STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

A BIND 9.x server implementation must maintain the integrity and confidentiality of DNS information while it is being prepared for transmission, in transmission, and in use and must perform integrity verification and data origin verification for all DNS information.

DISA Rule

SV-272417r1156947_rule

Vulnerability Number

V-272417

Group Title

SRG-APP-000348-DNS-000042

Rule Version

BIND-9X-001650

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Set the "dnssec-validation" option to "yes".

Sign each zone file for which the name server is responsible.

Configure each zone for which the name server is responsible to use a DNSSEC signed zone.

Check Contents

For a recursive server, verify that dnssec-validation yes is enabled.

Inspect the "named.conf" file for the following:

dnssec-validation yes;

If "dnssec-validation yes" does not exist or is not set to "yes", this is a finding.

For an authoritative server, verify that each zone on the name server has been signed.

Identify each zone file for which the name server is responsible and search each file for the "DNSKEY" entries:

# less <signed_zone_file>
86400 DNSKEY 257 3 8 ( HASHED_KEY ) ; KSK; alg = ECDSAP256SHA256; key id = 31225
86400 DNSKEY 256 3 8 ( HASHED_KEY ) ; ZSK; alg = ECDSAP256SHA256; key id = 52179

Verify that there are separate "DNSKEY" entries for the "KSK" and the "ZSK".

If the "DNSKEY" entries are missing, the zone file is not signed.

If the zone files are not signed, this is a finding.

Vulnerability Number

V-272417

Documentable

False

Rule Version

BIND-9X-001650

Severity Override Guidance

For a recursive server, verify that dnssec-validation yes is enabled.

Inspect the "named.conf" file for the following:

dnssec-validation yes;

If "dnssec-validation yes" does not exist or is not set to "yes", this is a finding.

For an authoritative server, verify that each zone on the name server has been signed.

Identify each zone file for which the name server is responsible and search each file for the "DNSKEY" entries:

# less <signed_zone_file>
86400 DNSKEY 257 3 8 ( HASHED_KEY ) ; KSK; alg = ECDSAP256SHA256; key id = 31225
86400 DNSKEY 256 3 8 ( HASHED_KEY ) ; ZSK; alg = ECDSAP256SHA256; key id = 52179

Verify that there are separate "DNSKEY" entries for the "KSK" and the "ZSK".

If the "DNSKEY" entries are missing, the zone file is not signed.

If the zone files are not signed, this is a finding.

Check Content Reference

M

Target Key

5687