STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The validity period for the RRSIGs covering a zone's DNSKEY RRSet must be no less than two days and no more than one week.

DISA Rule

SV-265981r1024487_rule

Vulnerability Number

V-265981

Group Title

SRG-APP-000516-DNS-000078

Rule Version

F5BI-DN-300012

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

KSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Configure the "Signature Validity Period" to between two and seven days.
7. Click "Update".

ZSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the ZSK.
6. Configure the "Signature Validity Period" to between two and seven days.
7. Click "Update".

Check Contents

KSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.

ZSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.

If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.

Vulnerability Number

V-265981

Documentable

False

Rule Version

F5BI-DN-300012

Severity Override Guidance

KSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.

ZSK validity period:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.

If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.

Check Content Reference

M

Target Key

5638