1.15 Ensure 'Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities' is set to 'Disabled'

Information

Google Chrome allows to disable the enforcing of Certificate Transparency requirements for a list of Legacy Certificate Authorities.
Rationale:
Legacy Certificate Authorities shall follow the Certificate Transparency policy.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities
Impact:
If this setting is disabled, certificates not properly publicly disclosed as required by Certificate Transparency are untrusted.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: faa80c22b4ac87004577eae96b8d567928ddfc85c3f7f7948607f0f39f228b7f