1.11 Ensure 'Whether online OCSP/CRL checks are performed' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome offers to reactivate soft-fail, online revocation checks although they provide no effective security benefit.
Rationale:
An attacker may block OCSP traffic and cause revocation checks to pass in order to cause usage of soft-fail behavior. Furthermore, the browser may leak what website is being accessed and who accesses it to CA servers.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Whether online OCSP/CRL checks are performed
Impact:
If this setting is disabled, unsecure online OCSP/CRL checks are no longer performed.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2), CSCv7|7

Plugin: Windows

Control ID: db2ee0dcf64bea91e555180e1176c4964893974b16b433fb80e9e5d86932d48b