The Tanium Module server must be installed on a separate system.

From Tanium 6.5 Security Technical Implementation Guide

Part of SRG-APP-000211

Associated with: CCI-001082

SV-81579r1_rule The Tanium Module server must be installed on a separate system.

Vulnerability discussion

Unauthorized access to the Tanium Server is protected by disabling the Module Server service on the Tanium Server and by configuring the Module Server on a separate system. When X509 smartcard certificates (CAC or PIV tokens) are used for access to the Tanium Server, the Tanium Module server must be on a separate system.In order to restrict access to the Tanium Server resulting from an attack on the Module Server, it is recommended that the Tanium Module Server be installed on a separate system or VM from the Tanium Server. Adding to this recommendation, if the Tanium Server is configured to accept X509 Smartcard certificates (also referred to as CAC or PIV tokens) in lieu of username/password logon, the requirement becomes explicit and the Tanium Module Server must be installed on a separate system or VM.

Check content

Note: If the server being validated is the Module server, this check is Not Applicable. Access the Tanium Server interactively. Log on with an account with administrative privileges to the server. Click “Start” and access Server Manager. Select Local Server. Click "Tools". Select "Services". If the Tanium Module Server service is "Running", this is a finding.

Fix text

Access the Tanium Server interactively. Log on with an account with administrative privileges to the server. Click “Start” and access Server Manager. Select Local Server. Click "Tools" Select "Services". Disable the Tanium Module Server service.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer