Mozilla工程師們一直積極支持TLS 1.3,并將之整合到了最新的Firefox 49中,同時還將移除掉默認安裝的 Hello 系統(tǒng)擴展,該計劃將從 v49 開始,也就是 9 月 13 日起。TLS 1.3是安全傳輸層協(xié)議的最新版本,是通過https連接網(wǎng)站的一個重要組成部分。該協(xié)議宣布于互聯(lián)網(wǎng)工程任務(wù)組開始著手草案的1月份,最終版本預(yù)計將在今夏正式制定為RFC。在協(xié)議成型的過程中,Mozilla工程師們從今年2月份就開始了在瀏覽器中集成支持的工作。
下載地址:
https://ftp.mozilla.org/pub/firefox/releases/49.0/
更新列表:
Updated Firefox Login Manager to allow HTTPS pages to used saved HTTP logins. It’s one more way Firefox is supporting Let’s Encryptand helping users transition to a more secure web.
Added features to Reader Mode that make it easier on the eyes and the ears
Controls that allow users to adjust the width and line spacing of text
Narrate, which reads the content of a page out loud
Improved video performance for users on systems that support SSSE3 without hardware acceleration
HTML5 audio and video improvements
Files can now be looped through the built-in controls in the context menu
Play audio and video at 1.25× speed through the context menu
Enhancements for Mac users
Improved performance on OS X systems without hardware acceleration
Improved appearance of anti-aliased OS X fonts
Reader Mode can now read articles out loud
Improved appearance of anti-aliased OS X fonts
Fixed
Fixed an issue that prevented users from updating Firefox for Mac unless they originally installed Firefox. Now, those users as well as any user with administrative credentials can update Firefox.
Changed
Ended Firefox for Mac support for OS X 10.6, 10.7, and 10.8.
Ended Firefox for Windows support for SSE processors
Removed Firefox Hello
Re-enabled the default for Graphite2 font shaping
Developer
Added a Cause columnto the Network Monitor to show what caused each network request
Introduced web speech synthesis API
Mozilla開發(fā)工程師David Keeler還宣布,將在Windows版的Firefox瀏覽器中修改根證書處理過程(Root Certificate Handling Procedures)。在Windows版的Firefox中瀏覽器擁有自主的證書存儲機制,這是同Windows系統(tǒng)證書存儲互相獨立的一套證書存儲機制,盡管安全性得到了進一步保障,但是在某些企業(yè)環(huán)境中,證書存儲數(shù)據(jù)的不同導(dǎo)致了使用火狐瀏覽器不能訪問一些私有網(wǎng)絡(luò)。
企業(yè)環(huán)境中由于IT管理員需要安裝根證書至Windows PC以訪問企業(yè)私有網(wǎng)絡(luò)或應(yīng)用,火狐瀏覽器采用的另一套證書存儲機制無法驗證一些私有根證書,就造成了用戶無法通過火狐瀏覽器訪問這些私有網(wǎng)絡(luò)。
現(xiàn)在這一情況終于將得到改善,Keeler稱從Firefox 49版本開始,如果遇到未知的CA證書,瀏覽器將會直接對正在使用的Windows系統(tǒng)證書存儲機制進行檢查對比。要激活此功能,用戶需要在地址欄鍵入
"access:config"
進入高級Firefox配置頁面,搜索并找到“security.enterprise_roots.enabled”項目
雙擊即可激活此功能。
用戶無法自主管理Firefox證書存儲中的所有CA證書,目前需要手動尋找Windows 系統(tǒng)根證書存儲中的對應(yīng)CA證書,這點可能在未來某個版本改變?yōu)橹苯幼詣铀阉鳌?/p>