STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

A unique Transaction Signature (TSIG) key must be generated for each pair of communicating hosts.

DISA Rule

SV-259410r1156963_rule

Vulnerability Number

V-259410

Group Title

SRG-APP-000176-DNS-000076

Rule Version

WDNS-22-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Regenerate a unique TSIG key for each pair of communicating hosts within the DNS architecture.

Check Contents

This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.

Review the DNS implementation. Verify that each pair of communicating hosts has a unique TSIG key (i.e., a separate key for each secondary name server to authenticate transactions with the primary name server, etc.).

If a unique TSIG key has not been generated for each pair of communicating hosts, this is a finding.

If using DNSSEC, this requirement is not applicable.

Vulnerability Number

V-259410

Documentable

False

Rule Version

WDNS-22-000090

Severity Override Guidance

This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.

Review the DNS implementation. Verify that each pair of communicating hosts has a unique TSIG key (i.e., a separate key for each secondary name server to authenticate transactions with the primary name server, etc.).

If a unique TSIG key has not been generated for each pair of communicating hosts, this is a finding.

If using DNSSEC, this requirement is not applicable.

Check Content Reference

M

Target Key

5576