STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

Only the private key corresponding to the ZSK alone must be kept on the name server that does support dynamic updates.

DISA Rule

SV-69055r1_rule

Vulnerability Number

V-54809

Group Title

SRG-APP-000176-DNS-000094

Rule Version

SRG-APP-000176-DNS-000094

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Store the private keys of the ZSK and KSK off-line in an encrypted file system.

Check Contents

Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, verify only the private keys corresponding to the ZSK (Zone Signing Key) are located on the server.

If the private keys to the KSK are located on the name server that accepts dynamic updates, this is a finding.

Vulnerability Number

V-54809

Documentable

False

Rule Version

SRG-APP-000176-DNS-000094

Severity Override Guidance

Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, verify only the private keys corresponding to the ZSK (Zone Signing Key) are located on the server.

If the private keys to the KSK are located on the name server that accepts dynamic updates, this is a finding.

Check Content Reference

M

Target Key

2355

Comments