SV-207565r612253_rule
V-207565
SRG-APP-000176-DNS-000019
BIND-9X-001112
CAT II
10
Change the permissions of the TSIG key files:
# chmod 600 <TSIG_key_file>
Verify permissions assigned to the TSIG keys enforce read-write access to the key owner and deny access to group or system users:
With the assistance of the DNS Administrator, determine the location of the TSIG keys used by the BIND 9.x implementation:
# ls –al <TSIG_Key_Location>
-rw-------. 1 named named 76 May 10 20:35 tsig-example.key
If the key files are more permissive than 600, this is a finding.
V-207565
False
BIND-9X-001112
Verify permissions assigned to the TSIG keys enforce read-write access to the key owner and deny access to group or system users:
With the assistance of the DNS Administrator, determine the location of the TSIG keys used by the BIND 9.x implementation:
# ls –al <TSIG_Key_Location>
-rw-------. 1 named named 76 May 10 20:35 tsig-example.key
If the key files are more permissive than 600, this is a finding.
M
2926