SV-234132r612749_rule
V-234132
SRG-APP-000439
TANS-SV-000107
CAT II
10
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: "regedit".
Press "Enter".
Navigate to: HKEY_LOCAL_MACHINE >> Software >> Wow6432Node >> Tanium >> Tanium Server.
Right-click in the right window pane.
Select: New >> String Value.
In the "Name" field, enter "SSLCipherSuite".
Press "Enter".
Right-click on the newly created "Name".
Select "Modify...".
Add the following: ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
Click "OK".
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: "regedit".
Press "Enter".
Navigate to: HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Name: SSLCipherSuite
Type: String
Value:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
V-234132
False
TANS-SV-000107
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Access the server's registry by typing: "regedit".
Press "Enter".
Navigate to: HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Name: SSLCipherSuite
Type: String
Value:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSAAES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
M
5259