STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The validity period for the Resource Record Signatures (RRSIGs) covering the Delegation Signer (DS) Resource Record (RR) for a zone's delegated children must be no less than two days and no more than one week.

DISA Rule

SV-259339r961104_rule

Vulnerability Number

V-259339

Group Title

SRG-APP-000214-DNS-000079

Rule Version

WDNS-22-000007

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Right-click on the zone and choose DNSSEC >> Properties.

On the ZSK tab, for DS signature validity period (hours), choose more than 48 and less than 168.

Check Contents

Note: This check is not applicable for Windows DNS Servers that host only Active Directory-integrated zones or for Windows DNS Servers on a classified network.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

View the validity period for the DS RR.

If the validity period for the DS RR for the child domain is less than two days (48 hours) or more than one week (168 hours), this is a finding.

Vulnerability Number

V-259339

Documentable

False

Rule Version

WDNS-22-000007

Severity Override Guidance

Note: This check is not applicable for Windows DNS Servers that host only Active Directory-integrated zones or for Windows DNS Servers on a classified network.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

View the validity period for the DS RR.

If the validity period for the DS RR for the child domain is less than two days (48 hours) or more than one week (168 hours), this is a finding.

Check Content Reference

M

Target Key

5576