2.4.1 Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Specifies which HTTP authentication schemes are supported by Google Chrome.

Disabled (0): Allows all supported authentication schemes.

The recommended state for this setting is: Enabled with the value of ntlm, negotiate

Rationale:

Possible values are 'basic', 'digest', 'ntlm' and 'negotiate'. Basic and Digest authentication do not provide sufficient security and can lead to submission of users password in plaintext or minimal protection (Integrated Authentication is supported for negotiate and ntlm challenges only).

Impact:

If some legacy application(s) or website(s) required insecure authentication mechanisms they will not work correctly.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: ntlm, negotiate:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\HTTP Authentication\Supported authentication schemes

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CSCv6|16.13, CSCv7|16.5

Plugin: Windows

Control ID: 4e643206e512d85633f6634f4afafa67617fa9c4e3dbb90e557e29ac62ca38f0