Microsoft KB Archive/300443

= A Description of the Changes to the Security Settings of the Web Content Zones in Internet Explorer 6 =

Article ID: 300443

Article Last Modified on 7/27/2007

-

APPLIES TO


 * Microsoft Internet Explorer 6.0
 * Microsoft Internet Explorer 6.0
 * Microsoft Internet Explorer 6.0
 * Microsoft Internet Explorer 6.0
 * Microsoft Internet Explorer 6.0
 * Microsoft Internet Explorer 6.0

-



This article was previously published under Q300443





SUMMARY
This article describes the changes to the security settings for the Web content zones in Internet Explorer 6.



MORE INFORMATION
Unless an exception is listed in the following sections, your current security settings are retained when you upgrade to Internet Explorer 6. However, the security level for all zones is set to Custom.

For additional information about your security level being set to Custom, click the article number below to view the article in the Microsoft Knowledge Base:

300891 Custom Security Zones After Upgrading to Internet Explorer 6

If you click Default Level for any zone on the Security tab of the Internet Options dialog box, you can apply the new default settings.

Changes to All Zones Settings
When you click Custom Level on the Security tab of the Internet Options dialog box in Internet Explorer 6, the following settings have been removed from the Security Settings section:  The Cookies settings have been moved from the Security tab to the Privacy tab. These settings are not retained when you upgrade to Internet Explorer 6.For additional information about cookie settings, click the article numbers below to view the articles in the Microsoft Knowledge Base:

296363 Cookies Settings Are Not Retained After You Upgrade to Internet Explorer 6

283185 How to Manage Cookies in Internet Explorer 6

 The settings that are located under the Microsoft VM heading, which contains the &quot;Java permissions&quot; subheading, are not present if the Microsoft virtual machine (Microsoft VM) is not installed. If the Microsoft VM is installed as a stand-alone package or by means of &quot;install on demand&quot;, these settings are added back.

The following new settings have been added to the Security Settings section when you click Custom Level on the Security tab of the Internet Options dialog box in Internet Explorer 6:  Under the Miscellaneous heading, the &quot;Don't prompt for client certificate selection when no certificate or only one certificate exists&quot; setting is set to Disable for all security levels, except for the Low security level (by default, only the &quot;Trusted sites&quot; zone has a Low security level).

The preceding setting had been added to Internet Explorer 5.5 Service Pack 1 (SP1). When this setting is set to Disable, Internet Explorer does not prompt you with a &quot;Client Authentication&quot; message when you connect to a Web site that has no certificate or only one certificate. The versions of Internet Explorer prior to version 5.5 SP1 display the following &quot;Client Authentication&quot; message even if the Web site does not have a certificate or has only one certificate:

Identification

The Web site you want to view requests identification. Select the certificate to use when connecting.

 Under the Miscellaneous heading, the &quot;Allow Meta Refresh&quot; setting is set to Enable for all security levels (except for the High security level) and the Meta Refresh setting continues to work as it did in previous versions of Internet Explorer. At the High security level (by default, only the &quot;Restricted sites&quot; zone has a High security level), the &quot;Allow Meta Refresh&quot; setting is set to Disable and the Meta Refresh setting does not work.

The Meta Refresh setting (tag) enables the author of a Web page to redirect your browser to another Web page after a specified amount of time. For additional information about the Meta Refresh setting, refer to the following Microsoft Web site:

http://msdn2.microsoft.com/en-us/library/Aa769236.aspx

NOTE: This setting does not function in the Internet Explorer 6 Public Preview (Version 6.00.2462.0000). This problem was first corrected in the Internet Explorer 6 Public Preview Refresh (Version 6.00.2479.0006). Under the Miscellaneous heading, the &quot;Display mixed content&quot; setting is set to Prompt (which is the same behavior as previous versions of Internet Explorer) for all security levels, and you may receive the following &quot;Security Information&quot; message on the Web pages that contain both secure (https://) and nonsecure (http://) content:

This page contains both secure and nonsecure items.

Do you want to display the nonsecure items?

If the &quot;Display mixed content&quot; setting is set to Enable, you cannot receive the preceding message and nonsecure content can be displayed. If the &quot;Display mixed content&quot; setting is set to Disable, you cannot receive the preceding message and nonsecure content cannot be displayed.</li></ul>

Changes to Restricted sites Zone Settings
The following &quot;Restricted sites&quot; zone settings have been changed:
 * The Active Scripting setting is set to Disable, and your previous setting is not retained.
 * The Java Permissions setting, which is located under the Microsoft VM heading, is set to Disable Java, and your previous setting is not retained.
 * The &quot;Script ActiveX Controls marked as safe for scripting&quot; setting is set to Disabled, but your previous setting is retained.
 * The &quot;Allow Meta Refresh&quot; setting is set to Disabled.

NOTE: By default, the &quot;Restricted sites&quot; zone is used by Microsoft Outlook Express 6, and can be used by Microsoft Outlook to restrict active content in Hypertext Markup Language (HTML) e-mail messages.

For additional information, click the article number below to view the article in the Microsoft Knowledge Base:

182569 Description of Internet Explorer Security Zones Registry Entries

Additional query words: Urlmon.dll, Inetcpl.cpl IE6Setup

Keywords: kbenv kbinfo KB300443

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.