Skip to main content

RequireOnlineRevocationChecksForLocalAnchors

Require online OCSP/CRL checks for local trust anchors - RequireOnlineRevocationChecksForLocalAnchors​

Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail).

Setting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.

On macOS, this policy has no effect if the ChromeRootStoreEnabled policy is set to False.

  • True = Perform revocation checks for successfully validated server certificates signed by locally installed CA certificates
  • False = Use existing online revocation-checking settings

Data Type:

Boolean

Supported features:

  • Dynamic Policy Refresh: True
  • Per Profile: False