2.64 (L1) Ensure 'Enable post-quantum key agreement TLS' Is Set to 'Enabled'

Information

This configures whether Google Chrome will offer a post-quantum key agreement algorithm in TLS, using the ML-KEM NIST standard, and will protect user traffic from quantum computers when communicating with compatible servers. Enabling a post-quantum key agreement is backwards compatible, so there will be no issue with existing TLS servers.

This will protect user traffic from quantum computer decrypting.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Administrative Templates\Google\Google Chrome\Enable deleting browser and download history

Impact:

There should be no impact on the user

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: 23f54af7496111356ec73106f1fc6bed330240039c65447e416c5bc669b4254e