1.5 Ensure 'Enable HTTP/0.9 support on non-default ports' is set to 'Disabled'

Information

Non-HTTP services' responses may be read via XHR as their response streams will be interpreted by Chrome as HTTP/0.9. This setting allows to enable HTTP/0.9 on ports other than 80 for HTTP and 443 for HTTPS.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:


Computer Configuration\Administrative Templates\Google\Google Chrome\Enable HTTP/0.9 support on non-default ports


Impact:
If this setting is disabled, HTTP/0.9 will be disabled on non-default ports 80/443.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|9.2

Plugin: Windows

Control ID: 7598d54cceb47b6b79d70569b249450f2c6e3fe314016088b7215633200913c1