SV-272429r1123762_rule
V-272429
SRG-APP-000231-DNS-000033
BIND-9X-001850
CAT II
10
Change the group ownership of the DNSSEC keys to the named process it is running as.
# chgrp <named_proccess_group> <DNSSEC_key_file>.
With the assistance of the DNS administrator, identify all of the DNSSEC keys used by the BIND 9.x implementation.
Identify the account that the "named" process is running as:
# ps -ef | grep named
named 3015 1 0 12:59 ? 00:00:00 /usr/sbin/named -u named -t /var/named/chroot
With the assistance of the DNS administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation.
# ls -al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key
If any of the DNSSEC keys are not group owned by the above account, this is a finding.
V-272429
False
BIND-9X-001850
With the assistance of the DNS administrator, identify all of the DNSSEC keys used by the BIND 9.x implementation.
Identify the account that the "named" process is running as:
# ps -ef | grep named
named 3015 1 0 12:59 ? 00:00:00 /usr/sbin/named -u named -t /var/named/chroot
With the assistance of the DNS administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation.
# ls -al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key
If any of the DNSSEC keys are not group owned by the above account, this is a finding.
M
5687