SV-265988r1024496_rule
V-265988
SRG-APP-000213-DNS-000024
F5BI-DN-300028
CAT II
10
DNSSEC Keys:
From the BIG-IP GUI:
1. DNS.
2. Zones.
3. DNSSEC Zones.
4. DNSSEC Zone List.
5. Click the name of the zone.
6. Move a key for both "Zone Signing Key" and "Key Signing Key" into the "Active" column.
7. Click "Update".
Note: To create a Zone Signing Key and/or Key Signing Key go to DNS >> Delivery >> Keys >> DNSSEC Key List.
DNS Profile:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features set "DNSSEC" to "Enabled".
Note: If the setting is grayed out click the box to the right of the setting and then change it.
7. Click "Update".
From the BIG-IP Console, type the following commands:
Note: Assuming you are checking a DNSSEC Zone, from the command line of a management computer, run:
dig +dnssec @<DNS Server IP> <DNSSEC zonename>
#verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).
DNS Profile:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features verify "DNSSEC" is set to "Enabled".
If the BIG-IP DNS appliance is not configured to provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries, this is a finding.
V-265988
False
F5BI-DN-300028
From the BIG-IP Console, type the following commands:
Note: Assuming you are checking a DNSSEC Zone, from the command line of a management computer, run:
dig +dnssec @<DNS Server IP> <DNSSEC zonename>
#verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).
DNS Profile:
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Profiles.
4. DNS.
5. Click the name of the DNS profile being used by the listener.
6. Under DNS Features verify "DNSSEC" is set to "Enabled".
If the BIG-IP DNS appliance is not configured to provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries, this is a finding.
M
5638