#1006558 /usr/bin/firefox: with TLS 1.3 disabled in the config settings, firefox still connects to websites with TLS 1.3

Package:
firefox-esr
Source:
firefox-esr
Description:
Mozilla Firefox web browser - Extended Support Release (ESR)
Submitter:
ryan
Date:
2022-03-20 21:30:02 UTC
Severity:
normal
#1006558#5
Date:
2022-02-27 20:09:51 UTC
From:
To:
Dear Maintainer,


In Firefox, suppose I go to about:config and set

security.tls.version.max = 3

which disables TLS 1.3 and leaves TLS 1.2 as the highest security setting.  If I check the browser at ssllabs.com, it confirms TLS 1.2 is the highest available protocol and lists the appropriate cipher suites.  Yet, a number of websites (e.g. Google, Facebook, Youtube) connect with TLS 1.3 and a new cipher suite; at least, that is what I learn when I click on the lockbox in the address bar.  What is going on?

I have toggled

security.tls.version.fallback-limit

between 3 and 4, but it does not seem to make any difference.  Also, how does a person choose the cipher suites for TLS 1.3?  They do not seem to be listed under

security.ssl3

in the about:config settings.

#1006558#10
Date:
2022-03-20 21:27:36 UTC
From:
To:
Hello.  I am checking in on things.  I filed a bug report three weeks ago and have not heard back from anyone yet.  Thanks.