STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

Permissions assigned to the DNSSEC keys used with the BIND 9.x implementation must enforce read-only access to the key owner and deny access to all other users.

DISA Rule

SV-272427r1124022_rule

Vulnerability Number

V-272427

Group Title

SRG-APP-000231-DNS-000033

Rule Version

BIND-9X-001830

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the permissions of the DNSSEC key files:

# chmod 400 <DNSSEC_key_file>

Check Contents

Verify permissions assigned to the DNSSEC keys enforce read-only access to the key owner and deny access to group or system users.

With the assistance of the DNS administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation:

# ls -al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key

If the key files are more permissive than 400, this is a finding.

Vulnerability Number

V-272427

Documentable

False

Rule Version

BIND-9X-001830

Severity Override Guidance

Verify permissions assigned to the DNSSEC keys enforce read-only access to the key owner and deny access to group or system users.

With the assistance of the DNS administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation:

# ls -al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key

If the key files are more permissive than 400, this is a finding.

Check Content Reference

M

Target Key

5687