2.20 (L1) Ensure 'Allow Web Authentication requests on sites with broken TLS certificates' Is Disabled

Information

This policy setting controls the WebAuthn API and its interaction with sites that have a broken TLS certificate. It can be configured to either:

- Disabled (0): Do not allow WebAuthn API requests on sites with broken TLS certificates.
- Enabled (1): Allow WebAuthn API requests on sites with broken TLS certificates.

If the value for AllowWebAuthnWithBrokenTlsCerts is not changed from the default, it will behave as it is disabled.xempt.

Setting this policy will block the ability to authenticate to any website that does not have a valid TLS certificate since the identity of the site cannot be verified.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Allow Web Authentication requests on sites with broken TLS certificates.

Impact:

There should be no user impact.

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL, AWARENESS AND TRAINING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|AT-2, 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 99ef5392e0901f8f15d2ab5ed27bf06eb7e8782c37e4bbdd2205753e1e9427f4