STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

On the BIND 9.x server the private key corresponding to the ZSK, stored on name servers accepting dynamic updates, must be group owned by root.

DISA Rule

SV-207590r612253_rule

Vulnerability Number

V-207590

Group Title

SRG-APP-000516-DNS-000111

Rule Version

BIND-9X-001411

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the group ownership of the ZSK private key to the root group account.

# chgrp root <key_file>

Check Contents

If the server is in a classified network, this is Not Applicable.
Note: This check only verifies for ZSK key file ownership. Permissions for key files are required under V-72451, BIND-9X-001132 and V-72461, BIND-9X-001142.

For each signed zone file, identify the ZSK "key id" number:

# cat <signed_zone_file> | grep -i "zsk"
ZSK; alg = ECDSAP256SHA256; key id = 22335

Using the ZSK "key id", verify the private ZSK.

Kexample.com.+008+22335.private

Verify that the private ZSK is owned by root:

# ls -l <ZSK_key_file>
-r------- 1 root root 1776 Jul 3 17:56 Kexample.com.+008+22335.private

If the key file is not group owned by root, this is a finding.

Vulnerability Number

V-207590

Documentable

False

Rule Version

BIND-9X-001411

Severity Override Guidance

If the server is in a classified network, this is Not Applicable.
Note: This check only verifies for ZSK key file ownership. Permissions for key files are required under V-72451, BIND-9X-001132 and V-72461, BIND-9X-001142.

For each signed zone file, identify the ZSK "key id" number:

# cat <signed_zone_file> | grep -i "zsk"
ZSK; alg = ECDSAP256SHA256; key id = 22335

Using the ZSK "key id", verify the private ZSK.

Kexample.com.+008+22335.private

Verify that the private ZSK is owned by root:

# ls -l <ZSK_key_file>
-r------- 1 root root 1776 Jul 3 17:56 Kexample.com.+008+22335.private

If the key file is not group owned by root, this is a finding.

Check Content Reference

M

Target Key

2926

Comments