SV-253839r997264_rule
V-253839
SRG-APP-000015
TANS-SV-000004
CAT II
10
Obtain the public key from the content providers and validate the keys are present in the Tanium folders.
If the public keys are found for nontrusted content providers, remove the associated signing key and remove any content imported by that provider.
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Open an Explorer window.
4. Navigate to the following folder: Program Files >> Tanium >> Tanium Server >> content_public_keys >> content folder.
5. Copy any trusted source's .pub keys into the folder and document them.
6. Remove any nontrusted source's .pub keys from the folder.
Note: If only using Tanium-provided content and not accepting content from any other content providers, this is not applicable.
Obtain documentation that contains the public key validation data from the Tanium system administrator.
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Open an Explorer window.
4. Navigate to the following folder: Program Files >> Tanium >> Tanium Server >> content_public_keys >> content folder.
If the Tanium default content-release.pub key is the only key in the folder, this is not a finding.
If documented content provider keys are in the content folder, this is not a finding.
If nondocumented content provider keys are in the content folder, this is a finding.
V-253839
False
TANS-SV-000004
Note: If only using Tanium-provided content and not accepting content from any other content providers, this is not applicable.
Obtain documentation that contains the public key validation data from the Tanium system administrator.
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Open an Explorer window.
4. Navigate to the following folder: Program Files >> Tanium >> Tanium Server >> content_public_keys >> content folder.
If the Tanium default content-release.pub key is the only key in the folder, this is not a finding.
If documented content provider keys are in the content folder, this is not a finding.
If nondocumented content provider keys are in the content folder, this is a finding.
M
5476