SV-259410r1156963_rule
V-259410
SRG-APP-000176-DNS-000076
WDNS-22-000090
CAT II
10
Regenerate a unique TSIG key for each pair of communicating hosts within the DNS architecture.
This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.
Review the DNS implementation. Verify that each pair of communicating hosts has a unique TSIG key (i.e., a separate key for each secondary name server to authenticate transactions with the primary name server, etc.).
If a unique TSIG key has not been generated for each pair of communicating hosts, this is a finding.
If using DNSSEC, this requirement is not applicable.
V-259410
False
WDNS-22-000090
This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.
Review the DNS implementation. Verify that each pair of communicating hosts has a unique TSIG key (i.e., a separate key for each secondary name server to authenticate transactions with the primary name server, etc.).
If a unique TSIG key has not been generated for each pair of communicating hosts, this is a finding.
If using DNSSEC, this requirement is not applicable.
M
5576