SV-254946r962034_rule
V-254946
SRG-APP-000416
TANS-AP-001095
CAT II
10
1. Access the Tanium Server interactively.
2. Log on to the server with the tanadmin role.
3. Enter 2: Tanium Operations >> 2: Tanium Configuration Settings >> 1: Edit Tanium Server Settings.
4. Enter the number associated with key "SSLCipherSuite" to edit its value.
5. Add or modify the "SSLCipherSuite" key to have a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
1. Access the Tanium Server interactively.
2. Log on to the server with the tanadmin role.
3. Enter 2: Tanium Operations >> 2: Tanium Configuration Settings >> 1: Edit Tanium Server Settings.
4. Verify the existence of a "SSLCipherSuite" key with a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
V-254946
False
TANS-AP-001095
1. Access the Tanium Server interactively.
2. Log on to the server with the tanadmin role.
3. Enter 2: Tanium Operations >> 2: Tanium Configuration Settings >> 1: Edit Tanium Server Settings.
4. Verify the existence of a "SSLCipherSuite" key with a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
M
5492