STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

The two files generated by the BIND 9.x server dnssec-keygen program must be owned by the administrator account or deleted once they have been copied to the key file in the name server.

DISA Rule

SV-272386r1123985_rule

Vulnerability Number

V-272386

Group Title

SRG-APP-000516-DNS-000086

Rule Version

BIND-9X-001290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the ownership of the keys to the administrator account.

# chown named:named <key_file>.

Check Contents

With the assistance of the DNS administrator, identify all dnssec-keygen key files that reside on the BIND 9.x server.

An example dnssec-keygen key file will look like the following:

Kns1.example.com_ns2.example.com.+161+28823.key
OR
Kns1.example.com_ns2.example.com.+161+28823.private

For each key file identified, verify that the key file is owned by "named":

# ls -al
-rw-r-----. 1 named named 76 May 10 20:35 dnssec-example.key

If the key files are not owned by named, this is a finding.

Vulnerability Number

V-272386

Documentable

False

Rule Version

BIND-9X-001290

Severity Override Guidance

With the assistance of the DNS administrator, identify all dnssec-keygen key files that reside on the BIND 9.x server.

An example dnssec-keygen key file will look like the following:

Kns1.example.com_ns2.example.com.+161+28823.key
OR
Kns1.example.com_ns2.example.com.+161+28823.private

For each key file identified, verify that the key file is owned by "named":

# ls -al
-rw-r-----. 1 named named 76 May 10 20:35 dnssec-example.key

If the key files are not owned by named, this is a finding.

Check Content Reference

M

Target Key

5687