STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium Server certificate must be signed by a DOD Certificate Authority.

DISA Rule

SV-254947r961596_rule

Vulnerability Number

V-254947

Group Title

SRG-APP-000427

Rule Version

TANS-AP-001130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Request or regenerate the certificate from a DOD Root Certificate Authority.

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. When connected, review the Certificate for the Tanium Server.

3. In the web browser, view the presented Certificate and verify that the Certificate shows as issued by a DOD Root CA. Also verify that the Certification path's top-level is a DOD Root CA.

4. If the certificate authority is not DOD Root CA, this is a finding.

Vulnerability Number

V-254947

Documentable

False

Rule Version

TANS-AP-001130

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. When connected, review the Certificate for the Tanium Server.

3. In the web browser, view the presented Certificate and verify that the Certificate shows as issued by a DOD Root CA. Also verify that the Certification path's top-level is a DOD Root CA.

4. If the certificate authority is not DOD Root CA, this is a finding.

Check Content Reference

M

Target Key

5492