SV-272375r1123858_rule
V-272375
SRG-APP-000176-DNS-000019
BIND-9X-001180
CAT II
10
Change the permissions of the TSIG key files:
# chmod 640 <TSIG_key_file>
Verify permissions assigned to the TSIG keys enforce read-write access to the key owner and deny access to group or system users.
With the assistance of the DNS administrator, determine the location of the TSIG keys used by the BIND 9.x implementation:
# ls -al <TSIG_Key_Location>
-rw-r-----. 1 root named 76 May 10 20:35 tsig-example.key
If the key files are more permissive than 640, this is a finding.
V-272375
False
BIND-9X-001180
Verify permissions assigned to the TSIG keys enforce read-write access to the key owner and deny access to group or system users.
With the assistance of the DNS administrator, determine the location of the TSIG keys used by the BIND 9.x implementation:
# ls -al <TSIG_Key_Location>
-rw-r-----. 1 root named 76 May 10 20:35 tsig-example.key
If the key files are more permissive than 640, this is a finding.
M
5687