SV-272384r1156952_rule
V-272384
SRG-APP-000516-DNS-000084
BIND-9X-001270
CAT II
10
Re-sign each zone that is missing NSEC records.
Restart the BIND 9.x process.
If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.
With the assistance of the DNS administrator, identify each internal DNS zone listed in the "named.conf" file.
For each internal zone identified, inspect the signed zone file for the NSEC resource records:
86400 NSEC example.com. A RRSIG NSEC
If the zone file does not contain an NSEC record for the zone, this is a finding.
V-272384
False
BIND-9X-001270
If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.
With the assistance of the DNS administrator, identify each internal DNS zone listed in the "named.conf" file.
For each internal zone identified, inspect the signed zone file for the NSEC resource records:
86400 NSEC example.com. A RRSIG NSEC
If the zone file does not contain an NSEC record for the zone, this is a finding.
M
5687