2.23 Ensure 'Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store' Is Enabled

Information

This setting controls constraints encoded into trust anchors loaded from the platform trust store. It can be configured to either:

Disabled (0): Do not enforce constraints in locally added trust anchors

Enabled (1): Enforce constraints in locally added trust anchors

If the value for EnforceLocalAnchorConstraintsEnabled is not changed from the default, it will behave as if it is enabled.

Rationale:

Setting this policy will not allow access to any sites that do not enforce constraints.

Impact:

Enabling this might cause certain internal sites to not properly load until they are updated.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.

Default Value:

Unset (Enabled)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 11a4de30f1e5c0839525d42535fa57064c4bab77e51754e0eaf6aee2a18b9845