SV-93393r1_rule
V-78687
SRG-APP-000175
TANS-SV-000020
CAT II
10
Request or regenerate the certificate being used to include both the "Server Authentication" and "Client Authentication" objects.
Access the Tanium Server interactively.
Log on with an account with administrative privileges to the server.
Navigate to Program Files >> Tanium >> Tanium Server.
Locate the SOAPServer.crt file.
Double-click on the file to open the certificate.
Select the "Details" tab.
Scroll down through the details to find and select the "Enhanced Key Usage" Field.
If there is no "Enhanced Key Usage" field, this is a finding.
In the bottom screen, verify "Server Authentication" and "Client Authentication" are both identified.
If "Server Authentication" and "Client Authentication" are not both identified, this is a finding.
V-78687
False
TANS-SV-000020
Access the Tanium Server interactively.
Log on with an account with administrative privileges to the server.
Navigate to Program Files >> Tanium >> Tanium Server.
Locate the SOAPServer.crt file.
Double-click on the file to open the certificate.
Select the "Details" tab.
Scroll down through the details to find and select the "Enhanced Key Usage" Field.
If there is no "Enhanced Key Usage" field, this is a finding.
In the bottom screen, verify "Server Authentication" and "Client Authentication" are both identified.
If "Server Authentication" and "Client Authentication" are not both identified, this is a finding.
M
3215