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-javascript_window_changes:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-javascript_window_resizing" selected="false" severity="medium">
          <xccdf-1.2:title>Disable JavaScript's Moving Or Resizing Windows Capability</xccdf-1.2:title>
          <xccdf-1.2:description>JavaScript can configure and make changes to the web browser's appearance by
specifically moving and resizing browser windows. This can be disabled by
setting <html:code>dom.disable_window_move_resize</html:code> to <html:code>true</html:code> in the policy file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000010</xccdf-1.2:reference>
          <xccdf-1.2:rationale>JavaScript can make changes to the browser’s appearance. This activity
can help disguise an attack taking place in a minimized background window.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-javascript_window_resizing" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'dom.disable_window_move_resize' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['dom.disable_window_move_resize'] = dict()

_tree['policies']['Preferences']['dom.disable_window_move_resize']['Value'] = True


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'dom.disable_window_move_resize' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['dom.disable_window_move_resize'] = dict()

_tree['policies']['Preferences']['dom.disable_window_move_resize']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-javascript_window_resizing:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-network_prediction" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Firefox network prediction</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox has a feature where it predicts and caches DNS requests.
This can be disabled by
setting <html:code>NetworkPrediction</html:code> to <html:code>true</html:code> in the policy file.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000022</xccdf-1.2:reference>
          <xccdf-1.2:rationale>With network prediction enabled, URL requests are made without user consent.
Browsers should always make a direct DNS request with prefetching. </xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-network_prediction" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['NetworkPrediction'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-network_prediction:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-no_sanitize_on_shutdown" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to not delete data upon shutdown.</xccdf-1.2:title>
          <xccdf-1.2:description>The default certificate to present may be configured by setting multiple options
under <html:code>SanitizeOnShutdown</html:code> key.
<html:ul><html:li><html:code>Cache</html:code> = <html:code>false</html:code></html:li></html:ul></xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7 a</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000017</xccdf-1.2:reference>
          <xccdf-1.2:rationale>For diagnostic purposes, data must remain behind when the browser is closed. This is required to meet non-repudiation controls.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-no_sanitize_on_shutdown" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['Cache'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['Cookies'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['Downloads'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['FormData'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['History'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['Sessions'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['SiteSettings'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['OfflineApps'] = False


if 'SanitizeOnShutdown' in _tree['policies']:
   pass
else:
   _tree['policies']['SanitizeOnShutdown'] = dict()

_tree['policies']['SanitizeOnShutdown']['Locked'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-no_sanitize_on_shutdown:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-nonessential_capabilities" selected="false" severity="medium">
          <xccdf-1.2:title>The Firefox New Tab page must not show Top Sites, Sponsored Top sites, Pocket Recommendations, Sponsored Pocket Stories, Searches, Highlights, or Snippets.</xccdf-1.2:title>
          <xccdf-1.2:description>Display of top sites may be disabled in an administrative policy by setting the following items under <html:code>FirefoxHome</html:code>
to <html:code>false</html:code> and by setting the <html:code>locked</html:code> key to <html:code>true</html:code>.
<html:code>Search</html:code>
<html:code>TopSites</html:code>
<html:code>SponsoredTopSites</html:code>
<html:code>Pocket</html:code>
<html:code>SponsoredPocket</html:code>
<html:code>Highlights</html:code>
<html:code>Snippets</html:code></xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000029</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The New Tab page by default shows a list of built-in top sites, as well as the top sites the user has visited.
It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors.
Applications are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions).
Examples of non-essential capabilities include but are not limited to advertising software or browser plug-ins that are not related to requirements or provide a wide array of functionality not required for every mission but that cannot be disabled.
The new tab page must not actively show user activity.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-nonessential_capabilities" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['Search'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['TopSites'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['SponsoredTopSites'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['Pocket'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['SponsoredPocket'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['Highlights'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['Snippets'] = False


if 'FirefoxHome' in _tree['policies']:
   pass
else:
   _tree['policies']['FirefoxHome'] = dict()

_tree['policies']['FirefoxHome']['locked'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-nonessential_capabilities:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-password_manager" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to not use a password store with or without a master password.</xccdf-1.2:title>
          <xccdf-1.2:description>The update check may be disabled in an administrative policy by setting
the <html:code>PasswordManager</html:code> key under <html:code>policies</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000008</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Firefox can be set to store passwords for sites visited by the user. These individual passwords are stored in a file and can be protected by a master password. Autofill of the password can then be enabled when the site is visited. This feature could also be used to autofill the certificate PIN, which could lead to compromise of information.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-password_manager" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['PasswordManagerEnabled'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-password_manager:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-pop-up_windows" selected="false" severity="medium">
          <xccdf-1.2:title>Enable Firefox Pop-up Blocker</xccdf-1.2:title>
          <xccdf-1.2:description>The pop-up blocker can be enabled by setting
<html:code>Default</html:code> key under <html:code>PopupBlocking</html:code> to <html:code>true</html:code> in <html:code>policies.json</html:code>.
<html:code>Allowed</html:code> may be set to a list of sites allowed to use popups. </xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000009</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Popup windows may be used to launch an attack within a new browser window
with altered settings.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-pop-up_windows" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'PopupBlocking' in _tree['policies']:
   pass
else:
   _tree['policies']['PopupBlocking'] = dict()

_tree['policies']['PopupBlocking']['Default'] = True


if 'PopupBlocking' in _tree['policies']:
   pass
else:
   _tree['policies']['PopupBlocking'] = dict()

_tree['policies']['PopupBlocking']['Locked'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-pop-up_windows:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-private_browsing" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox private browsing must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Private browsing may be disabled in an administrative policy by setting
the <html:code>DisablePrivateBrowsing</html:code> key under <html:code>policies</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000019</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Private browsing allows the user to browse the internet without recording their browsing history/activity. From a forensics perspective, this is unacceptable. Best practice requires that browser history is retained.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-private_browsing" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisablePrivateBrowsing'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-private_browsing:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-search_suggestion" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox search suggestions must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Search Suggestions may be disabled in an administrative policy by setting
the <html:code>SearchSuggestEnabled</html:code> key under <html:code>policies</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000020</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Search suggestions must be disabled as this could lead to searches being conducted that were never intended to be made.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-search_suggestion" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['SearchSuggestEnabled'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-search_suggestion:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-search_update" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Installed Search Plugins Update Checking</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox automatically checks for updated versions of search plugins.
To disable the automatic updates of plugins, set value of
<html:code>browser.search.update</html:code> to <html:code>false</html:code> via policies.json.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000004</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Updates need to be controlled and installed from authorized and trusted servers.
This setting overrides a number of other settings which may direct the application
to access external URLs.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-search_update" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'browser.search.update' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['browser.search.update'] = dict()

_tree['policies']['Preferences']['browser.search.update']['Value'] = False


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'browser.search.update' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['browser.search.update'] = dict()

_tree['policies']['Preferences']['browser.search.update']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-search_update:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-ssl_minimum_version" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must be configured to allow only TLS 1.2 or above.</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox may be configured via administrative policy to allow TLS 1.2 at minimum
by setting <html:code>SSLVersionMin</html:code> to <html:code>tls1.2</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17 (2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000002</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Use of versions prior to TLS 1.2 are not permitted. SSL 2.0 and SSL 3.0 contain a number of security flaws. 
These versions must be disabled in compliance with the Network Infrastructure and Secure Remote Computing STIGs.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-ssl_minimum_version" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['SSLVersionMin'] = 'tls1.2'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-ssl_minimum_version:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-sync" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox accounts must be disabled.</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox accounts feature may be disabled via administrative policy by setting
<html:code>DisableFirefoxAccounts</html:code> under <html:code>policies</html:code> to <html:code>true</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000034</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Disable Firefox Accounts integration (Sync). 
It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors.
Applications are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions).
Examples of non-essential capabilities include but are not limited to advertising software or browser plug-ins that are not related to requirements or provide a wide array of functionality not required for every mission but that cannot be disabled.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-sync" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableFirefoxAccounts'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-sync:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-telemetry" selected="false" severity="medium">
          <xccdf-1.2:title>Disable Firefox Telemetry</xccdf-1.2:title>
          <xccdf-1.2:description>Telemetry can be disabled by setting
<html:code>toolkit.telemetry.enabled</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000014</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The Telemetry feature provides this capability by sending performance and usage info to Mozilla. As you use Firefox, Telemetry measures and collects non-personal information, such as performance, hardware, usage and customizations. It then sends this information to Mozilla on a daily basis and we use it to improve Firefox</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-telemetry" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


_tree['policies']['DisableTelemetry'] = True

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-telemetry:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-user_messaging" selected="false" severity="medium">
          <xccdf-1.2:title>Firefox must not recommend extensions as the user is using the browser.</xccdf-1.2:title>
          <xccdf-1.2:description>The extension recommendation messages may be disabled in an administrative policy by setting
the <html:code>ExtensionRecommendations</html:code> key under <html:code>UserMessaging</html:code> to <html:code>false</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000028</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The Recommended Extensions program recommends extensions to users as they surf the web.
The user must not be encouraged to install extensions from the websites they visit. Allowed extensions are to be centrally managed.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-user_messaging" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'UserMessaging' in _tree['policies']:
   pass
else:
   _tree['policies']['UserMessaging'] = dict()

_tree['policies']['UserMessaging']['ExtensionRecommendations'] = False

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-user_messaging:def:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_policy-verification" selected="false" severity="medium">
          <xccdf-1.2:title>Enable Certificate Verification</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox can be configured to prompt the user to choose a certificate
to present to a website when asked. To enable certificate verification,
set <html:code>security.default_personal_cert</html:code> to <html:code>Ask Every Time</html:code>
in an administrative policies file</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000003</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Websites within the organization require user authentication for access which increases
security for the information within. Access will be denied to the user if
certificate management is not configured.</xccdf-1.2:rationale>
          <xccdf-1.2:fix id="firefox_policy-verification" strategy="policy" system="urn:xccdf:fix:script:sh">
firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644

declare __REMEDIATE_PYTHON
if [ -x /usr/bin/python ]; then
    __REMEDIATE_PYTHON=/usr/bin/python
elif [ -x /usr/bin/python3 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python3
elif [ -x /usr/bin/python2 ]; then
    __REMEDIATE_PYTHON=/usr/bin/python2
else
    echo "Python required and no python interpreter found."
    exit 1
fi
declare __FIREFOX_DISTRIBUTION
if find /usr -iname firefox\* -type f -print | grep -qe "firefox.sh$\|firefox-bin$"; then
   __FIREFOX_DISTRIBUTION=$(dirname "$(find /usr -iname firefox\* -type f -print | grep -e "firefox.sh$\|firefox-bin$" | head -n1)")/distribution
fi
# If there's a policies file in the distribution directory already, modify it.
if [ -f ${__FIREFOX_DISTRIBUTION}/policies.json ]; then
        firefox_dirs="${__FIREFOX_DISTRIBUTION}"
fi
# Check the possible Firefox install directories
for firefox_dir in ${firefox_dirs}; do
    if ! [ -d "${firefox_dir}" ]; then
        mkdir -p "${firefox_dir}"
        chmod 755 "${firefox_dir}"
    fi
    # Make sure the Firefox .cfg file exists and has the appropriate permissions
    if ! [ -f "${firefox_dir}/${firefox_cfg}" ] ; then
        echo "{" &gt; "${firefox_dir}/${firefox_cfg}"
        echo "    \"policies\": {" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "    }" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        echo "}" &gt;&gt; "${firefox_dir}/${firefox_cfg}"
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
    # If the key exists, change it. Otherwise, add it to the config_file.
    if [ -x ${__REMEDIATE_PYTHON} ]; then
        echo """
import json
_file=open('${firefox_dir}/${firefox_cfg}', 'r')
_tree=json.load(_file)
_file.close()


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'security.default_personal_cert' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['security.default_personal_cert'] = dict()

_tree['policies']['Preferences']['security.default_personal_cert']['Value'] = 'Ask Every Time'


if 'Preferences' in _tree['policies']:
   pass
else:
   _tree['policies']['Preferences'] = dict()

if 'security.default_personal_cert' in _tree['policies']['Preferences']:
   pass
else:
   _tree['policies']['Preferences']['security.default_personal_cert'] = dict()

_tree['policies']['Preferences']['security.default_personal_cert']['Status'] = 'locked'

_file=open('${firefox_dir}/${firefox_cfg}', 'w')
json.dump(_tree, _file, indent=4, sort_keys=True)
_file.close()
""" | ${__REMEDIATE_PYTHON}
        chmod ${permissions} "${firefox_dir}/${firefox_cfg}"
    fi
done
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-firefox_policy-verification:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_preferences-auto-download_actions" selected="false" severity="medium">
          <xccdf-1.2:title>Disable auto-download for proscribed MIME types.</xccdf-1.2:title>
          <xccdf-1.2:description>Firefox must be configured to not automatically execute or download MIME types that are not
authorized for auto-download.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3 c</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000006</xccdf-1.2:reference>
          <xccdf-1.2:rationale>This setting ensures that some file types that may be downloaded or executed without user interaction
are not downloaded and/or executed.</xccdf-1.2:rationale>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_installed_firefox_version_supported" selected="false" severity="high">
          <xccdf-1.2:title>Supported Version of Firefox Installed</xccdf-1.2:title>
          <xccdf-1.2:description>If the system is joined to the Red Hat Network, a Red Hat Satellite Server,
or a yum server, run the following command to install updates:
<html:pre>$ sudo yum update</html:pre>
If the system is not configured to use one of these sources, updates (in the form of RPM packages)
can be manually downloaded and installed using <html:code>rpm</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-22</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000001</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Use of versions of an application which are not supported by the vendor
are not permitted. Vendors respond to security flaws with updates and
patches. These updates are not available for unsupported version which
can leave the application vulnerable to attack.</xccdf-1.2:rationale>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-firefox-oval.xml" name="oval:ssg-installed_firefox_version_supported:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_firefox_preferences-dod_root_certificate">
          <xccdf-1.2:title>The DoD Root Certificate Is Required</xccdf-1.2:title>
          <xccdf-1.2:description>The Shared System Certificates store contains certificates that
applications can access for a single certificate repository.
If enabled, Firefox can access that single system certificate
repository. If the DoD root certificate is also installed into
the shared system certificate repository, Firefox will see and 
use the DoD root certificate as a valid certificate authority.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_preferences-dod_root_certificate_installed" selected="false" severity="medium">
            <xccdf-1.2:title>The DoD Root Certificate Exists</xccdf-1.2:title>
            <xccdf-1.2:description>The DoD root certificate should be installed in the Shared System Certificates store
for Firefox to be able to access the DoD certificate. To install the root certificated
into the Shared System Certificates store, copy the DoD root certificate into
<html:code>/etc/pki/ca-trust/source/anchors</html:code>. Once the file is copied, run the following
command:
<html:pre>$ sudo update-ca-trust extract</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5 (2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">FFOX-00-000016</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The DOD root certificate will ensure that the trust chain is
established for server certificates issued from the DOD CA.</xccdf-1.2:rationale>
            <xccdf-1.2:ident system="https://ncp.nist.gov/cce">CCE-82056-3</xccdf-1.2:ident>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firefox_preferences-enable_ca_trust" selected="false" severity="medium">
            <xccdf-1.2:title>Enable Shared System Certificates</xccdf-1.2:title>
            <xccdf-1.2:description>The Shared System Certificates store makes NSS, GnuTLS, OpenSSL, and Java
share a default source for retrieving system certificate anchors and blacklist
information. Firefox has the capability of using this centralized store for its
CA certificates. If the Shared System Certificates store is disabled, it can
be enabled by running the following command:
<html:pre>$ sudo update-ca-trust enable</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-10</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The DOD root certificate will ensure that the trust chain is
established for server certificates issued from the DOD CA.</xccdf-1.2:rationale>
            <xccdf-1.2:ident system="https://ncp.nist.gov/cce">CCE-82057-1</xccdf-1.2:ident>
            <xccdf-1.2:fix id="firefox_preferences-enable_ca_trust" system="urn:xccdf:fix:script:sh">P11=$(readlink /etc/alternatives/libnssckbi.so*)
P11LIB="/usr/lib/pkcs11/p11-kit-trust.so"
P11LIB64="/usr/lib64/pkcs11/p11-kit-trust.so"

if ! [[ ${P11} == "${P11LIB64}" ]] || ! [[ ${P11} == "${P11LIB}" ]] ; then
   /usr/bin/update-ca-trust enable
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-firefox-ocil.xml" name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
      </xccdf-1.2:Group>
    </xccdf-1.2:Benchmark>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-firefox-oval.xml" timestamp="2026-06-15T09:08:53">
    <oval-def:oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
      <oval-def:generator>
        <oval:product_name>OVALFileLinker from SCAP Security Guide</oval:product_name>
        <oval:product_version>ssg: [0, 1, 81], python: 3.6.8</oval:product_version>
        <oval:schema_version>5.11</oval:schema_version>
        <oval:timestamp>2026-06-15T09:08:52</oval:timestamp>
      </oval-def:generator>
      <oval-def:definitions>
        <oval-def:definition class="compliance" id="oval:ssg-installed_firefox_version_supported:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Supported Version of Firefox Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="installed_firefox_version_supported" source="ssg"/>
            <oval-def:description>Use of versions of an application which are not
      supported by the vendor are not permitted. Vendors respond to
      security flaws with updates and patches. These updates are not
      available for unsupported versions which can leave the application
      vulnerable to attack.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="installed version of firefox supported" test_ref="oval:ssg-test_supported_version_of_firefox:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-addons_permission:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to disable the installation of extensions.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-addons_permission" source="ssg"/>
            <oval-def:description>Check setting of Disable extension installation in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting InstallAddonsPermission.Default to 'false'." test_ref="oval:ssg-test_firefox_policy-addons_permission_InstallAddonsPermission_Default:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-autoplay_video:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox autoplay must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-autoplay_video" source="ssg"/>
            <oval-def:description>Check setting of Disable autoplay for videos with audio content in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Permissions.Autoplay.Default to 'block-audio-video'." test_ref="oval:ssg-test_firefox_policy-autoplay_video_Permissions_Autoplay_Default:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-content_blocker:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the Content Blocker uBlock Origin is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-content_blocker" source="ssg"/>
            <oval-def:description>Check setting of Ensure the content blocker uBlock Origin is installed in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting ExtensionSettings.uBlock0@raymondhill.net.installation_mode to 'normal_installed'." test_ref="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting ExtensionSettings.uBlock0@raymondhill.net.install_url to 'https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi'." test_ref="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting ExtensionSettings.uBlock0@raymondhill.net.updates_disabled to 'false'." test_ref="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-cryptomining:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enabled Firefox Cryptomining protection</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-cryptomining" source="ssg"/>
            <oval-def:description>Check setting of Enable tracking protection for cryptomining in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting EnableTrackingProtection.Cryptomining to 'true'." test_ref="oval:ssg-test_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-development_tools:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox Development Tools</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-development_tools" source="ssg"/>
            <oval-def:description>Check setting of Disable developer tools in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableDeveloperTools to 'true'." test_ref="oval:ssg-test_firefox_policy-development_tools__DisableDeveloperTools:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-disable_deprecated_ciphers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox deprecated ciphers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-disable_deprecated_ciphers" source="ssg"/>
            <oval-def:description>Check setting of Disable deprecated ciphers in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting DisabledCiphers.TLS_RSA_WITH_3DES_EDE_CBC_SHA to 'true'." test_ref="oval:ssg-test_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-disable_form_history:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to disable form fill assistance.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-disable_form_history" source="ssg"/>
            <oval-def:description>Check setting of Disable form fill history. in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableFormHistory to 'true'." test_ref="oval:ssg-test_firefox_policy-disable_form_history__DisableFormHistory:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-disable_pocket:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox Pocket</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-disable_pocket" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Pocket in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisablePocket to 'true'." test_ref="oval:ssg-test_firefox_policy-disable_pocket__DisablePocket:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-disable_studies:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox Studies</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-disable_studies" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Studies in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableFirefoxStudies to 'true'." test_ref="oval:ssg-test_firefox_policy-disable_studies__DisableFirefoxStudies:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-dns_over_https:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured so that DNS over HTTPS is disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-dns_over_https" source="ssg"/>
            <oval-def:description>Check setting of Disable DNS over HTTPS in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting DNSOverHTTPS.Enabled to 'false'." test_ref="oval:ssg-test_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-encrypted_media_extensions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox encrypted media extensions must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-encrypted_media_extensions" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Site Feedback in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting EncryptedMediaExtensions.Enabled to 'false'." test_ref="oval:ssg-test_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting EncryptedMediaExtensions.Locked to 'true'." test_ref="oval:ssg-test_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-enhanced_tracking:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enabled Firefox Enhanced Tracking Protection</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-enhanced_tracking" source="ssg"/>
            <oval-def:description>Check setting of Enable enhanced tracking protection in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.browser.contentblocking.category.Value to 'strict'." test_ref="oval:ssg-test_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.browser.contentblocking.category.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-extension_recommendation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disabled Firefox Extension Recommendations</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-extension_recommendation" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox extension recommendations in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.extensions.htmlaboutaddons.recommendations.enabled.Value to 'false'." test_ref="oval:ssg-test_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.extensions.htmlaboutaddons.recommendations.enabled.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-extension_update:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to not automatically update installed add-ons and plugins.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-extension_update" source="ssg"/>
            <oval-def:description>Check setting of Disable addon and plugin automatic update in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .ExtensionUpdate to 'false'." test_ref="oval:ssg-test_firefox_policy-extension_update__ExtensionUpdate:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-feedback_reporting:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox feedback reporting must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-feedback_reporting" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Site Feedback in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableFeedbackCommands to 'true'." test_ref="oval:ssg-test_firefox_policy-feedback_reporting__DisableFeedbackCommands:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-fingerprinting_protection:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enabled Firefox Fingerprinting Protection</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-fingerprinting_protection" source="ssg"/>
            <oval-def:description>Check setting of Enable tracking protection for fingerprinting in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting EnableTrackingProtection.Fingerprinting to 'true'." test_ref="oval:ssg-test_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-forget_button:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must prevent the user from quickly deleting data.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-forget_button" source="ssg"/>
            <oval-def:description>Check setting of Disable Forget button in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableForgetButton to 'true'." test_ref="oval:ssg-test_firefox_policy-forget_button__DisableForgetButton:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-javascript_window_changes:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable JavaScript's Raise Or Lower Windows Capability</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-javascript_window_changes" source="ssg"/>
            <oval-def:description>Check setting of Disable addon and plugin automatic update in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.dom.disable_window_flip.Value to 'true'." test_ref="oval:ssg-test_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.dom.disable_window_flip.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-javascript_window_resizing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable JavaScript's Moving Or Resizing Windows Capability</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-javascript_window_resizing" source="ssg"/>
            <oval-def:description>Check setting of Disable Javascript window move/resize in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.dom.disable_window_move_resize.Value to 'true'." test_ref="oval:ssg-test_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.dom.disable_window_move_resize.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-network_prediction:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox network prediction</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-network_prediction" source="ssg"/>
            <oval-def:description>Check setting of Disable addon and plugin automatic update in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .NetworkPrediction to 'false'." test_ref="oval:ssg-test_firefox_policy-network_prediction__NetworkPrediction:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-no_sanitize_on_shutdown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to not delete data upon shutdown.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-no_sanitize_on_shutdown" source="ssg"/>
            <oval-def:description>Check setting of Require default personal certificate be chosen every time in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.Cache to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.Cookies to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.Downloads to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.FormData to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.History to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.Sessions to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.SiteSettings to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.OfflineApps to 'false'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting SanitizeOnShutdown.Locked to 'true'." test_ref="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-nonessential_capabilities:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Firefox New Tab page must not show Top Sites, Sponsored Top sites, Pocket Recommendations, Sponsored Pocket Stories, Searches, Highlights, or Snippets.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-nonessential_capabilities" source="ssg"/>
            <oval-def:description>Check setting of Disable dynamic New Tab features in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.Search to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Search:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.TopSites to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.SponsoredTopSites to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.Pocket to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.SponsoredPocket to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.Highlights to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.Snippets to 'false'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting FirefoxHome.locked to 'true'." test_ref="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_locked:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-password_manager:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to not use a password store with or without a master password.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-password_manager" source="ssg"/>
            <oval-def:description>Check setting of Disable password manager in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .PasswordManagerEnabled to 'false'." test_ref="oval:ssg-test_firefox_policy-password_manager__PasswordManagerEnabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-pop-up_windows:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Firefox Pop-up Blocker</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-pop-up_windows" source="ssg"/>
            <oval-def:description>Check setting of Disable popup blocking in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting PopupBlocking.Default to 'true'." test_ref="oval:ssg-test_firefox_policy-pop-up_windows_PopupBlocking_Default:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting PopupBlocking.Locked to 'true'." test_ref="oval:ssg-test_firefox_policy-pop-up_windows_PopupBlocking_Locked:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-private_browsing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox private browsing must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-private_browsing" source="ssg"/>
            <oval-def:description>Check setting of Disable Private Browsing feature in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisablePrivateBrowsing to 'true'." test_ref="oval:ssg-test_firefox_policy-private_browsing__DisablePrivateBrowsing:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-search_suggestion:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox search suggestions must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-search_suggestion" source="ssg"/>
            <oval-def:description>Check setting of Disable search suggestion in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .SearchSuggestEnabled to 'false'." test_ref="oval:ssg-test_firefox_policy-search_suggestion__SearchSuggestEnabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-search_update:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Installed Search Plugins Update Checking</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-search_update" source="ssg"/>
            <oval-def:description>Check setting of Disable Search Plugin Updates in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.browser.search.update.Value to 'false'." test_ref="oval:ssg-test_firefox_policy-search_update_Preferences_browser.search.update_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.browser.search.update.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-search_update_Preferences_browser.search.update_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-ssl_minimum_version:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must be configured to allow only TLS 1.2 or above.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-ssl_minimum_version" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Sync in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .SSLVersionMin to 'tls1.2'." test_ref="oval:ssg-test_firefox_policy-ssl_minimum_version__SSLVersionMin:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-sync:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox accounts must be disabled.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-sync" source="ssg"/>
            <oval-def:description>Check setting of Disable Firefox Sync in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableFirefoxAccounts to 'true'." test_ref="oval:ssg-test_firefox_policy-sync__DisableFirefoxAccounts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-telemetry:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Firefox Telemetry</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-telemetry" source="ssg"/>
            <oval-def:description>Check setting of Disable telemetry in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting .DisableTelemetry to 'true'." test_ref="oval:ssg-test_firefox_policy-telemetry__DisableTelemetry:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-user_messaging:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Firefox must not recommend extensions as the user is using the browser.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-user_messaging" source="ssg"/>
            <oval-def:description>Check setting of Disable Extension Recommendation Messages in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting UserMessaging.ExtensionRecommendations to 'false'." test_ref="oval:ssg-test_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firefox_policy-verification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Certificate Verification</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="firefox_policy-verification" source="ssg"/>
            <oval-def:description>Check setting of Configure Default Personal Certificate to Ask Every Time in Firefox policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - Firefox policy item is set." operator="AND">
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.security.default_personal_cert.Value to 'Ask Every Time'." test_ref="oval:ssg-test_firefox_policy-verification_Preferences_security.default_personal_cert_Value:tst:1"/>
            <oval-def:criterion comment="Check that Firefox administrative policy setting Preferences.security.default_personal_cert.Status to 'locked'." test_ref="oval:ssg-test_firefox_policy-verification_Preferences_security.default_personal_cert_Status:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
      </oval-def:definitions>
      <oval-def:tests>
        <linux:rpminfo_test check="all" check_existence="any_exist" comment="Installed version of firefox is greater than 68.4.0" id="oval:ssg-test_supported_version_of_firefox:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_supported_version_of_firefox:obj:1"/>
          <linux:state state_ref="oval:ssg-state_supported_version_of_firefox:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of InstallAddonsPermission.Default in Firefox policy file" id="oval:ssg-test_firefox_policy-addons_permission_InstallAddonsPermission_Default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-addons_permission_InstallAddonsPermission_Default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-addons_permission_InstallAddonsPermission_Default:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Permissions.Autoplay.Default in Firefox policy file" id="oval:ssg-test_firefox_policy-autoplay_video_Permissions_Autoplay_Default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-autoplay_video_Permissions_Autoplay_Default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-autoplay_video_Permissions_Autoplay_Default:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of ExtensionSettings.uBlock0@raymondhill.net.installation_mode in Firefox policy file" id="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of ExtensionSettings.uBlock0@raymondhill.net.install_url in Firefox policy file" id="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of ExtensionSettings.uBlock0@raymondhill.net.updates_disabled in Firefox policy file" id="oval:ssg-test_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of EnableTrackingProtection.Cryptomining in Firefox policy file" id="oval:ssg-test_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableDeveloperTools in Firefox policy file" id="oval:ssg-test_firefox_policy-development_tools__DisableDeveloperTools:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-development_tools__DisableDeveloperTools:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-development_tools__DisableDeveloperTools:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of DisabledCiphers.TLS_RSA_WITH_3DES_EDE_CBC_SHA in Firefox policy file" id="oval:ssg-test_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableFormHistory in Firefox policy file" id="oval:ssg-test_firefox_policy-disable_form_history__DisableFormHistory:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-disable_form_history__DisableFormHistory:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-disable_form_history__DisableFormHistory:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisablePocket in Firefox policy file" id="oval:ssg-test_firefox_policy-disable_pocket__DisablePocket:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-disable_pocket__DisablePocket:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-disable_pocket__DisablePocket:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableFirefoxStudies in Firefox policy file" id="oval:ssg-test_firefox_policy-disable_studies__DisableFirefoxStudies:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-disable_studies__DisableFirefoxStudies:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-disable_studies__DisableFirefoxStudies:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of DNSOverHTTPS.Enabled in Firefox policy file" id="oval:ssg-test_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of EncryptedMediaExtensions.Enabled in Firefox policy file" id="oval:ssg-test_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of EncryptedMediaExtensions.Locked in Firefox policy file" id="oval:ssg-test_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.browser.contentblocking.category.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.browser.contentblocking.category.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.extensions.htmlaboutaddons.recommendations.enabled.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.extensions.htmlaboutaddons.recommendations.enabled.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .ExtensionUpdate in Firefox policy file" id="oval:ssg-test_firefox_policy-extension_update__ExtensionUpdate:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-extension_update__ExtensionUpdate:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-extension_update__ExtensionUpdate:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableFeedbackCommands in Firefox policy file" id="oval:ssg-test_firefox_policy-feedback_reporting__DisableFeedbackCommands:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-feedback_reporting__DisableFeedbackCommands:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-feedback_reporting__DisableFeedbackCommands:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of EnableTrackingProtection.Fingerprinting in Firefox policy file" id="oval:ssg-test_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableForgetButton in Firefox policy file" id="oval:ssg-test_firefox_policy-forget_button__DisableForgetButton:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-forget_button__DisableForgetButton:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-forget_button__DisableForgetButton:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.dom.disable_window_flip.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.dom.disable_window_flip.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.dom.disable_window_move_resize.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.dom.disable_window_move_resize.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .NetworkPrediction in Firefox policy file" id="oval:ssg-test_firefox_policy-network_prediction__NetworkPrediction:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-network_prediction__NetworkPrediction:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-network_prediction__NetworkPrediction:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.Cache in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.Cookies in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.Downloads in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.FormData in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.History in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.Sessions in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.SiteSettings in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.OfflineApps in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of SanitizeOnShutdown.Locked in Firefox policy file" id="oval:ssg-test_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.Search in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Search:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Search:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Search:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.TopSites in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.SponsoredTopSites in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.Pocket in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.SponsoredPocket in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.Highlights in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.Snippets in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of FirefoxHome.locked in Firefox policy file" id="oval:ssg-test_firefox_policy-nonessential_capabilities_FirefoxHome_locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_locked:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_locked:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .PasswordManagerEnabled in Firefox policy file" id="oval:ssg-test_firefox_policy-password_manager__PasswordManagerEnabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-password_manager__PasswordManagerEnabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-password_manager__PasswordManagerEnabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of PopupBlocking.Default in Firefox policy file" id="oval:ssg-test_firefox_policy-pop-up_windows_PopupBlocking_Default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-pop-up_windows_PopupBlocking_Default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-pop-up_windows_PopupBlocking_Default:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of PopupBlocking.Locked in Firefox policy file" id="oval:ssg-test_firefox_policy-pop-up_windows_PopupBlocking_Locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-pop-up_windows_PopupBlocking_Locked:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-pop-up_windows_PopupBlocking_Locked:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisablePrivateBrowsing in Firefox policy file" id="oval:ssg-test_firefox_policy-private_browsing__DisablePrivateBrowsing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-private_browsing__DisablePrivateBrowsing:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-private_browsing__DisablePrivateBrowsing:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .SearchSuggestEnabled in Firefox policy file" id="oval:ssg-test_firefox_policy-search_suggestion__SearchSuggestEnabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-search_suggestion__SearchSuggestEnabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-search_suggestion__SearchSuggestEnabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.browser.search.update.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-search_update_Preferences_browser.search.update_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-search_update_Preferences_browser.search.update_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-search_update_Preferences_browser.search.update_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.browser.search.update.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-search_update_Preferences_browser.search.update_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-search_update_Preferences_browser.search.update_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-search_update_Preferences_browser.search.update_Status:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .SSLVersionMin in Firefox policy file" id="oval:ssg-test_firefox_policy-ssl_minimum_version__SSLVersionMin:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-ssl_minimum_version__SSLVersionMin:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-ssl_minimum_version__SSLVersionMin:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableFirefoxAccounts in Firefox policy file" id="oval:ssg-test_firefox_policy-sync__DisableFirefoxAccounts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-sync__DisableFirefoxAccounts:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-sync__DisableFirefoxAccounts:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of .DisableTelemetry in Firefox policy file" id="oval:ssg-test_firefox_policy-telemetry__DisableTelemetry:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-telemetry__DisableTelemetry:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-telemetry__DisableTelemetry:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of UserMessaging.ExtensionRecommendations in Firefox policy file" id="oval:ssg-test_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.security.default_personal_cert.Value in Firefox policy file" id="oval:ssg-test_firefox_policy-verification_Preferences_security.default_personal_cert_Value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-verification_Preferences_security.default_personal_cert_Value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-verification_Preferences_security.default_personal_cert_Value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check setting of Preferences.security.default_personal_cert.Status in Firefox policy file" id="oval:ssg-test_firefox_policy-verification_Preferences_security.default_personal_cert_Status:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firefox_policy-verification_Preferences_security.default_personal_cert_Status:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firefox_policy-verification_Preferences_security.default_personal_cert_Status:ste:1"/>
        </ind:textfilecontent54_test>
      </oval-def:tests>
      <oval-def:objects>
        <linux:rpminfo_object id="oval:ssg-obj_supported_version_of_firefox:obj:1" version="1">
          <linux:name>firefox</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-addons_permission_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-addons_permission_InstallAddonsPermission_Default:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-addons_permission_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="InstallAddonsPermission")"InstallAddonsPermission"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Default"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-autoplay_video_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-autoplay_video_Permissions_Autoplay_Default:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-autoplay_video_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Permissions")"Permissions"[\s]*:[\s]*\{[\s\S]*?(?="Autoplay")"Autoplay"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Default"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-content_blocker_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-content_blocker_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="ExtensionSettings")"ExtensionSettings"[\s]*:[\s]*\{[\s\S]*?(?="uBlock0\@raymondhill\.net")"uBlock0\@raymondhill\.net"[\s]*:[\s]*\{[\s\S]*?(?=[^"])installation_mode"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-content_blocker_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="ExtensionSettings")"ExtensionSettings"[\s]*:[\s]*\{[\s\S]*?(?="uBlock0\@raymondhill\.net")"uBlock0\@raymondhill\.net"[\s]*:[\s]*\{[\s\S]*?(?=[^"])install_url"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-content_blocker_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="ExtensionSettings")"ExtensionSettings"[\s]*:[\s]*\{[\s\S]*?(?="uBlock0\@raymondhill\.net")"uBlock0\@raymondhill\.net"[\s]*:[\s]*\{[\s\S]*?(?=[^"])updates_disabled"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-cryptomining_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-cryptomining_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="EnableTrackingProtection")"EnableTrackingProtection"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Cryptomining"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-development_tools_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-development_tools__DisableDeveloperTools:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-development_tools_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableDeveloperTools"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-disable_deprecated_ciphers_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-disable_deprecated_ciphers_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="DisabledCiphers")"DisabledCiphers"[\s]*:[\s]*\{[\s\S]*?(?=[^"])TLS_RSA_WITH_3DES_EDE_CBC_SHA"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-disable_form_history_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-disable_form_history__DisableFormHistory:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-disable_form_history_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableFormHistory"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-disable_pocket_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-disable_pocket__DisablePocket:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-disable_pocket_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisablePocket"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-disable_studies_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-disable_studies__DisableFirefoxStudies:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-disable_studies_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableFirefoxStudies"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-dns_over_https_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-dns_over_https_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="DNSOverHTTPS")"DNSOverHTTPS"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Enabled"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-encrypted_media_extensions_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-encrypted_media_extensions_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="EncryptedMediaExtensions")"EncryptedMediaExtensions"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Enabled"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-encrypted_media_extensions_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="EncryptedMediaExtensions")"EncryptedMediaExtensions"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Locked"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-enhanced_tracking_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-enhanced_tracking_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="browser\.contentblocking\.category")"browser\.contentblocking\.category"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-enhanced_tracking_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="browser\.contentblocking\.category")"browser\.contentblocking\.category"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-extension_recommendation_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-extension_recommendation_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="extensions\.htmlaboutaddons\.recommendations\.enabled")"extensions\.htmlaboutaddons\.recommendations\.enabled"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-extension_recommendation_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="extensions\.htmlaboutaddons\.recommendations\.enabled")"extensions\.htmlaboutaddons\.recommendations\.enabled"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-extension_update_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-extension_update__ExtensionUpdate:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-extension_update_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])ExtensionUpdate"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-feedback_reporting_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-feedback_reporting__DisableFeedbackCommands:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-feedback_reporting_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableFeedbackCommands"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-fingerprinting_protection_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-fingerprinting_protection_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="EnableTrackingProtection")"EnableTrackingProtection"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Fingerprinting"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-forget_button_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-forget_button__DisableForgetButton:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-forget_button_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableForgetButton"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-javascript_window_changes_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-javascript_window_changes_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="dom\.disable_window_flip")"dom\.disable_window_flip"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-javascript_window_changes_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="dom\.disable_window_flip")"dom\.disable_window_flip"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-javascript_window_resizing_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-javascript_window_resizing_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="dom\.disable_window_move_resize")"dom\.disable_window_move_resize"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-javascript_window_resizing_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="dom\.disable_window_move_resize")"dom\.disable_window_move_resize"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-network_prediction_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-network_prediction__NetworkPrediction:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-network_prediction_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])NetworkPrediction"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Cache"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Cookies"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Downloads"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])FormData"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])History"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Sessions"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])SiteSettings"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])OfflineApps"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="SanitizeOnShutdown")"SanitizeOnShutdown"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Locked"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-nonessential_capabilities_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Search:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Search"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])TopSites"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])SponsoredTopSites"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Pocket"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])SponsoredPocket"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Highlights"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Snippets"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-nonessential_capabilities_FirefoxHome_locked:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="FirefoxHome")"FirefoxHome"[\s]*:[\s]*\{[\s\S]*?(?=[^"])locked"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-password_manager_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-password_manager__PasswordManagerEnabled:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-password_manager_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])PasswordManagerEnabled"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-pop-up_windows_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-pop-up_windows_PopupBlocking_Default:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-pop-up_windows_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="PopupBlocking")"PopupBlocking"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Default"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-pop-up_windows_PopupBlocking_Locked:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-pop-up_windows_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="PopupBlocking")"PopupBlocking"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Locked"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-private_browsing_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-private_browsing__DisablePrivateBrowsing:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-private_browsing_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisablePrivateBrowsing"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-search_suggestion_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-search_suggestion__SearchSuggestEnabled:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-search_suggestion_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])SearchSuggestEnabled"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-search_update_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-search_update_Preferences_browser.search.update_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-search_update_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="browser\.search\.update")"browser\.search\.update"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-search_update_Preferences_browser.search.update_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-search_update_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="browser\.search\.update")"browser\.search\.update"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-ssl_minimum_version_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-ssl_minimum_version__SSLVersionMin:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-ssl_minimum_version_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])SSLVersionMin"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-sync_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-sync__DisableFirefoxAccounts:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-sync_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableFirefoxAccounts"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-telemetry_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-telemetry__DisableTelemetry:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-telemetry_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?=[^"])DisableTelemetry"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-user_messaging_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-user_messaging_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="UserMessaging")"UserMessaging"[\s]*:[\s]*\{[\s\S]*?(?=[^"])ExtensionRecommendations"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Find all installations of Firefox" id="oval:ssg-obj_firefox_policy-verification_firefox_path:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/usr</unix:path>
          <unix:filename operation="pattern match">^firefox.sh$|^firefox-bin$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-verification_Preferences_security.default_personal_cert_Value:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-verification_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="security\.default_personal_cert")"security\.default_personal_cert"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Value"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firefox_policy-verification_Preferences_security.default_personal_cert_Status:obj:1" version="1">
          <ind:path datatype="string" var_check="at least one" var_ref="oval:ssg-var_firefox_policy-verification_firefox_path:var:1"/>
          <ind:filename datatype="string">policies.json</ind:filename>
          <ind:pattern operation="pattern match">^(?i)\{\s*(?="policies")"policies"[\s]*:[\s]*\{[\s\S]*(?="Preferences")"Preferences"[\s]*:[\s]*\{[\s\S]*?(?="security\.default_personal_cert")"security\.default_personal_cert"[\s]*:[\s]*\{[\s\S]*?(?=[^"])Status"[\s]*:[\s]*([^,}]+),?\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
      </oval-def:objects>
      <oval-def:states>
        <linux:rpminfo_state id="oval:ssg-state_supported_version_of_firefox:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="greater than">68.4.0</linux:evr>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-addons_permission_InstallAddonsPermission_Default:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-autoplay_video_Permissions_Autoplay_Default:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"block-audio-video"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_installation_mode:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"normal_installed"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_install_url:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-content_blocker_ExtensionSettings_uBlock0_at_raymondhill.net_updates_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-cryptomining_EnableTrackingProtection_Cryptomining:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-development_tools__DisableDeveloperTools:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-disable_deprecated_ciphers_DisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-disable_form_history__DisableFormHistory:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-disable_pocket__DisablePocket:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-disable_studies__DisableFirefoxStudies:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-dns_over_https_DNSOverHTTPS_Enabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Enabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-encrypted_media_extensions_EncryptedMediaExtensions_Locked:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"strict"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-enhanced_tracking_Preferences_browser.contentblocking.category_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-extension_recommendation_Preferences_extensions.htmlaboutaddons.recommendations.enabled_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-extension_update__ExtensionUpdate:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-feedback_reporting__DisableFeedbackCommands:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-fingerprinting_protection_EnableTrackingProtection_Fingerprinting:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-forget_button__DisableForgetButton:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-javascript_window_changes_Preferences_dom.disable_window_flip_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-javascript_window_resizing_Preferences_dom.disable_window_move_resize_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-network_prediction__NetworkPrediction:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cache:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Cookies:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Downloads:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_FormData:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_History:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Sessions:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_SiteSettings:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_OfflineApps:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-no_sanitize_on_shutdown_SanitizeOnShutdown_Locked:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Search:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_TopSites:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredTopSites:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Pocket:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_SponsoredPocket:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Highlights:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_Snippets:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-nonessential_capabilities_FirefoxHome_locked:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-password_manager__PasswordManagerEnabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-pop-up_windows_PopupBlocking_Default:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-pop-up_windows_PopupBlocking_Locked:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-private_browsing__DisablePrivateBrowsing:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-search_suggestion__SearchSuggestEnabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-search_update_Preferences_browser.search.update_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-search_update_Preferences_browser.search.update_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-ssl_minimum_version__SSLVersionMin:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">tls1\.[23]</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-sync__DisableFirefoxAccounts:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-telemetry__DisableTelemetry:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Tt]rue</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-user_messaging_UserMessaging_ExtensionRecommendations:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">[Ff]alse</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-verification_Preferences_security.default_personal_cert_Value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"Ask Every Time"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firefox_policy-verification_Preferences_security.default_personal_cert_Status:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" entity_check="all" operation="pattern match">"locked"</ind:subexpression>
        </ind:textfilecontent54_state>
      </oval-def:states>
      <oval-def:variables>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-addons_permission_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-addons_permission_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-autoplay_video_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-autoplay_video_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-content_blocker_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-content_blocker_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-cryptomining_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-cryptomining_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-development_tools_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-development_tools_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-disable_deprecated_ciphers_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-disable_deprecated_ciphers_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-disable_form_history_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-disable_form_history_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-disable_pocket_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-disable_pocket_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-disable_studies_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-disable_studies_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-dns_over_https_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-dns_over_https_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-encrypted_media_extensions_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-encrypted_media_extensions_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-enhanced_tracking_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-enhanced_tracking_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-extension_recommendation_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-extension_recommendation_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-extension_update_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-extension_update_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-feedback_reporting_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-feedback_reporting_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-fingerprinting_protection_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-fingerprinting_protection_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-forget_button_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-forget_button_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-javascript_window_changes_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-javascript_window_changes_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-javascript_window_resizing_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-javascript_window_resizing_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-network_prediction_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-network_prediction_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-no_sanitize_on_shutdown_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-no_sanitize_on_shutdown_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-nonessential_capabilities_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-nonessential_capabilities_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-password_manager_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-password_manager_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-pop-up_windows_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-pop-up_windows_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-private_browsing_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-private_browsing_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-search_suggestion_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-search_suggestion_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-search_update_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-search_update_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-ssl_minimum_version_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-ssl_minimum_version_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-sync_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-sync_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-telemetry_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-telemetry_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-user_messaging_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-user_messaging_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="policies.json path for Firefox." datatype="string" id="oval:ssg-var_firefox_policy-verification_firefox_path:var:1" version="1">
          <oval-def:unique>
            <oval-def:literal_component>/etc/firefox/policies</oval-def:literal_component>
            <oval-def:concat>
              <oval-def:object_component item_field="path" object_ref="oval:ssg-obj_firefox_policy-verification_firefox_path:obj:1"/>
              <oval-def:literal_component>/distribution</oval-def:literal_component>
            </oval-def:concat>
          </oval-def:unique>
        </oval-def:local_variable>
      </oval-def:variables>
    </oval-def:oval_definitions>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-firefox-ocil.xml" timestamp="2026-06-15T09:08:53">
    <ocil:ocil>
      <ocil:generator>
        <ocil:product_name>build_shorthand.py from SCAP Security Guide</ocil:product_name>
        <ocil:product_version>ssg: 0.1.81</ocil:product_version>
        <ocil:schema_version>2.0</ocil:schema_version>
        <ocil:timestamp>2026-06-15T09:08:52</ocil:timestamp>
      </ocil:generator>
      <ocil:questionnaires>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
          <ocil:title>Firefox autoplay must be disabled.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
          <ocil:title>Ensure the Content Blocker uBlock Origin is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
          <ocil:title>Enabled Firefox Cryptomining protection</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
          <ocil:title>Disable Firefox Development Tools</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
          <ocil:title>Disable Firefox deprecated ciphers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
          <ocil:title>Disable Firefox Pocket</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
          <ocil:title>Disable Firefox Studies</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
          <ocil:title>Enabled Firefox Enhanced Tracking Protection</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
          <ocil:title>Disabled Firefox Extension Recommendations</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
          <ocil:title>Firefox must be configured to not automatically update installed add-ons and plugins.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
          <ocil:title>Enabled Firefox Fingerprinting Protection</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
          <ocil:title>Firefox must prevent the user from quickly deleting data.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
          <ocil:title>Disable JavaScript's Raise Or Lower Windows Capability</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
          <ocil:title>Disable JavaScript's Moving Or Resizing Windows Capability</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
          <ocil:title>Disable Firefox network prediction</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
          <ocil:title>Enable Firefox Pop-up Blocker</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
          <ocil:title>Firefox private browsing must be disabled.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
          <ocil:title>Firefox search suggestions must be disabled.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">
          <ocil:title>Disable Installed Search Plugins Update Checking</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
          <ocil:title>Disable Firefox Telemetry</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
          <ocil:title>Enable Certificate Verification</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
          <ocil:title>Disable auto-download for proscribed MIME types.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
          <ocil:title>The DoD Root Certificate Exists</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
          <ocil:title>Enable Shared System Certificates</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
          <ocil:title>Supported Version of Firefox Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
      </ocil:questionnaires>
      <ocil:test_actions>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-autoplay_video_action:testaction:1" question_ref="ocil:ssg-firefox_policy-autoplay_video_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-content_blocker_action:testaction:1" question_ref="ocil:ssg-firefox_policy-content_blocker_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-cryptomining_action:testaction:1" question_ref="ocil:ssg-firefox_policy-cryptomining_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-development_tools_action:testaction:1" question_ref="ocil:ssg-firefox_policy-development_tools_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1" question_ref="ocil:ssg-firefox_policy-disable_deprecated_ciphers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-disable_pocket_action:testaction:1" question_ref="ocil:ssg-firefox_policy-disable_pocket_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-disable_studies_action:testaction:1" question_ref="ocil:ssg-firefox_policy-disable_studies_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1" question_ref="ocil:ssg-firefox_policy-enhanced_tracking_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1" question_ref="ocil:ssg-firefox_policy-extension_recommendation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-extension_update_action:testaction:1" question_ref="ocil:ssg-firefox_policy-extension_update_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1" question_ref="ocil:ssg-firefox_policy-fingerprinting_protection_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-forget_button_action:testaction:1" question_ref="ocil:ssg-firefox_policy-forget_button_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1" question_ref="ocil:ssg-firefox_policy-javascript_window_changes_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1" question_ref="ocil:ssg-firefox_policy-javascript_window_resizing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-network_prediction_action:testaction:1" question_ref="ocil:ssg-firefox_policy-network_prediction_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1" question_ref="ocil:ssg-firefox_policy-pop-up_windows_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-private_browsing_action:testaction:1" question_ref="ocil:ssg-firefox_policy-private_browsing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-search_suggestion_action:testaction:1" question_ref="ocil:ssg-firefox_policy-search_suggestion_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-search_update_action:testaction:1" question_ref="ocil:ssg-firefox_policy-search_update_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-telemetry_action:testaction:1" question_ref="ocil:ssg-firefox_policy-telemetry_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_policy-verification_action:testaction:1" question_ref="ocil:ssg-firefox_policy-verification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1" question_ref="ocil:ssg-firefox_preferences-auto-download_actions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1" question_ref="ocil:ssg-firefox_preferences-dod_root_certificate_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1" question_ref="ocil:ssg-firefox_preferences-enable_ca_trust_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-installed_firefox_version_supported_action:testaction:1" question_ref="ocil:ssg-installed_firefox_version_supported_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
      </ocil:test_actions>
      <ocil:questions>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-autoplay_video_question:question:1">
          <ocil:question_text>To verify that search suggestions are disabled,
type the following into the browser address bar:
about:policies
The output should have the following under Permissions -&gt; Autoplay:
"Default": "block-audio-video"
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-content_blocker_question:question:1">
          <ocil:question_text>To verify that the policy is modified to automatically install the content blocker and that it's updates are not disabled,
type the following into the browser address bar:
about:policies
The output should have the following under ExtensionSettings:
"uBlock0@raymondhill.net": {
"    "installation_mode":"normal_installed",
"    "install_url":"https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi",
"    "updates_disabled":false}
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-cryptomining_question:question:1">
          <ocil:question_text>To verify that cryptomining protection is enabled,
type the following into the browser address bar:
about:policies
The output should have the following under EnableTrackingProtection:
"Cryptomining": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-development_tools_question:question:1">
          <ocil:question_text>To verify that Firefox Development Tools are disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"DisableDeveloperTools": true,
      Is it the case that it is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_question:question:1">
          <ocil:question_text>To verify that deprecated ciphers are disabled,
type the following into the browser address bar:
about:policies
The output should have the following under DisabledCiphers:
"TLS_RSA_WITH_3DES_EDE_CBC_SHA": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-disable_pocket_question:question:1">
          <ocil:question_text>To verify that Pocket is disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"DisablePocket": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-disable_studies_question:question:1">
          <ocil:question_text>To verify that Studies is disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"DisableFirefoxStudies": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-enhanced_tracking_question:question:1">
          <ocil:question_text>To verify that enhanced tracking protection is enabled,
type the following into the browser address bar:
about:policies
The output should have the following under Preferences -&gt; browser.contentblocking.category:
"Value": "strict"
"Status": "locked"
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-extension_recommendation_question:question:1">
          <ocil:question_text>To verify that enhanced tracking protection is enabled,
type the following into the browser address bar:
about:policies
The output should have the following under Preferences -&gt; extensions.htmlaboutaddons.recommendations.enabled:
"Value": false
"Status": "locked"
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-extension_update_question:question:1">
          <ocil:question_text>To verify that certificate verification is enabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"ExtensionUpdate": false
Status: "locked"
      Is it the case that it is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-fingerprinting_protection_question:question:1">
          <ocil:question_text>To verify that fingerprinting protection is enabled,
type the following into the browser address bar:
about:policies
The output should have the following under EnableTrackingProtection:
"Fingerprinting": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-forget_button_question:question:1">
          <ocil:question_text>To verify that users cannot access the forget button,
type the following into the browser address bar:
about:policies
The output should have the following:
"DisableForgetButon": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-javascript_window_changes_question:question:1">
          <ocil:question_text>To verify that JavaScript cannot change windows sizing,
type the following into the browser address bar:
about:policies
The output should have the following uder dom.disable_window_flip:
"Value": true,
"Status": "locked",
      Is it the case that it is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-javascript_window_resizing_question:question:1">
          <ocil:question_text>To verify that JavaScript cannot change windows sizing,
type the following into the browser address bar:
about:policies
The output should have the following uder dom.disable_window_move_resize:
"Value": true,
"Status": "locked",
      Is it the case that it is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-network_prediction_question:question:1">
          <ocil:question_text>To verify that network prediction is disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"NetworkPrediction": false
      Is it the case that it is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-pop-up_windows_question:question:1">
          <ocil:question_text>To verify that pop-up blocker is enabled,
run the following command:
$ grep -B10 'PopupBlocking' FIREFOX_INSTALL_DIR/*.cfg
The output should include:
"Default": true
"Locked": true
      Is it the case that it is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-private_browsing_question:question:1">
          <ocil:question_text>To verify that private browsing is disabled
type the following into the browser address bar:
about:policies
The output should have the following uder dom.disable_window_move_resize:
"DisablePrivateBrowsing": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-search_suggestion_question:question:1">
          <ocil:question_text>To verify that search suggestions are disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"SearchSuggestEnabled": false
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-search_update_question:question:1">
          <ocil:question_text>To verify that checks for installed search plugin updates are disabled,
type the following into the browser address bar:
about:policies
The output should have the following under browser.search.update:
Value: false
Status: "locked"
      Is it the case that it is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-telemetry_question:question:1">
          <ocil:question_text>To verify that Firefox telemetry is disabled,
type the following into the browser address bar:
about:policies
The output should have the following:
"DisableTelemetry": true
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_policy-verification_question:question:1">
          <ocil:question_text>To verify that certificate verification is enabled, type the following into the browser address bar:
    about:policies
The output should have the following under security.default_personal_cert:
Value: "Ask Every Time"
Status: "locked"
      Is it the case that it is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_preferences-auto-download_actions_question:question:1">
          <ocil:question_text>To verify that any proscribed file types are configured for automatic download,
type "about:preferences" into the search bar,  then
type "Applications" in the Find bar in the upper-right corner.
If any of the following file extensions are listed and the Action item associated with it 
is an application that does or can execute the code, this is a finding.
If the entry exists and the "Action" is "Save File" or "Always Ask", this is not a finding.

  HTA
  JSE
  JS
  MOCHA
  SHS
  VBE
  VBS
  SCT
  WSC
  FDF
  XFDF
  LSL
  LSO
  LSS
  IQY
  RQY
  DOS
  BAT
  PS
  EPS
  WCH
  WCM
  WB1
  WB3
  WCH
  WCM
  AD

      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_question:question:1">
          <ocil:question_text>To verify that the DoD root certificate is installed,
list all certificates in /etc/pki/ca-trust/source/anchors
and compare them to the DoD root certificate. If there is a match
to the DoD root certificate, then the DoD root certificate is
installed.
      Is it the case that it is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firefox_preferences-enable_ca_trust_question:question:1">
          <ocil:question_text>To verify that the central system cerificate authority store is enabled,
run the following command:
$ ls -l /etc/alternatives/libnssckbi.so.x86_64
The output should return something similar to:
lrwxrwxrwx. 1 root root 34 Apr 30 09:19 /etc/alternatives/libnssckbi.so.x86_64 -&gt; /usr/lib64/pkcs11/p11-kit-trust.so
      Is it the case that it is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-installed_firefox_version_supported_question:question:1">
          <ocil:question_text>If the system is joined to the Red Hat Network, a Red Hat Satellite Server, or
a yum server which provides updates, invoking the following command will
indicate if updates are available:
$ sudo yum check-update
If the system is not configured to update from one of these sources,
run the following command to list when each package was last updated:
$ rpm -qa -last
Compare this to Red Hat Security Advisories (RHSA) listed at

    https://access.redhat.com/security/updates/active/
to determine if the system is missing applicable updates.
      Is it the case that it is not updated?
      </ocil:question_text>
        </ocil:boolean_question>
      </ocil:questions>
    </ocil:ocil>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml" timestamp="2026-06-15T09:08:53">
    <oval-def:oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
      <oval-def:generator>
        <oval:product_name>build_cpe.py from SCAP Security Guide</oval:product_name>
        <oval:product_version>ssg: [0, 1, 81], python: 3.6.8</oval:product_version>
        <oval:schema_version>5.11</oval:schema_version>
        <oval:timestamp>2026-06-15T09:08:53</oval:timestamp>
      </oval-def:generator>
      <oval-def:definitions>
        <oval-def:definition class="inventory" id="oval:ssg-installed_app_is_firefox:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Mozilla Firefox</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:mozilla:firefox" source="CPE"/>
            <oval-def:description>The application installed on the system is firefox.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criterion comment="Firefox is installed" test_ref="oval:ssg-test_firefox:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_part_of_Unix_family:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Installed operating system is part of the Unix family</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>multi_platform_all</oval-def:platform>
              <oval-def:platform>Mozilla Firefox</oval-def:platform>
              <oval-def:product>Firefox</oval-def:product>
            </oval-def:affected>
            <oval-def:description>The operating system installed on the system is part of the Unix OS family</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_unix_family:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
      </oval-def:definitions>
      <oval-def:tests>
        <linux:rpminfo_test check="all" comment="Firefox is installed via RPM" id="oval:ssg-test_firefox:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_firefox:obj:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="Test installed OS is part of the unix family" id="oval:ssg-test_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_unix_family:ste:1"/>
        </ind:family_test>
      </oval-def:tests>
      <oval-def:objects>
        <linux:rpminfo_object id="oval:ssg-obj_firefox:obj:1" version="1">
          <linux:name>firefox</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-object_unix_family:obj:1" version="1"/>
      </oval-def:objects>
      <oval-def:states>
        <ind:family_state id="oval:ssg-state_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
      </oval-def:states>
    </oval-def:oval_definitions>
  </ds:component>
</ds:data-stream-collection>

Youez - 2016 - github.com/yon3zu
LinuXploit