UCF STIG Viewer Logo

Extensions that are approved for use must be whitelisted


Overview

Finding ID Version Rule ID IA Controls Severity
V-0006 DTBC-0006 SV-0006r1_rule Medium
Description
Allows you to specify which extensions are not subject to the blacklist. A blacklist value of * means all extensions are blacklisted and users can only install extensions listed in the whitelist. By default, no extensions are whitelisted. If all extensions have been blacklisted by policy, then the whitelist policy can be used to allow specific extensions to be installed. Administrators should determine which extensions should be allowed to be installed by their users. If no extensions are whitelisted, then no extensions can be installed when combined with blacklisting all extensions.
STIG Date
Google Chrome STIG Draft 2012-09-25

Details

Check Text ( C-0006r1_chk )
Universal method (Requires Chrome Browser v15 or later):
1. In the omnibox (address bar) type chrome://policy
2. If ExtensionInstallWhitelist is displayed under the Policy Name column and it is set to oiigbmnaadbkfbmpbfijlflahbdbdgd or a list of administrator approved extension IDs, then this is not a finding.

Windows method:
1. Start regedit
2. Navigate to HKLM\Software\Policies\Google\Chrome\ExtensionInstallWhitelist
3. If the ExtensionInstallWhitelist key does not exist or is not set to oiigbmnaadbkfbmpbfijlflahbdbdgd or a list of administrator approved extension IDs, then this is a finding.
Fix Text (F-0006r1_fix)

Valid for Chrome Browser version 8 or later.

Windows registry:
Key Path: HKLM\Software\Policies\Google\Chrome\ExtensionInstallWhitelist
Value Name:
Value Type: String (REG_SZ)
Value Data: oiigbmnaadbkfbmpbfijlflahbdbdgd

Windows group policy:
Policy Path: Computer Configuration\Administrative Templates\Google\Google Chrome\Extensions\
Policy Name: Configure extension installation whitelist
Policy State: Enabled
Policy Value: oiigbmnaadbkfbmpbfijlflahbdbdgd

Note: oiigbmnaadbkfbmpbfijlflahbdbdgd is the ID for scriptno