STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The private keys corresponding to both the zone signing key (ZSK) and the key signing key (KSK) must not be kept on the DNSSEC-aware primary authoritative name server when the name server does not support dynamic updates.

DISA Rule

SV-259414r1156961_rule

Vulnerability Number

V-259414

Group Title

SRG-APP-000516-DNS-000112

Rule Version

WDNS-22-000107

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Store the private keys of the ZSK and KSK offline in an encrypted file system.

Check Contents

This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.

Review the DNS name server and documentation to determine if it accepts dynamic updates.

If dynamic updates are not accepted, verify the private keys corresponding to both the ZSK and KSK are not located on the name server.

If the private keys to the ZSK and/or the KSK are located on the name server, this is a finding.

Vulnerability Number

V-259414

Documentable

False

Rule Version

WDNS-22-000107

Severity Override Guidance

This check is not applicable for Windows DNS Servers that only host Active Directory-integrated zones or for Windows DNS servers on a classified network.

Review the DNS name server and documentation to determine if it accepts dynamic updates.

If dynamic updates are not accepted, verify the private keys corresponding to both the ZSK and KSK are not located on the name server.

If the private keys to the ZSK and/or the KSK are located on the name server, this is a finding.

Check Content Reference

M

Target Key

5576