SV-253877r997299_rule
V-253877
SRG-APP-000439
TANS-SV-000107
CAT I
10
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to: HKEY_LOCAL_MACHINE >> Software >> Wow6432Node >> Tanium >> Tanium Server.
5. Right-click in the right window pane.
6. Select: New >> String Value.
7. In the "Name" field, enter "SSLCipherSuite".
8. Press "Enter".
9. Right-click the newly created "Name".
10. Select "Modify".
11. Add the following: ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
12. Click "OK".
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to: HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Name: SSLCipherSuite
Type: String
Value:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
V-253877
False
TANS-SV-000107
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to: HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Name: SSLCipherSuite
Type: String
Value:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
M
5476