2.27 Ensure 'Http Allowlist' Is Properly Configured

Information

This setting allows administrators to list specific sites that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled.

Note: Wildcards (*, [*], etc.) are not allowed in the URL listings.

Rationale:

Setting this policy allows organizations to maintain access to servers that do not support HTTPS without having to disable HTTPS-First mode or HTTPS Upgrades.

Impact:

This should not have an impact on the user.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the approved URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\HTTP Allowlist

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1), CSCv7|2.5

Plugin: Windows

Control ID: 92867da9dd74537483412aacc777614fc26b658844b76abcf2a562e2162a6ff3