5.3 Set 'Prevent ignoring certificate errors' to 'Enabled'

Information

*Description*

When a user experiences Secure Socket Layer/Transport Layer Security (SSL/TLS)
certificate errors such as 'expired,' 'revoked,' or 'name mismatch,' Internet Explorer
blocks the user's ability to continue browsing the Web site. The recommended state for this
setting is- Enabled.

*Rationale*

Users who ignore certificate errors are more likely to visit unauthorized sites or sites that
host malicious content.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Prevent ignoring certificate errors

Impact-If you enable this policy setting, the user is not permitted to continue browsing the Web
site. If you disable this policy setting or do not configure it, the user may elect to ignore
certificate errors and continue browsing the Web site.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(5)

Plugin: Windows

Control ID: 3332ae804735758c7f504bde71668c19dfc8789cd92254e5d800dabc11b8051d