STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

A BIND 9.x server must implement NIST FIPS-validated cryptography for provisioning digital signatures and generating cryptographic hashes.

DISA Rule

SV-272436r1137676_rule

Vulnerability Number

V-272436

Group Title

SRG-APP-000514-DNS-000075

Rule Version

BIND-9X-002050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create new DNSSEC and TSIG keys using a FIPS-approved cryptographic algorithm that meets or exceeds the strength of SHA-256.

Check Contents

Verify that the DNSSEC and TSIG keys used by the BIND 9.x implementation are FIPS compliant.

If the server is in a classified network, the DNSSEC portion of the requirement is Not Applicable.

DNSSEC keys:

Inspect the "named.conf" file and identify all of the DNSSEC signed zone files:

zone "example.com" {
file "signed_zone_file";
};

For each signed zone file identified, inspect the file for the "DNSKEY" records:

86400 DNSKEY 257 3 8 (
<KEY HASH>
) ; KSK;
86400 DNSKEY 256 3 8 (
<KEY HASH>
) ; ZSK;

The fifth field in the above example identifies what algorithm was used to create the DNSKEY.

If the fifth field, if the KSK DNSKEY is less than "8" (SHA256), this is a finding.

If the algorithm used to create the ZSK is less than "8" (SHA256), this is a finding.

TSIG keys:

Inspect the "named.conf" file and identify all of the TSIG key statements:

key tsig_example. {
algorithm hmac-SHA256;
include "tsig-example.key";
};

If each key statement does not use "hmac-SHA256" or a stronger algorithm, this is a finding.

Vulnerability Number

V-272436

Documentable

False

Rule Version

BIND-9X-002050

Severity Override Guidance

Verify that the DNSSEC and TSIG keys used by the BIND 9.x implementation are FIPS compliant.

If the server is in a classified network, the DNSSEC portion of the requirement is Not Applicable.

DNSSEC keys:

Inspect the "named.conf" file and identify all of the DNSSEC signed zone files:

zone "example.com" {
file "signed_zone_file";
};

For each signed zone file identified, inspect the file for the "DNSKEY" records:

86400 DNSKEY 257 3 8 (
<KEY HASH>
) ; KSK;
86400 DNSKEY 256 3 8 (
<KEY HASH>
) ; ZSK;

The fifth field in the above example identifies what algorithm was used to create the DNSKEY.

If the fifth field, if the KSK DNSKEY is less than "8" (SHA256), this is a finding.

If the algorithm used to create the ZSK is less than "8" (SHA256), this is a finding.

TSIG keys:

Inspect the "named.conf" file and identify all of the TSIG key statements:

key tsig_example. {
algorithm hmac-SHA256;
include "tsig-example.key";
};

If each key statement does not use "hmac-SHA256" or a stronger algorithm, this is a finding.

Check Content Reference

M

Target Key

5687