2.27 (L1) Ensure 'Http Allowlist' Is Properly Configured

Information

This setting allows administrators to list specific sites that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled.

Note: Wildcards ( * [*] etc.) are not allowed in the URL listings.

Setting this policy allows organizations to maintain access to servers that do not support HTTPS without having to disable HTTPS-First mode or HTTPS Upgrades.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the approved URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\HTTP Allowlist

Impact:

This should not have an impact on the user.

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1), CSCv7|2.5

Plugin: Windows

Control ID: 92867da9dd74537483412aacc777614fc26b658844b76abcf2a562e2162a6ff3