2.29 Ensure 'Insecure Hashes in TLS Handshakes Enabled' Is Disabled

Information

This setting controls the ability for Google Chrome to allow legacy or insecure hashes during the TLS handshake. It can be configured to either:

Disabled (0): Do Not Allow Insecure Hashes in TLS Handshakes

Enabled (1): Allow Insecure Hashes in TLS Handshakes

If the value for InsecureHashesInTLSHandshakesEnabled is not changed from the default, it will behave as if it is enabled.

Rationale:

Setting this policy to disabled will block Google Chrome from using insecure hashes. Using insecure, or legacy, hashes could allow sensitive data to be exposed.

Impact:

Users would be blocked from visiting sites that do not support more secure hashes.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Insecure Hashes in TLS Handshakes Enabled

Default Value:

Unset (Allow)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL, AWARENESS AND TRAINING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|AT-2, 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: ec5f75d79c86818455946a0ce451f0c155d2623a43b75520521186103b04fc5e