1.17 Ensure 'Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes' is set to 'Disabled'

Information

Google Chrome allows to exclude certificates by their subjectPublicKeyInfo hashes from enforcing Certificate Transparency requirements.
Rationale:
Certificate Transparency requirements shall be enforced for all certificates.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes
Impact:
If this setting is disabled, no certificates are excluded from Certificate Transparency requirements.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: f6eeea4b574842bbd5f7a609be328c684cb6358f953ba8c593a8e80bcc45ab2c