18.10.57.2 Ensure 'Turn on Basic feed authentication over HTTP' is set to 'Not configured' or 'Disabled' (STIG only)

Information

This policy setting allows users to have their feeds authenticated through the Basic authentication scheme over an unencrypted HTTP connection.

The recommended STIG state for this setting is: Not configured or Disabled

Basic authentication uses plain-text passwords that could be used to compromise a system. Disabling Basic authentication will reduce this potential.

Solution

To establish the recommended configuration via GP, set the following UI path to Not configured or Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\RSS Feeds\Turn on Basic feed authentication over HTTP

Note: This Group Policy path is provided by the Group Policy template InetRes.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

Plain-text passwords for RSS feeds over HTTP will not be allowed.

See Also

https://workbench.cisecurity.org/benchmarks/18857

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|14.4

Plugin: Windows

Control ID: 558ca425012a86d14e122738154f8603d5cb02fd334dff5d0ab49b0fa5a64499