Skip to content

Guide to the Secure Configuration of Chromium

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Enable Online OCSP/CRL Certificate Checks

    Certificates can become compromised, and Chromium should check that the certificates in its store are valid by setting <code>EnableOnlineRevocationChecks</code> to <code>true</code> in the Chromium...
    Rule Unknown Severity
  • Block Plugins by Default

    By default, websites are allowed to automatically run plugins. Users should be prompted to allow plugins to execute plugins by setting <code>DefaultPluginsSetting</code> to <code>3</code> in the Ch...
    Rule Unknown Severity
  • Enable the Default Search Provider

    By default users, can change search provider settings. To disable this, set DefaultSearchProviderEnabled to true in the Chromium policy file.
    Rule Unknown Severity
  • Set the Default Search Provider's URL

    Specifies the URL of the default search provider that is to be used. To set the URL of the default search provider, set <code>DefaultSearchProviderName</code> to <code><xccdf-1.2:sub idref="xccdf_o...
    Rule Unknown Severity
  • Disable the 3D Graphics APIs

    Chromium uses WebGL to render graphics using the GPU which allows website access to the GPU. This should be disabled by setting <code>Disable3DAPIs</code> to <code>true</code> in the Chromium polic...
    Rule Unknown Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules