An authoritative name server must be configured to enable DNSSEC Resource Records.
DISA Rule
SV-265982r1024488_rule
Vulnerability Number
V-265982
Group Title
SRG-APP-000516-DNS-000089
Rule Version
F5BI-DN-300013
Severity
CAT II
CCI(s)
- CCI-000366 - Implement the security configuration settings.
- CCI-001901 - Bind the identity of the information producer with the information to an organization-defined strength of binding.
- CCI-001902 - Provide the means for authorized individuals to determine the identity of the producer of the information.
- CCI-002463 - Provide data origin artifacts for internal name/address resolution queries.
- CCI-002464 - Provide data integrity protection artifacts for internal name/address resolution queries.
- CCI-000778 - Uniquely identify organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection.
- CCI-002462 - Provide additional data integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries.
- CCI-001663 - Provide the means to enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services), when operating as part of a distributed, hierarchical namespace.
- CCI-002465 - Request data origin authentication verification on the name/address resolution responses the system receives from authoritative sources.
- CCI-002466 - Request data integrity verification on the name/address resolution responses the system receives from authoritative sources.
- CCI-002467 - Perform data integrity verification on the name/address resolution responses the system receives from authoritative sources.
- CCI-002468 - Perform data origin verification authentication on the name/address resolution responses the system receives from authoritative sources.
- CCI-001184 - Protect the authenticity of communications sessions.
Weight
10
Fix Recommendation
DNSSEC Keys:
From the BIG-IP GUI:
1. DNS.
2. Zones.
3. DNSSEC Zones.
4. DNSSEC Zone List.
5. Click the name of the zone.
6. Move a key for both "Zone Signing Key" and "Key Signing Key" into the "Active" column.
7. Click "Update".
Note: To create a Zone Signing Key and/or Key Signing Key, go to DNS >> Delivery >> Keys >> DNSSEC Key List.
TSIG Key:
1. DNS.
2. Delivery.
3. Nameservers.
4. Nameserver List.
5. Click on the name of the Nameserver.
6. Select a value from the drop-down for "TSIG Key".
7. Click "Update".
Note: To create a TSIG Key, go to DNS >> Delivery >> Keys >> TSIG Key List.
Check Contents
DNSSEC Keys:
From the BIG-IP GUI:
1. DNS.
2. Zones.
3. DNSSEC Zones.
4. DNSSEC Zone List.
5. Click the name of the zone.
6. Verify a key is selected for both "Zone Signing Key" and "Key Signing Key".
TSIG Key:
1. DNS.
2. Delivery.
3. Nameservers.
4. Nameserver List.
5. Click the name of the Nameserver.
6. Verify a value is selected for "TSIG Key".
If the BIG-IP DNS implementation is not configured to enable DNSSEC Resource Records, this is a finding.
Vulnerability Number
V-265982
Documentable
False
Rule Version
F5BI-DN-300013
Severity Override Guidance
DNSSEC Keys:
From the BIG-IP GUI:
1. DNS.
2. Zones.
3. DNSSEC Zones.
4. DNSSEC Zone List.
5. Click the name of the zone.
6. Verify a key is selected for both "Zone Signing Key" and "Key Signing Key".
TSIG Key:
1. DNS.
2. Delivery.
3. Nameservers.
4. Nameserver List.
5. Click the name of the Nameserver.
6. Verify a value is selected for "TSIG Key".
If the BIG-IP DNS implementation is not configured to enable DNSSEC Resource Records, this is a finding.
Check Content Reference
M
Target Key
5638