SV-265989r1024498_rule
V-265989
SRG-APP-000214-DNS-000079
F5BI-DN-300030
CAT II
10
KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Configure the "Signature Validity Period" to two and seven days.
7. Click "Update".
ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the ZSK.
6. Configure the "Signature Validity Period" to two and seven days.
7. Click "Update".
KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.
ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.
If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.
V-265989
False
F5BI-DN-300030
KSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the Name of the KSK.
6. Verify the "Signature Validity Period" is between two and seven days.
ZSK validity period
From the BIG-IP GUI:
1. DNS.
2. Delivery.
3. Keys.
4. DNSSEC Key List.
5. Click the name of the ZSK.
6. Verify the "Signature Validity Period" is between two and seven days.
If the BIG-IP appliance is not configured with a validity period for the RRSIGs covering a zones DNSKEY RRSet of no less than two days and no more than one week, this is a finding.
M
5638