STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.

DISA Rule

SV-265989r1024498_rule

Vulnerability Number

V-265989

Group Title

SRG-APP-000214-DNS-000079

Rule Version

F5BI-DN-300030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Configure the "Signature Validity Period" to two and seven days.
7. Click "Update".

ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the ZSK.
6. Configure the "Signature Validity Period" to two and seven days.
7. Click "Update".

Check Contents

KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.

ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.

If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.

Vulnerability Number

V-265989

Documentable

False

Rule Version

F5BI-DN-300030

Severity Override Guidance

KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.

ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.

If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.

Check Content Reference

M

Target Key

5638