Blacklisting all extensions ("*") via GPO overriding whitelist - "Blocked by administrator" |
|||||||||||
Issue description
Version: 53.0.2785.116 (Official Build) m (64-bit)
OS: Windows 2012 Server
Settings Active Directory GPO to blacklist all chrome browser extensions ("*") for users on a windows domain overrides the whitelist GPO. The intended behavior should be for the whitelisted extensions to override the blacklist all policy.
What steps will reproduce the problem?
(1) Download and install Chrome ADMX/L on windows server 2012
(2) Set "Configure extension installation blacklist" to *
(3) Set "Configure extension installation blacklist" to lhpbckonakppajdgicbjdfokagjofnob
(4) gpupdate /force
(5) make sure policy is visible in chrome://policy
(6) navigate to https://chrome.google.com/webstore/detail/visor/lhpbckonakppajdgicbjdfokagjofnob?hl=en
(7) try to manually install extension...
(8) Receive error message: "[Extension] is blocked by your administrator"
What is the expected output?
Since extension is whitelisted, user should be able to install the extension from the webstore manually, even though blacklist policy is set to *.
What do you see instead?
Extension is blocked by administrator error.
Reproducible: Yes
PII Protected Logs:
https://drive.google.com/drive/folders/0B6fESMmJITTNQzQ2VUg0Z2tiLW8?usp=sharing
Feedback submitted @ roughly 9:45 pm eastern - 10/11/2016
(Search feedback for "admin@yehudatest.com")
Note: filing this bug as a P1 due to potential impact to enterprise/edu customers.
,
Oct 12 2016
Enterprise customer noted that this issue is reproducible on Chrome Browser versions 51,52,and 53 (Windows)
,
Oct 12 2016
TYPO: In "what steps will reproduce the issue"... (3) Set "Configure extension installation blacklist" to lhpbckonakppajdgicbjdfokagjofnob should be: (3) Set "Configure extension installation whitelist" to lhpbckonakppajdgicbjdfokagjofnob
,
Oct 12 2016
,
Oct 12 2016
,
Oct 14 2016
Matt: This seems like a very bad bug. Can you triage this ?
,
Oct 14 2016
untriaged w/ owner -> assigned
,
Oct 17 2016
Krishna, can you see if we can reproduce this? If yes, we should see when this change went live and mark as p0.
,
Oct 17 2016
+ bustamante@ on repro and prioritize as M54 is already in stable for Desktop.
,
Oct 17 2016
,
Oct 18 2016
Per #2 this has been around since M51, if administrators have already adjusted to how the blacklist/whitelist rules work, changing that may have unintended consequences. I reached out to our test folks to work on repro'ing it.
,
Oct 18 2016
Making this is ReleaseBlock-Stable for M55 since it's been around for a while.
,
Oct 18 2016
Assigning to few folks who can try a repro from TE. Meanwhile requesting yyefet@ to try a bisect since you already have the system setup. Instructions for bisecting. https://sites.google.com/a/google.com/chrome-te/home/tools/bisect-builds
,
Oct 25 2016
I have quickly checked this on my Windows 10 machine with Chrome version 55.0.2883.21(x64) everything works correctly, below are the steps which I have followed : Steps Followed : (1) Download and install Chrome ADM on windows 10 (2) Set "Configure extension installation blacklist" to * (3) Set "Configure extension installation Whitelist" to lhpbckonakppajdgicbjdfokagjofnob (4) Exit and relaunch Chrome (5) Visit chrome://policy and make sure the policies has been set i.e., "ExtensionInstallBlacklist : * " and "ExtensionInstallWhitelist : lhpbckonakppajdgicbjdfokagjofnob" (6) navigate to https://chrome.google.com/webstore/detail/visor/lhpbckonakppajdgicbjdfokagjofnob?hl=en (7) try to manually install extension... Observed behavior : Able to install the the extension which is being whitelisted. Note : I am not sure it makes any difference w.r.t setting the policies on Windows 10 or Windows 2012 server and enforcing thtoughout the domain. Please correct me if I am wrong.
,
Oct 26 2016
**** Bulk edit - please ignore if not applicable **** A friendly reminder that M55 Stable is launch is coming soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch ASAP so it gets enough baking time in Beta (before Stable promotion). Thank you!
,
Oct 27 2016
Yehuda & Royans, Can you guys please confirm that this is an issue? I am removing release-block-stable and marking as 'wontfix' as Prudhvi was able to confirm that everything is WAI yesterday. Please re-open if you see other behavior. |
|||||||||||
►
Sign in to add a comment |
|||||||||||
Comment 1 by yye...@google.com
, Oct 12 2016