2.9 Ensure 'Supported authentication schemes' is set to 'Enabled' (ntlm, negotiate)

Information

Specifies which HTTP authentication schemes are supported by Google Chrome.
Rationale:
Possible values are 'basic', 'digest', 'ntlm' and 'negotiate'. Basic and Digest authentication do not provide sufficient security and can lead to submission of users password in plaintext or minimal protection.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:(ntlm, negotiate).
Computer Configuration\Administrative Templates\Google\Google Chrome\Policies for HTTP Authentication\Supported authentication schemes
Default Value:
Enabled: basic, digest, ntlm, negotiate

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CSCv6|16.13, CSCv7|16.5

Plugin: Windows

Control ID: ac78d827776d23a5ab0da23406f8ceefcff4d0857e8f1f8356ee9e0dcc3aec24