STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

Read/Write access to the key file must be restricted to the account that runs the name server software only.

DISA Rule

SV-69051r1_rule

Vulnerability Number

V-54805

Group Title

SRG-APP-000176-DNS-000019

Rule Version

SRG-APP-000176-DNS-000019

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Apply permissions to the key file to provide read/modify permissions only to the account under which the name server software is run.

Check Contents

Review the DNS system to determine privileges on the key file and the account under which the name server software is run.

If the account under which the name server software is run is not the only account which has read/modify permissions to the key file, this is a finding.

Vulnerability Number

V-54805

Documentable

False

Rule Version

SRG-APP-000176-DNS-000019

Severity Override Guidance

Review the DNS system to determine privileges on the key file and the account under which the name server software is run.

If the account under which the name server software is run is not the only account which has read/modify permissions to the key file, this is a finding.

Check Content Reference

M

Target Key

2355

Comments