9.4 Set 'Turn on Basic feed authentication over HTTP' to 'Not Configured'

Information



This policy setting allows users to have their feeds authenticated using the Basic
authentication scheme over an unencrypted HTTP connection.
If you enable this policy setting, the RSS Platform will authenticate to servers using the
Basic authentication scheme in combination with an insecure HTTP connection.
If you disable or do not configure this setting, the RSS Platform will not authenticate to
servers using the Basic authentication scheme in combination with an insecure HTTP
connection.
A developer cannot change this setting through the Feed APIs. The recommended state for
this setting is- Not Configured.

*Rationale*

Allowing basic authentication over HTTP for RSS feeds means that user credentials will be
transmitted in plain text, they could be intercepted en route by a malicious user and either
altered or copied.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Not Configured.

Computer Configuration\Administrative Templates\Windows Components\RSS Feeds\Turn on
Basic feed authentication over HTTP

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CSCv6|16.13, CSCv6|16.14

Plugin: Windows

Control ID: a2fc51a87dd618495c0e5531efc2e4464fd1342e5fae35598aeb3d0891a9f125