STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Windows DNS Server must implement a local cache of revocation data for PKI authentication.

DISA Rule

SV-259371r1212361_rule

Vulnerability Number

V-259371

Group Title

SRG-APP-000401-DNS-000051

Rule Version

WDNS-22-000043

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure local revocation data to be used in the event access to Certificate Authorities is hindered.

Check Contents

Note: This check is not applicable for Windows DNS Servers that host only Active Directory (AD)-integrated zones or for Windows DNS Servers on a classified network.

Consult with the system administrator to determine if a third-party CRL server is being used for certificate revocation lookup.

If there is, determine if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.

If there is no local cache of revocation data, this is a finding.

Vulnerability Number

V-259371

Documentable

False

Rule Version

WDNS-22-000043

Severity Override Guidance

Note: This check is not applicable for Windows DNS Servers that host only Active Directory (AD)-integrated zones or for Windows DNS Servers on a classified network.

Consult with the system administrator to determine if a third-party CRL server is being used for certificate revocation lookup.

If there is, determine if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.

If there is no local cache of revocation data, this is a finding.

Check Content Reference

M

Target Key

5576