SV-234092r612749_rule
V-234092
SRG-APP-000175
TANS-SV-000020
CAT II
10
Request or regenerate the certificate being used to include both the "Server Authentication" and "Client Authentication" objects.
Access the Tanium Application server interactively.
Log on to the server with an account that has administrative privileges.
Navigate to Program Files >> Tanium >> Tanium Server.
Locate the "SOAPServer.crt" file.
Double-click on the file to open the certificate.
Select the "Details" tab.
Scroll down through the details to find and select the "Enhanced Key Usage" field.
If there is no "Enhanced Key Usage" field, this is a finding.
In the bottom screen, verify "Server Authentication" and "Client Authentication" are both identified.
If "Server Authentication" and "Client Authentication" are not both identified, this is a finding.
V-234092
False
TANS-SV-000020
Access the Tanium Application server interactively.
Log on to the server with an account that has administrative privileges.
Navigate to Program Files >> Tanium >> Tanium Server.
Locate the "SOAPServer.crt" file.
Double-click on the file to open the certificate.
Select the "Details" tab.
Scroll down through the details to find and select the "Enhanced Key Usage" field.
If there is no "Enhanced Key Usage" field, this is a finding.
In the bottom screen, verify "Server Authentication" and "Client Authentication" are both identified.
If "Server Authentication" and "Client Authentication" are not both identified, this is a finding.
M
5259