SV-272386r1123985_rule
V-272386
SRG-APP-000516-DNS-000086
BIND-9X-001290
CAT II
10
Change the ownership of the keys to the administrator account.
# chown named:named <key_file>.
With the assistance of the DNS administrator, identify all dnssec-keygen key files that reside on the BIND 9.x server.
An example dnssec-keygen key file will look like the following:
Kns1.example.com_ns2.example.com.+161+28823.key
OR
Kns1.example.com_ns2.example.com.+161+28823.private
For each key file identified, verify that the key file is owned by "named":
# ls -al
-rw-r-----. 1 named named 76 May 10 20:35 dnssec-example.key
If the key files are not owned by named, this is a finding.
V-272386
False
BIND-9X-001290
With the assistance of the DNS administrator, identify all dnssec-keygen key files that reside on the BIND 9.x server.
An example dnssec-keygen key file will look like the following:
Kns1.example.com_ns2.example.com.+161+28823.key
OR
Kns1.example.com_ns2.example.com.+161+28823.private
For each key file identified, verify that the key file is owned by "named":
# ls -al
-rw-r-----. 1 named named 76 May 10 20:35 dnssec-example.key
If the key files are not owned by named, this is a finding.
M
5687