SV-93545r1_rule
V-78839
SRG-APP-000416
TANS-SV-000044
CAT II
10
Access the Tanium Server interactively.
Log on with an account with administrative privileges to the server.
Access the server's registry by typing: regedit <enter>.
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Add or modify the String "SSLCipherSuite" to have a value of:
AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-CCM:AES128-CCM:AES256- CCM8:AES128-CCM8:AES256-SHA256:AES128- SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3- SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
Access the Tanium Server interactively.
Log on with an account with administrative privileges to the server.
Access the server's registry by typing: "regedit".
Click "Enter".
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Verify the existence of a String "SSLCipherSuite" with a value of:
AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-CCM:AES128-CCM:AES256- CCM8:AES128-CCM8:AES256-SHA256:AES128- SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3- SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
V-78839
False
TANS-SV-000044
Access the Tanium Server interactively.
Log on with an account with administrative privileges to the server.
Access the server's registry by typing: "regedit".
Click "Enter".
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Verify the existence of a String "SSLCipherSuite" with a value of:
AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-CCM:AES128-CCM:AES256- CCM8:AES128-CCM8:AES256-SHA256:AES128- SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3- SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
If the String "SSLCipherSuite" does not exist with the appropriate list values, this is a finding.
M
3215