SV-234110r612749_rule
V-234110
SRG-APP-000416
TANS-SV-000044
CAT II
10
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: regedit <enter>.
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Add or modify the String "SSLCipherSuite" to have a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: "regedit".
Click "Enter".
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Verify the existence of a String "SSLCipherSuite" with a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
V-234110
False
TANS-SV-000044
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: "regedit".
Click "Enter".
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Verify the existence of a String "SSLCipherSuite" with a value of:
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
M
5259