STIGQter STIGQter: STIG Summary: Infoblox 7.x DNS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

An authoritative name server must be configured to enable DNSSEC Resource Records.

DISA Rule

SV-214206r612370_rule

Vulnerability Number

V-214206

Group Title

SRG-APP-000516-DNS-000089

Rule Version

IDNS-7X-000770

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

DNSSEC must be enabled prior to zone signing. Enable by navigating to Data Management >> DNS >> Grid DNS properties.

Toggle Advanced Mode click on "DNSSEC" tab. Enable the "Enable DNSSEC" option.
When complete, click "Save & Close" to save the changes and exit the "Properties" screen.

Perform a service restart if necessary.

Check Contents

Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.

Validate that DNSSEC is enabled by navigating to Data Management >> DNS >> Grid DNS properties.

Toggle Advanced Mode click on "DNSSEC" tab.
When complete, click "Cancel" to exit the "Properties" screen.

If "Enable DNSSEC" is not configured this is a finding.

Vulnerability Number

V-214206

Documentable

False

Rule Version

IDNS-7X-000770

Severity Override Guidance

Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.

Validate that DNSSEC is enabled by navigating to Data Management >> DNS >> Grid DNS properties.

Toggle Advanced Mode click on "DNSSEC" tab.
When complete, click "Cancel" to exit the "Properties" screen.

If "Enable DNSSEC" is not configured this is a finding.

Check Content Reference

M

Target Key

3995

Comments