commoncriteria / webbrowser

Protection Profile for Web Browsers
The Unlicense
1 stars 0 forks source link

ensure selection only includes sign-able mobile code types #14

Closed jeffblank closed 9 years ago

jeffblank commented 9 years ago

This is in FPT_MCD_EXT.1 Mobile Code

japit commented 9 years ago

ActiveX, Flash, and Java are appropriate selections.

In IE configure ActiveX under Tools - Internet Options - Security - Internet - Custom level - Selections are: "Download signed Active X Controls" and "Download unsigned ActiveX controls". Both have Disable/Enable/Prompt options.