2.4.1 Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate'

Information

Specifies which HTTP authentication schemes are supported by Google Chrome.

Disabled (0): Allows all supported authentication schemes.

The recommended state for this setting is: Enabled with the value of ntlm, negotiate

Rationale:

Possible values are 'basic', 'digest', 'ntlm' and 'negotiate'. Basic and Digest authentication do not provide sufficient security and can lead to submission of user passwords in plaintext or minimal protection (Integrated Authentication is supported for negotiate and ntlm challenges only).

Impact:

If some legacy application(s) or website(s) required insecure authentication mechanisms they will not work correctly.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: ntlm, negotiate:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\HTTP Authentication\Supported authentication schemes

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|16.5

Plugin: Windows

Control ID: f680915d71ede4bef4f2bbdb41a94e71c2db82ad5b96e74ac24558f85ed12041