IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Release Notes Tanium Server (Version 7.8.2.1111)

From Tanium Knowledge Base
Jump to navigation Jump to search

Thank you for choosing Tanium. The following Release Notes document changes between releases of the Tanium Server.
This platform release includes the release of both a Windows and Linux Tanium Server.
The previous version can be found here: Release Notes Tanium Server (Version 7.8.1.3147)


Tanium Server for Windows and Linux v7.8.2.1111

  • Tanium Cloud availability date: N/A.
  • On-premises availability date: November 19, 2025.

Special Notes

  • The Tanium Server now ships with Console v3.x.y.

Security Updates

  • N/A.

New Features

  • Tanium Platform components now ship with Python v3.12.12.
  • Fixes an issue in the Tanium Server which could result in the bypass action approval permission being removed from customized service account.
  • Adds an external_flag to the user groups API on the Tanium Server to allow the console to display when a user group is created locally or by an LDAP or SCIM integration.
  • Updates the manifest URL to prepare this newer version for use in SAR 2025-H2.
  • The Tanium Server now implements metrics that track the queue processing of incoming encrypted messages.
  • Adds a "depth" optional option to the Tanium Server group API that allows the caller to define how many levels of sub-groups should be returned in the response.
  • *** Removes the cpms_server setting from the Tanium Server since this configuration is now obtained from the TaaS Entitlements service.
  • Implements the allowed_entity_provider_endpoints API in the Tanium Server which will be used to manage which CIDv2 endpoints are allowed to act as operational technology entity providers.
  • The Tanium Server now implements an API through which solution modules can update sensor result information on behalf of operational technology entities, allowing solutions like Comply to calculate and update vulnerability information for OT entities.
  • Adds the enable_ai_ask_bar and enable_ai_ask_agents server global settings to control AI capabilities in a system.
  • Ensures that left-hand-side filters work on questions issued by the Tanium Server when combined with entity expansion results.
  • The Tanium Server will now keep a single copy package files in its Downloads/Cache/ directory and no longer duplicate these contents.
  • Improves the interaction of the Tanium Server with the database when looking up providers for a set of sensors.
  • Implements new reserved builtin sensors for the Tanium Client to complement entity queries. The new sensors are Provider Name, Provider Type, Entity Type and Is Endpoint.
  • Adds a new RBAC privilege to the Tanium Server to control access for entity providers.

Improvements

  • Tanium Platform components now ship with libExpat v2.7.3.
  • Adds the contents of PreLoginBannerHTML to unauthenticated requests for console.json to the Tanium Server so systems can display this before login.
  • Removes all of the GAUGE type metrics for bandwidth utilization in the Tanium Server and Zone Server.
  • The Tanium Server now issues its client_count_history and client_count_history_full metrics for 1 (one), 7, 14 and 30 days in the past.
  • The Tanium Server now issues HISTOGRAM metrics for cache_refresh_timing measures that reflect its database service timings when refreshing internal caches.
  • The cpms_upload_queued metric in the Tanium Server is now encoded as a COUNTER.
  • The Tanium Server now offers detailed logging for errors encountered when decompressing incoming messages instead of just logging: "Failed to decompress report batch".
  • Extends the Tanium Server user_group and user API routes to allow the assignment or removal of an individual user to a group.
  • Refactors the way in which the Tanium Server refreshes its active/ active servers list to avoid doing input-output operations on an asynchronous processing thread.
  • Modifies the database recorded contents for audit_type=5 records created by the Tanium Server.

Bug Fixes

  • Fixes a problem where pre-v7.8 Tanium Clients will attempt but fail to download files from CDN outside US regions. This fix is implemented as a server-side change to avoid the need to upgrade all non-US clients.
  • Ensures that OSSL_DISPATCH markers are present on all SSL structures to mark where they end and avoid OpenSSL reading past their allowed length.
  • Fixes an issue in the Tanium Server where it would fail to interpret download file sizes as 64-bit integers, impacting the handling of files larger than 4 gigabytes.
  • Fixes the Tanium Server RBAC preview-privileges API which would return an incomplete list of provided privileges.
  • Removes the DNS subject alternative name from issued certificates to avoid the problem of non-ASCII hostnames causing these certificates to be deemed as invalid by security tools.
  • Fixes the handling of instrumented global and per-subnet download connections counters in the Tanium Server.
  • Fixes the Tanium Server preview_content_set_role_detailed API which would incorrectly return "implied_by"="unknown" for implied permissions created by installed module solutions.
  • Fixes an issue in the replication of identity information between Tanium Servers that would trigger the error: "unexpected exception: CHECK failed: (index) < (current_size_)".
  • Fixes an issue in the Tanium Server when asking entity questions with a right-hand side filter, making filters like "all entities with Entity Type equals Mobile Device" return no results.
  • Fixes a problem with the encrypted_message_queue_batch_received_size_total metric emitted by Platform which displayed more than one "type" label.
  • Fixes a problem in the Tanium Client handling of version compatibility levels which would keep some client versions from peering and increased the leader count in some deployments.
  • Fixes a condition in the Tanium Server where a file was downloaded and available on the server but not present in its Downloads/Cache directory, triggering a "Failed to process package file: File missing" message and causing it to fail distribution.
  • Fixes an issue in the Tanium Server where its service discovery job could cause a hang during the server's shutdown sequence.
  • Fixes an issue with status syncing between Tanium Server and Tanium Zone Server occurring more often than required.
  • Fixes an issue in the Tanium Server where questions issued for "all machines" would return results from operational technology entities.
  • Fixes the handling of metadata for actions created by the Tanium Server.
  • Fixes an omission in the Tanium Server ListEntities gRPC API which would not honor filtering by its proxy_id field.
  • Fixes an unhandled exception in the Tanium Server when decompressing incoming messages, making sure they are properly tallied as communication failures.
  • Fixes an issue that prevented a Content Set from being deleted if a Preview Sensor had used that Content Set.

Known Issues and Workarounds

  • N/A.
    Workaround: N/A.

Product Documentation and Resources