2.23 (L2) Ensure 'Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store' Is Enabled

Information

This setting controls constraints encoded into trust anchors loaded from the platform trust store. It can be configured to either:

- Disabled (0): Do not enforce constraints in locally added trust anchors
- Enabled (1): Enforce constraints in locally added trust anchors

If the value for EnforceLocalAnchorConstraintsEnabled is not changed from the default, it will behave as if it is enabled.

Setting this policy will not allow access to any sites that do not enforce constraints.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.

Impact:

Enabling this might cause certain internal sites to not properly load until they are updated.

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Windows

Control ID: 94173f2ad0058beb46ced49b09f03b77387736adbd1f1edaf1d9ba468db42ca1