IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Release Notes Tanium Server (Version 7.8.1.3090)

From Tanium Knowledge Base
Jump to navigation Jump to search

Thank you for choosing Tanium. The following Release Notes document changes between releases of the Tanium Server.
This platform release includes the release of both a Windows and Linux Tanium Server.
The previous version can be found here: Release Notes Tanium Server (Version 7.7.3.8199)


Tanium Server for Windows and Linux v7.8.1.3090

  • Tanium Cloud availability date: July 15, 2025.
  • On-premises availability date: N/A.

Highlights

  • The Tanium Server now implements CDN / CPMS protocol version 2, allowing for global usage of CDN Downloads for all customers.
  • The Tanium Server now implements many of the functions of the System User Service, allowing migration of modules from usage of SUS to native Platform functionality.
  • The Tanium Server now implements the initial Endpoint Expansion functionality allowing non-Client based management of additional devices.

Special Notes

Security Updates

  • N/A.

New Features

  • The Tanium Server now allows XML solution imports to declare service_account entries to be created in the new Platform System User Service.
  • The Tanium Server now supports a specific "verify signature" privilege.
  • Removes the unused SOCKS proxy support from TDownloader.
  • Adds the ability to request batches of user IDs from the Tanium Server users API.
  • The Tanium Server will now keep an audit record of changes to sensor implementations.
  • The Tanium Server session/current API will now return the time of expiration for the API token being used for the request.
  • The Tanium Server now supports the sensors/<id>/versions, sensors/versions and sensors/<id>/version_history routes to support operations on sensor versions.
  • Upon installation the Tanium Module Server will generate new System User Service root keys if none exist yet.
  • The Tanium Server implements new metrics that track its successes and failures when connecting to a Module Server.
  • The Tanium Server users API will not allow modifications of system user accounts.
  • The Tanium Server now disallows changing the names of the "Reserved", "Default" and "Default Filter Groups" content sets.
  • The Tanium Server now supports proxying http2 requests to the Module Server gRPC API.
  • The Tanium Server API will route gRPC requests according to the package name in the service requested and directly handle requests labeled with tanium_server.
  • Adds support for ZIP file splitting and recombination to the TaniumExtractor command line utility.

Improvements

  • Tanium Platform components now ship with OpenSSL v3.4.1.
  • Tanium Platform components now ship with Python v3.12.11.
  • Updates the OpenSSL FIPS version used in platform components to v3.1.2.
  • Modifies the Tanium Server action API to ensure that timestamped fields display a UTC timezone format.
  • The maximum backoff value for the Tanium Server to retry repeated file downloads has been changed from 12 hours to 4 hours in order to improve the chances of a successful downloads for URLs which fail often.
  • The Tanium Server now allows SCIM-sourced users and groups to be matched to already existing local users instead of deleting them, which had ownership consequences over existing content objects.
  • Changes the internal definition of question select specs in the Tanium Server to accommodate different versions of the same sensor.
  • Implements the GET:api/v2/sensors/<ID>/dependents/<VERSION> REST API in the Tanium Server.
  • The Tanium Server now supports a different hashing algorithm to identify package file chunks as well as a larger size for them for increased download efficiency.
  • The Tanium Server output for group audit records will now include information about the type of each group reported as "Computer Group", "Filter Group" or "Managements Right Group".
  • Adapts the way in which the Tanium Server resolves versioned sensor references in order to be able to remove old objects no longer in use.
  • The Tanium Server will no longer allow registering duplicate whitelisted URLs.
  • The Tanium Server changes the database persistence of non-counting questions to use the force_computer_id_flag instead of adding an empty select specification to them.
  • Implements the logic needed to update sensor versions in the Tanium Server when they are updated by an API request.
  • Adds sensor versioning information to the Tanium Server solution import and export representations.
  • Incorporates the use of version information in the Tanium Server SOAPSensorCache to support the new sensor versioning functionality.
  • TDownloader will now log information about the certificate chosen for authentication when downloading a URL that uses this configuration. This helps troubleshoot client-side-certificate configurations.
  • Improves the performance of the Tanium Server download catalog cleaner which could keep Packages in a "Pending" state while it was running.
  • Adds a safeguard to the Tanium Server APIs to detect the incorrect uppercase use of "ID" and "NAME" elements in target_group, preventing the undesired behavior of targeting all computers.
  • The TDownloader utility now calculates the file hash of a downloaded file while it is streaming, which is more efficient than doing it from its contents on disk after the download.
  • Changes the internal definition of filter specs in the Tanium Server to accommodate different versions of the same sensor.
  • The Tanium Server groups API now supports using the "summary" option which will return a select set of properties for each group instead of their full definition.
  • Implements the functionality needed for the Tanium Server to inform clients about sensor versions during registration.
  • The Tanium Server APIs now disallow modifications to deleted objects that do not support being un-deleted.
  • Refactors the organization of the file chunk cache to accommodate new download types with variable chunk sizes.
  • The Tanium Server will now issue a log a message in its authentication log when an API token is used from a non-authorized IP address source as dictated by the token's configuration settings.
  • Adds role names to content set audit records emitted by the Tanium Server, making these records easier to interpret.
  • Ensure that question select specs serialize the sensor versions they are using.
  • Ensures that newer Tanium Clients do not peer with older incompatible versions which cannot handle the new chunk request scheme.
  • The Tanium Server now queues incoming client challenge requests into batches for more efficient processing.
  • Filters deleted privileges read and loaded from the tanium database into the Tanium Server.
  • Ensures that platform privileges cannot be deleted, since the correct operation of the Tanium Server and solution modules depend on them.
  • The Tanium Server now offers an API route to retrieve persona objects by their name.
  • Adds a Tanium Server setting to enable sensor versioning features in a future release.
  • Validates System User Service mTLS identities for Module Server requests received by the Tanium Server.
  • The Tanium Server now issues mTLS credentials to module services as specified by their import definitions during installation.
  • Implements certificate renewal from the Tanium Server to the Module Server solutions one month before they expire.
  • Implements deletion of users as directed by an XML uninstall manifest imported to the Tanium Server.
  • Ensures that mTLS API requests to the Tanium Server are only allowed to access the auth REST route and are otherwise used exclusively for gRPC module requests.
  • Adds a mechanism for the Tanium Server to deliver a file that lists all existing Tanium Servers to the Module server, so solution modules can read and use this information.
  • The Tanium Server APIs now return an expiration value for the session identifier which made the request.
  • The Tanium Server issues SUS-style formatted session tokens for requests that authenticate using System User Service mTLS.
  • Adds SPIFFE ids support in System User Service mTLS certificates issued by the Tanium Server.
  • The Tanium Server will internally look up System User Service users by their SPIFFE id.
  • The Tanium Server now emits metrics that reflect the number of background jobs running within the server process.
  • Augments the Tanium Server users and user_groups API routes to return their SCIM-related properties.
  • Adds authoritative_domains information to SCIM server records in the Tanium Server database as a precursor for the new user-adoption implementation.
  • The scim_servers route in the Tanium Server API now accepts an authoritative_domains field which allows it to implement the adoption of existing user accounts into a SCIM source.
  • The DELETE operation on the Tanium Server scim_servers API now accepts an "unlink_objects" field which controls whether associated user and group records should also be removed.
  • The Tanium Server database upgrade command-line now supports the option "--preview" that can be used to display all of the needed upgrade steps without actually performing them.
  • Implements sequence number tracking in Tanium Server active/ active synchronization messages, allowing for a non-lossy exchange of data between servers.
  • Ensures that a mismatched software version between a Tanium Server and Zone Server does not increment its unhandled exceptions counter, to avoid false positive increases during Platform upgrades.
  • Implements returning supported entity providers information for each sensor when querying the Tanium Server sensors API.
  • In the Tanium Server entity expansion subsystem deleting a provided removes all of the entities created by it.
  • Entities will return "[no results]" values for sensors that do not support external providers.
  • The Tanium Server will no longer allow HTTP PATCH requests on SCIM managed groups except by the associated scim_user_id. This is to avoid changes which are requested by any other than the SCIM provider itself.
  • Reinstates issuing download_identifier response data in the Tanium Server packages API, because some solution modules still use that value for package files.
  • For backwards compatibility existing questions content in the Tanium Server will be paired with a "Device Type = Tanium Client", and only new content which explicitly declares "All Entities" will be spared of this filter.
  • Allows the Tanium Server to issue system user certificates when the Module Server is unreachable. This allows importing solutions when a Module Server is unavailable.
  • Implements the ability to remove entities from the Tanium Server entity expansion subsystem.
  • Changes the Tanium Server to receive a raw PEM format identity for the System User Service identity, avoiding the need for a base-64 encoding.
  • The Tanium Server only accepts sensor result value updates for entities when delivered with increasing sequence numbers. This ensures that the active/ active synchronization between servers keeps moving forward in time.
  • Implements Computer ID sensor results for entity questions in the Tanium Server.
  • Improves the efficiency of the CheckPackageFiles recurrent job in the Tanium Server to limit its activity only to those packages that need to be verified.
  • Implements the use of the "all entities" scope in the Tanium Server question parser for use in entity questions.
  • Adds the is_tanium_client_entity to provider types in the Tanium Server API to distinguish whether results originated at the Tanium Client or at the server through a provider integration.
  • Improves the handling of exceptions when the Tanium Server receives malformed certificate signing requests.
  • Adds question scope information to the Tanium Server export API.
  • Changes the Platform-based System User Service in the Tanium Server to support multiple accounts for each solution module.
  • The Tanium Server now includes computer IDs when emitting counting question results to allow a better user experience in Console when querying all entities.
  • The Tanium Server will now remove unknown files from its Downloads directory which were created more than clean_download_catalog_grace_period_hours ago.
  • Add the default_scope field to the Tanium Server question parser which allows parsing requests to specify if the query is applicable to "all machines" or to "all entities".
  • The Tanium Server will now initialize the TLS context for the System User Service as soon as it receives a root message from the TMS. This avoids having to restart the server before these certificates will work.
  • Moves the upgrade package file migration in the Tanium Server to a separate thread to avoid a long blocking delay on server startup after a software version upgrade.

Bug Fixes

  • Fixes an issue where the Tanium Server would ignore some module solution properties like "service_hostname" during import.
  • The Tanium Server action API will now return an HTTP-400 response when the request values cannot be parsed correctly.
  • Fixes an omission in the Tanium Server content sets API where it would not apply requested cache filters correctly.
  • The Tanium Server now validates that all sensor references in a solution import either already exist or are defined within the solution itself.
  • Reverts some of the existing UserPrincipalName validation rules in the Tanium Server to accommodate for the new style System User Service in Platform.
  • Fixes the omission of a text description in the saved action audit records emitted by the Tanium Server.
  • Fixes a logging message in the Tanium Server where a trailing curly brace was missing from SCIM response messages.
  • Fixes missing data from the permissions array in the Tanium Server session/current API responses.
  • Fixes an omission in the Tanium Server question API where metadata cannot be added to saved questions.
  • Fixes a problem in the Tanium Server where creating actions with a parametrized package would have some missing source package verification parameters.
  • Fixes an omission of content membership audit records generated by the Tanium Server when changes were made as part of user management requests.
  • Fixes a memory leak detected in the use of OpenSSL v3.4.1.
  • Fixes an omission of content membership audit records generated by the Tanium Server when changes were made as part of user group management requests.
  • Fixes a problem in the Tanium Server's instantiation of questions with parametrized sensors which would result in the error message: "IDDoesNotMatchSourceID".
  • Fixes a problem in the Tanium Server that triggered the error "assertion 'fileSize > mapChunkSize' failed" when a package file had the same size as a chunk map.
  • Periodically refreshes the Module Server information that the Tanium Server communicates with so its System User Service SSL context is also refreshed accordingly.
  • Fixes an issue where the Tanium Server would attempt to push its tanium-servers.json information to the Module Server and fail, and then retry only every ten minutes, resulting in a long period of failed communications between both.
  • Fixes an issue in the Tanium Server installer database upgrade steps which incurred in database constraint violations over global settings.
  • Fixes an unmet assertion in the Tanim Server which results in the error: assertion 'hash.size() > 0 && hash.size() <= kMaxHashSize' failed.
  • Fixes a deadlock condition in the Tanium Server EncryptedMessageProcessor.
  • Fixes the handling of unexpected exceptions in the Tanium Server scheduled actions processing which could cause that subsystem to halt its processing.
  • Fixes an issue where the Tanium Server would interpret question text using a "not" modifier as "All Computers".
  • Fixes an issue in the Tanium Server that would cause data services harvest failures while logging the message: assertion failed: no hashes for computer id.
  • Fixes a behavior in the Tanium Server where processing of package files in two different threads would compete with each other and cause an unnecessary double processing of some entries.

Known Issues and Workarounds

  • N/A.

Product Documentation and Resources