Web-Browser Configuration Wiki Page Notes
- Note_1 Read-Only public wiki page.
- Note_2 Read/Write OIT wiki page.
- Note_3 Move / Copy to a public wiki space.
- Note_4 Add-to, edit, and modify after suggested content is approved by OIT.
- Note_5 Please feel free to add content, and include references.
Introduction and Purpose.
The Web-Browser configuration OIT wiki page is designed to provide detailed information, and guidance regarding the configuration and usage of various web-browsers listed.
This is both a description of how-to configure, and a best practices guide for web-browsers. The information provided will enhance user knowledge of web-browsers configuration and operation with the goal of providing secure access to UCI 1, UCI-OIT 2, and UC 3 applications and web-sites.
1 UCI — University of California, Irvine.
2 UCI-OIT and OIT — Office of Information and Technology.
3 UC — University of California.
University of California, Irvine useful web-sites.
Web-Browser informational external web-site links.
Please refer to the following external web-sites for information pertaining to Web-Browser terminology, technologies, and detailed "how-to" instructions.
- Web-Browser history
- A list of past, and present web-browsers
- Mobile device Web-Browsers
- Web-Browser Markup Languages / Document Content
- Web-Browser interpretive languages
- Web-Browser Java Applets
- Web-Browser Protocol Definitions
- HTTP – http://
- HTTPS – https://
- FILE – file://hostname/pathname or file:///pathname
- FTP – ftp://user@hostname/URL — It is recommend that you not use this web-browser protocol as it is insecure.
- FTPS – ftps://user@hostname/URL
1 CCS is "Cascading Style Sheets"
2 Parent web-browser scripting language of the following languages — JavaScript, ActionScript, and JScript.
3 Ubiquitous and prevalently used of the common web-browser scripting languages.
4 Adobe corporation's specialized scripting language.
5 Microsoft corporation's Internet Explorer scripting language.
Web-Browser Configuration Guide
General Web-Browser Configuration Notes.
- Enable Pop-Window blocking. 1
- Selectivity allow web-sites to display Pop-Windows only if required for the application to function properly.
- Disable Java. 2
- Enable Java if the web-site and/or web application require Java Applets or other Java services.
- Once access to the web-site / application is completed then disable Java.
- Enable JavaScript.
- Selective display JavaScript if you are accessing a web-sites of unknown trust that are potential security risks.
- Use https when accessing UC, UCI, and UCI-OIT web-sites whenever possible.
- Always follow UCI and UC security policies — Security Wiki Pages
1 Web-browser Pop-Window information
2 Java Virtual Machine information
FireFox Web-Browser Configuration.
Start FireFox in order to configure the following user defined settings.
- Start FireFox web-browser application.
- If you have multiple FireFox user profiles defined then configuration of user defined setting is required for each profile defined. 1
- Open the FireFox options window.
- Windows and Linux Select Tools --> Options
- Mac Computers
- Select the FireFox application window to make the "active" application.
- Select FireFox --> Preferences OR Command key + ,
The FireFox options ("preferences") window appears, and the following user option sections are displayed.
Windows System – Open FireFox web-browser options window
- General – Configure the following general preferences. – General or Main Preferences Figure
- Set the "Startup home page display URL" 2 value.
- File download processing, and save to directory location.
- Plugin management and preferences.
- Tabs – Configure Tab browsing settings.
- Content preferences - Web-page content browser settings.
- Block pop-up windows.
- Enable blocking pop-up windows, and only allow selected application web-sites to open pop-up windows.
- Enable "Load images automatically."
- Enable JavaScript
- Enable JavaScript processing for web-sites, but if there is a doubt regarding the authenticity, functionality or trust-worthiness of a specific web-site then either disable JavaScript and proceed, or do not visit the web-site.
- Note OIT web applications utilize JavaScript in order to function correctly.
- Disable Java / Do not select: "Enable Java."
- Block pop-up windows.
- Security Preferences figure
- Enable – "Warn me when sites try to install add-ons."
- Enable – "Block reported attack sites."
- Enable – "Block reported web forgeries."
- Disable – "Remember passwords for sites."
- Disable – "Use a master password."
2 URL – Uniform Resource Locator
1 Creating and managing FireFox user profiles
- Mozilla FireFox Managing Profiles web-page
- Select the operating system type: (a) Windows (b) Linux (c) Mac OS
- Start the FireFox profile manager.
- Follow the instructions provided.
Microsoft Internet Explorer Web-Browser Configuration.
Internet Explorer Configuration
Internet Explorer requires a moderate amount configuration in order for UC, Irvine web applications to function correctly. The initial out of the box / as is installed configuration is insufficient; therefore, it is suggested that each Internet Explorer user follow the steps described within the IE web-configuration section.
IE Security Level Note
Enabling Mixed Web-page Content
Start Internet Explorer in order to configure the following user defined settings.
- Start Internet Explorer web-browser application.
- Select the Tools menu
- Open the Internet Options dialog preference window.
- Select the Security tab
- User Choice based on UCI, UC and UC web-site, and web applications accessed
- [Basic Security setting Medium High|Internet Options dialog preference window.
- Select the Custom level button to customize the Security Settings
- Suggested customized Security Settings
- (a) Select the Privacy tab (Default Privacy Settings Active)
- Set the privacy setting to Medium High
- (b) Select the Privacy tab (Customized Privacy Setting Active)
- Note the suggested Advanced Option tab settings. Carefully read and understand each of these settings and how they affect web-site, and web application functionality.
- Suggested Advanced Option Settings
Google Chrome Web-Browser Configuration.
Start Google Chrome Web-Browser
- Open the Chrome web-browser option's window by selecting the "tools icon", which is the icon in upper right hand corner following the URL input line that looks like a wrench / spanner.
- Refer to this figure How-to open Chrome's options window
- Select Options and the Google Chrome Options window appears.
- Basics settings – Basic options window
- Personal Stuff settings
- Ignore setting the Sync options.
- Select the "Never save passwords" option.
- Select the "Disable AutoFill" option.
-
- Select the Content settings button and configure the following.
- Cookies Preferences
- Select "Ask me when a site tries to set cookie data."
- Select "Block all third-party cookies without exception."
- Select "Clear cookies and other site data when I close my browser."
-
- Image Preferences.
- Select "Show all images."
- Image Preferences.
-
- JavaScript Preferences
- Select "Allow all sites to run JavaScript"
- Enable JavaScript processing for web-sites, but if there is a doubt regarding the authenticity, functionality or trust-worthiness of a specific web-site then either disable JavaScript and proceed, or do not visit the web-site.
- Note OIT web applications utilize JavaScript in order to function correctly.
-
- Plug-ins Preferences
- Select "Allow all sites to use plug-ins."
- For increased security – Select "Do not allow any sites to use plug-ins." And create a web-site exceptions list that includes web-sites that need to run plug-ins to function correctly.
-
- Pop-ups window preferences
- Select "Do not allow any site to show pop-ups." – (i.e. Pop-up Window)
-
- Location Tracking Preferences
- Select "Ask me when a site tries to track my physical location."
- or Select "Do not allow any site to track my physical location."
-
- Web services options.
- Enable – Show suggestions for navigation errors.
- Personal Choice – Use a suggestion service to help complete searches and URLs typed in the address bar. Disable this option if URL string completion interferes with an UCI, UCI OIT or UC applications functionality or if URL completion is not desired.
- Enable – Use DNS (i.e. Domain Name System or Server pre-fetching to improve page loading performance.
- Enable – Enable phishing and malware protection.
- Disable – Sending usage statistics and crash reports to Google.
- Web services options.
-
- Network
- Change Proxy Settings – In general there is no need to configure the proxy settings.
- Network
-
- Translate web-pages.
- Personal Choice – Offer to translate web-pages.
- Translate web-pages.
-
- Downloads
- Enable – Ask where to save each file before downloading.
- Downloads
-
- Web Content – Configure web-browser font and language settings.
-
- Security
- As needed – Select trusted SSL certificates – Manage certificates.
- Computer-wide SSL settings – Enable "Check for server certificate revocation."
- Security