STIGQter STIGQter: STIG Summary:

BIND 9.x Security Technical Implementation Guide

Version: 3

Release: 3 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-272364r1124029_ruleA BIND 9.x primary name server must limit the number of concurrent zone transfers between authorized secondary name servers.
SV-272365r1124031_ruleThe BIND 9.x secondary name server must limit the number of zones requested from a single primary name server.
SV-272366r1124033_ruleThe BIND 9.x secondary name server must limit the total number of zones the name server can request at any one time.
SV-272367r1123978_ruleThe BIND 9.x server implementation must limit the number of concurrent session client connections.
SV-272368r1123822_ruleThe print-severity variable for the configuration of BIND 9.x server logs must be configured to produce audit records containing information to establish what type of events occurred.
SV-272369r1123825_ruleThe print-time variable for the configuration of BIND 9.x server logs must be configured to establish when (date and time) the events occurred.
SV-272370r1123423_ruleThe print-category variable for the configuration of BIND 9.x server logs must be configured to record information indicating which process generated the events.
SV-272371r1156965_ruleA BIND 9.x server implementation must be configured to allow DNS administrators to audit all DNS server components based on selectable event criteria and produce audit records within all DNS server components that contain information for failed security verification tests, information to establish the outcome and source of the events, any information necessary to determine cause of failure, and any information necessary to return to operations with least disruption to mission processes.
SV-272372r1123853_ruleThe BIND 9.x server private key corresponding to the zone-signing key (ZSK) pair must be the only DNSSEC key kept on a name server that supports dynamic updates.
SV-272373r1192864_ruleThe BIND 9.x server signature generation using the key signing key (KSK) must be done offline, using the KSK-private key stored offline.
SV-272375r1123858_ruleThe read and write access to a TSIG key file used by a BIND 9.x server must be restricted to only the account that runs the name server software.
SV-272376r1156963_ruleA unique TSIG key used by a BIND 9.x server must be generated for each pair of communicating hosts.
SV-272377r1205821_ruleThe TSIG keys used with the BIND 9.x implementation must be owned by a privileged account.
SV-272378r1123864_ruleThe TSIG keys used with the BIND 9.x implementation must be group owned by a privileged account.
SV-272379r1124035_ruleOn a BIND 9.x server, for zones split between the external and internal sides of a network, the RRs for the external hosts must be separate from the RRs for the internal hosts.
SV-272380r1124037_ruleOn a BIND 9.x server in a split DNS configuration, where separate name servers are used between the external and internal networks, the internal name server must be configured to not be reachable from outside resolvers.
SV-272381r1124039_ruleOn a BIND 9.x server in a split DNS configuration, where separate name servers are used between the external and internal networks, the external name server must be configured to not be reachable from inside resolvers.
SV-272382r1124041_ruleA BIND 9.x implementation operating in a split DNS configuration must be approved by the organization's authorizing official (AO).
SV-272383r1124043_ruleOn the BIND 9.x server the IP address for hidden primary authoritative name servers must not appear in the name servers set in the zone database.
SV-272384r1156952_ruleA BIND 9.x server NSEC3 must be used for all internal DNS zones.
SV-272385r1156961_ruleOn the BIND 9.x server, the private keys corresponding to both the zone signing key (ZSK) and the key signing key (KSK) must not be kept on the BIND 9.x DNSSEC-aware primary authoritative name server when the name server does not support dynamic updates.
SV-272386r1123985_ruleThe two files generated by the BIND 9.x server dnssec-keygen program must be owned by the administrator account or deleted once they have been copied to the key file in the name server.
SV-272387r1123881_ruleThe two files generated by the BIND 9.x server dnssec-keygen program must be group owned by the server administrator account or deleted once they have been copied to the key file in the name server.
SV-272388r1124010_rulePermissions assigned to the dnssec-keygen keys used with the BIND 9.x implementation must enforce read-only access to the key owner and deny access to all other users.
SV-272389r1123885_ruleA BIND 9.x server validity period for the RRSIGs covering a zones DNSKEY RRSet must be no less than two days and no more than one week.
SV-272390r1156960_ruleOn the BIND 9.x server, the private key corresponding to the zone signing key (ZSK), stored on name servers accepting dynamic updates, must be owned by named.
SV-272391r1156960_ruleOn the BIND 9.x server, the private key corresponding to the zone signing key (ZSK), stored on name servers accepting dynamic updates, must be group owned by named.
SV-272392r1124046_ruleThe BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government.
SV-272393r1124048_ruleThe secondary name servers in a BIND 9.x implementation must be configured to initiate zone update notifications to other authoritative zone name servers.
SV-272394r1156949_ruleA BIND 9.x server implementation must prohibit recursion on authoritative name servers.
SV-272395r1124052_ruleThe primary servers in a BIND 9.x implementation must notify authorized secondary name servers when zone files are updated.
SV-272396r1192866_ruleOn a BIND 9.x server, all root name servers listed in the local root zone file hosted on a BIND 9.x authoritative name server must be valid for that zone.
SV-272397r1124056_ruleOn a BIND 9.x server, all root name servers listed in the local root zone file hosted on a BIND 9.x authoritative name server must be empty or removed.
SV-272399r1124058_ruleThe BIND 9.x server implementation must implement internal/external role separation.
SV-272400r1123993_ruleEvery NS record in a zone file on a BIND 9.x server must point to an active name server and that name server must be authoritative for the domain specified in that record.
SV-272401r1156953_ruleOn a BIND 9.x server, all authoritative name servers for a zone must be located on different network segments.
SV-272402r1124060_ruleOn the BIND 9.x server, the platform on which the name server software is hosted must be configured to send outgoing DNS messages from a random port.
SV-272403r1156957_ruleA BIND 9.x server implementation must be operating on a Current-Stable version as defined by ISC.
SV-272404r1156959_ruleThe host running a BIND 9.x implementation must use a dedicated management interface to separate management traffic from DNS-specific traffic.
SV-272405r1156959_ruleThe host running a BIND 9.x implementation must use an interface that is configured to process only DNS traffic.
SV-272406r1156959_ruleThe platform on which the name server software is hosted must only run processes and services needed to support the BIND 9.x implementation.
SV-272407r1156956_ruleThe core BIND 9.x server files must be group owned by a group designated for DNS administration only.
SV-272408r1156956_ruleThe core BIND 9.x server files must be owned by the root or BIND 9.x process account.
SV-272410r1124061_ruleOn a BIND 9.x server, all authoritative name servers for a zone must have the same version of zone information.
SV-272411r1156962_ruleOn the BIND 9.x server, CNAME records must not point to a zone with lesser security for more than six months.
SV-272412r1124064_ruleOn the BIND 9.x server, a zone file must not include resource records that resolve to a fully qualified domain name residing in another zone.
SV-272413r1156958_ruleThe BIND 9.x name server software must run with restricted privileges.
SV-272414r1123797_ruleThe BIND 9.x implementation must not use a TSIG or DNSSEC key for more than one year.
SV-272415r1156956_ruleThe permissions assigned to the core BIND 9.x server files must be set to use the least privilege possible.
SV-272416r1156959_ruleThe host running a BIND 9.x implementation must implement a set of firewall rules that restrict traffic on the DNS interface.
SV-272417r1156947_ruleA BIND 9.x server implementation must maintain the integrity and confidentiality of DNS information while it is being prepared for transmission, in transmission, and in use and must perform integrity verification and data origin verification for all DNS information.
SV-272418r1156948_ruleIn the event of an error when validating the binding of other DNS servers' identity to the BIND 9.x information, when anomalies in the operation of the signed zone transfers are discovered, for the success and failure of start and stop of the name server service or daemon, and for the success and failure of all name server events, a BIND 9.x server implementation must generate a log entry.
SV-272419r1123570_ruleThe BIND 9.x server implementation must be configured to use only approved ports and protocols.
SV-272421r1124019_ruleThe BIND 9.x server implementation must use separate TSIG key-pairs when securing server-to-server transactions.
SV-272422r1137672_ruleA BIND 9.x server implementation must be running in a chroot(ed) directory structure.
SV-272423r1123940_ruleA BIND 9.x implementation configured as a caching name server must restrict recursive queries to only the IP addresses and IP address ranges of known supported clients.
SV-272424r1124066_ruleA BIND 9.x server implementation must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.
SV-272425r1123944_ruleA BIND 9.x server must provide secure delegation to all child zones.
SV-272426r1124021_ruleThe BIND 9.x server validity period for the RRSIGs covering the DS RR for zones delegated children must be no less than two days and no more than one week.
SV-272427r1124022_rulePermissions assigned to the DNSSEC keys used with the BIND 9.x implementation must enforce read-only access to the key owner and deny access to all other users.
SV-272428r1123761_ruleThe DNSSEC keys used with the BIND 9.x implementation must be owned by a privileged account.
SV-272429r1123762_ruleThe DNSSEC keys used with the BIND 9.x implementation must be group owned by a privileged account.
SV-272430r1123947_ruleThe BIND 9.x server implementation must maintain at least three file versions of the local log file.
SV-272431r1123606_ruleThe BIND 9.x server implementation must be configured with a channel to send audit records to a local file.
SV-272432r1123950_ruleThe BIND 9.x server implementation must be configured with a channel to send audit records to at least two remote syslogs.
SV-272433r1123612_ruleThe BIND 9.x server implementation must not be configured with a channel to send audit records to null.
SV-272435r1124068_ruleThe BIND 9.x server implementation must uniquely identify and authenticate the other DNS server before responding to a server-to-server transaction, zone transfer, and/or dynamic update request using cryptographically based bidirectional authentication to protect the integrity of the information in transit.
SV-272436r1137676_ruleA BIND 9.x server must implement NIST FIPS-validated cryptography for provisioning digital signatures and generating cryptographic hashes.
SV-275935r1124025_ruleThe BIND 9.x server implementation must have QNAME minimization set to "strict".
SV-275936r1156959_ruleThe BIND 9.x server implementation must have fetches-per-zone enabled.
SV-275937r1156959_ruleThe BIND 9.x server implementation must have fetches-per-server enabled.
SV-275938r1156959_ruleThe host running a BIND 9.x implementation must have DNS cookies enabled.
SV-275939r1156959_ruleThe BIND 9.x server implementation must limit the number of allowed dynamic update clients.