18.10.58.2 (L1) Ensure 'Turn on Basic feed authentication over HTTP' is set to 'Disabled'

Information

This policy setting controls whether RSS feeds can be authenticated using the Basic authentication scheme over an unencrypted HTTP connection.

A developer cannot change this setting through the Feed APIs.

The recommended state for this setting is: Disabled

Allowing RSS feeds to use Basic authentication over HTTP will transmit user credentials in plain text, where they could be intercepted en route by a malicious user.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Administrative Templates\Windows Components\RSS Feeds\Turn on Basic feed authentication over HTTP

Note: This Group Policy path is provided by the Group Policy template InetRes.admx/adml that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 9398ce025566397c8402cdbbb5d86b8b4e7ddc7f1d9239a7c2c5a198fcc83eff