Tanium™ Appliance Deployment Guide
Total Page:16
File Type:pdf, Size:1020Kb
Tanium™ Appliance Deployment Guide Version 1.5.6 June 06, 2020 The information in this document is subject to change without notice. Further, the information provided in this document is provided “as is” and is believed to be accurate, but is presented without any warranty of any kind, express or implied, except as provided in Tanium’s customer sales terms and conditions. Unless so otherwise provided, Tanium assumes no liability whatsoever, and in no event shall Tanium or its suppliers be liable for any indirect, special, consequential, or incidental damages, including without limitation, lost profits or loss or damage to data arising out of the use or inability to use this document, even if Tanium Inc. has been advised of the possibility of such damages. Any IP addresses used in this document are not intended to be actual addresses. Any examples, command display output, network topology diagrams, and other figures included in this document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental. Please visit https://docs.tanium.com for the most current Tanium product documentation. This documentation may provide access to or information about content, products (including hardware and software), and services provided by third parties (“Third Party Items”). With respect to such Third Party Items, Tanium Inc. and its affiliates (i) are not responsible for such items, and expressly disclaim all warranties and liability of any kind related to such Third Party Items and (ii) will not be responsible for any loss, costs, or damages incurred due to your access to or use of such Third Party Items unless expressly set forth otherwise in an applicable agreement between you and Tanium. Further, this documentation does not require or contemplate the use of or combination with Tanium products with any particular Third Party Items and neither Tanium nor its affiliates shall have any responsibility for any infringement of intellectual property rights caused by any such combination. You, and not Tanium, are responsible for determining that any combination of Third Party Items with Tanium products is appropriate and will not cause infringement of any third party intellectual property rights. Tanium is committed to the highest accessibility standards to make interaction with Tanium software more intuitive and to accelerate the time to success. To ensure high accessibility standards, Tanium complies with the U.S. Federal regulations - specifically Section 508 of the Rehabilitation Act of 1998. We have conducted third-party accessibility assessments over the course of product development for many years, and most recently a comprehensive audit against the WCAG 2.1 / VPAT 2.3 standards for all major product modules was completed in September 2019. Tanium can make available any VPAT reports on a module-by-module basis as part of a larger solution planning process for any customer or prospect. © 2020 Tanium Inc. All Rights Reserved Page 2 As new products and features are continuously delivered, Tanium will conduct testing to identify potential gaps in compliance with accessibility guidelines. Tanium is committed to making best efforts to address any gaps quickly, as is feasible, given the severity of the issue and scope of the changes. These objectives are factored into the ongoing delivery schedule of features and releases with our existing resources. Tanium welcomes customer input on making solutions accessible based on your Tanium modules and assistive technology requirements. Accessibility requirements are important to the Tanium customer community and we are committed to prioritizing these compliance efforts as part of our overall product roadmap. Tanium maintains transparency on our progress and milestones and welcomes any further questions or discussion around this work. Contact your TAM, sales representative, or email [email protected] to make further inquiries. Tanium is a trademark of Tanium, Inc. in the U.S. and other countries. Third-party trademarks mentioned are the property of their respective owners. © 2020 Tanium Inc. All rights reserved. © 2020 Tanium Inc. All Rights Reserved Page 3 Table of contents Tanium Appliance overview 20 Tanium Infrastructure types 20 Appliance roles 21 Topology 21 TanOS menus 22 TanOS Flexible Menu Search 22 Requirements 25 License 25 SSL certificates 25 Network connectivity and firewall 25 Internet access (direct or by proxy) 27 Proxies 27 Airgap 27 Getting started 28 Completing the initial setup (hardware appliances) 29 Requirements 29 Configure temporary bootstrap network settings 29 Before you begin 29 Configure the temporary settings 29 Remote access to TanOS 30 Configure network and host settings 30 Configure user access 31 Before you begin 32 © 2020 Tanium Inc. All Rights Reserved Page 4 Change the default passwords 32 Add SSH keys 32 Add SSH keys for the tancopy user 32 Add SSH keys for TanOS users 36 Upload the license file 37 Before you begin 37 Tanium Core Platform 7.4 or later 38 Tanium Core Platform 7.3 or earlier 38 Export the RAID controller security key 39 Export the grub key 41 Add TanOS system users 41 What to do next 42 Completing the initial setup (virtual appliances) 43 Requirements 43 Deploy the virtual image to the hypervisor 43 (Optional) Configure temporary bootstrap network settings 46 Before you begin 46 Configure the temporary settings 46 Remote access to TanOS 47 Configure network and host settings 47 Configure user access 48 Before you begin 48 Change the default passwords 49 Add SSH keys 49 Add SSH keys for the tancopy user 49 © 2020 Tanium Inc. All Rights Reserved Page 5 Add SSH keys for TanOS users 52 Upload the license file 53 Before you begin 53 Tanium Core Platform 7.4 or later 54 Tanium Core Platform 7.3 or earlier 54 Export the grub key 55 Add TanOS system users 55 What to do next 56 Installing a Tanium All-in-One role 57 Before you begin 57 Install the Tanium Server All-in-One role 58 What to do next 58 Installing Tanium Server 59 Before you begin 59 Import keys (optional) 59 Install Tanium Server 60 Set up TLS for the Tanium Server deployment 60 Tanium Core Platform version 7.3 or prior 60 Tanium Core Platform version 7.4 or later 60 What to do next 61 Installing Tanium Module Server 62 Before you begin 62 Install the Tanium Module Server 62 Configure the Tanium Server to use the remote Module Server 63 Enable the remote Module Server 63 © 2020 Tanium Inc. All Rights Reserved Page 6 What to do next 63 Installing Tanium Zone Server 64 Overview 64 Before you begin 65 Install the Tanium Zone Server 65 Install the Zone Server 65 Import the Tanium Server public key file to the Zone Server 65 Import tanium.pub for Tanium Core Platform 7.3 and earlier 66 Import tanium-init.dat for Tanium Core Platform 7.4 and later 68 Install the Zone Server hub 69 Set up AllowedHubs on the Zone Server appliance 69 Configure trust mappings for 7.4 and later 70 Approve trust for the Zone Server Hub 70 Map the Zone Server to the Zone Server Hub 71 Set up TLS for the Tanium Zone Server 7.3 and earlier 73 Verifying the deployment 75 Log into the Tanium Console 75 Deploy the Tanium Client to your lab computers 76 Verify the basic deployment 76 Verify the Zone Server deployment 77 Installing Tanium Server in a redundant cluster 80 Overview 80 Redundant cluster requirements and limitations 81 Before you begin 82 Add required SSH keys 82 © 2020 Tanium Inc. All Rights Reserved Page 7 Set up the IPsec tunnel 83 Deploy the cluster 84 Verify the installation 85 Deploying a standby Module Server 88 About the standby Module Server 88 Requirements and limitations 88 Before you begin 88 Set up the IPsec tunnel 89 Configure Sync 90 Perform a manual sync 90 Schedule sync jobs 91 Display detailed status for Module Server sync 91 Upgrading Tanium Appliance software 92 About Tanium Appliance software versions 92 Upgrade TanOS 92 Upgrade path 93 Upgrade from TanOS 1.5.x 93 Upgrade from TanOS 1.4.x 94 Upgrade from TanOS 1.3.x 95 Upgrade the TanOS shell 95 Upgrade path 95 Upgrade the TanOS shell 95 Upgrade Tanium server software 96 Upgrade path 96 Before you begin 96 © 2020 Tanium Inc. All Rights Reserved Page 8 Order of upgrade 97 Upgrade the server software 97 What to do next 97 Troubleshooting the installation 98 Display version information 98 Run the Health Check 98 Restart services or networking 98 Restart services 99 Restart networking 99 Review Tanium core platform logs 99 Review Tanium solution module logs 99 Review the configuration 100 Run Tanium Support Gatherer 100 Examine OS processes and files 101 Open read-only restricted shell 101 Request read-write restricted shell or full shell access 102 Perform a TanOS reset (software/factory) 103 Reference: Tanium Operations menu 105 Start, stop, and restart Tanium services 105 Change a Tanium server configuration 105 Edit server settings 106 Add an authentication user for TDownloader 106 Add an authentication certificate for TDownloader 106 Manage authentication certificates for Tanium Patch connections with RedHat 107 Edit zone server list 107 © 2020 Tanium Inc. All Rights Reserved Page 9 Edit zone server isolated subnets list 107 Change a Tanium component server port 108 Install a custom SOAP certificate 108 Upload the CA certificate file 109 Install the SOAP certificate file 111 Enable import of user-created content 111 Manage content signing keys 112 Download the Tanium Server public key file 113 Download the Tanium Server SOAP certificate 113 Import the Tanium public/private