STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

Content providers must provide their public key to the Tanium administrator to import for validating signed content.

DISA Rule

SV-254879r960762_rule

Vulnerability Number

V-254879

Group Title

SRG-APP-000015

Rule Version

TANS-AP-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Note: If only using Tanium-provided content and not accepting content from any other content providers, this is Not Applicable.

Obtain documentation from the Tanium System Administrator that contains the public key validation data.

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "2" for "Tanium Operations Menu," and then press "Enter".

4. Press "5" for "Manage Custom Signing Keys," and then press "Enter".

5. Press "A" for "List Content Signing Keys," and then press "Enter".

6. Check the provided documentation and either update the document with the name and SHA-256 hash of the key or remove the key.

Check Contents

Note: If only using Tanium-provided content and not accepting content from any other content providers, this is Not Applicable.

Obtain documentation from the Tanium System Administrator that contains the public key validation data.

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "2" for "Tanium Operations Menu," and then press "Enter".

4. Press "5" for "Manage Custom Signing Keys," and then press "Enter".

5. Press "L" for "List Content Signing Keys," and then press "Enter".

If signing keys not listed in the provided documentation are present, this is a finding.

Vulnerability Number

V-254879

Documentable

False

Rule Version

TANS-AP-000050

Severity Override Guidance

Note: If only using Tanium-provided content and not accepting content from any other content providers, this is Not Applicable.

Obtain documentation from the Tanium System Administrator that contains the public key validation data.

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "2" for "Tanium Operations Menu," and then press "Enter".

4. Press "5" for "Manage Custom Signing Keys," and then press "Enter".

5. Press "L" for "List Content Signing Keys," and then press "Enter".

If signing keys not listed in the provided documentation are present, this is a finding.

Check Content Reference

M

Target Key

5492