2.20 Ensure 'Allow Web Authentication requests on sites with broken TLS certificates' Is Disabled

Information

This policy setting controls the WebAuthn API and its interaction with sites that have a broken TLS certificate. It can be configured to either:

Disabled (0): Do not allow WebAuthn API requests on sites with broken TLS certificates.

Enabled (1): Allow WebAuthn API requests on sites with broken TLS certificates.

If the value for AllowWebAuthnWithBrokenTlsCerts is not changed from the default, it will behave as it is disabled.xempt.

Rationale:

Setting this policy will block the ability to authenticate to any website that does not have a valid TLS certificate since the identity of the site cannot be verified.

Impact:

There should be no user impact.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Allow Web Authentication requests on sites with broken TLS certificates.

Default Value:

Unset (Disabled)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL, AWARENESS AND TRAINING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|AT-2, 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 99ef5392e0901f8f15d2ab5ed27bf06eb7e8782c37e4bbdd2205753e1e9427f4