SV-207570r612253_rule
V-207570
SRG-APP-000231-DNS-000033
BIND-9X-001132
CAT II
10
Change the permissions of the DNSSEC key files:
# chmod 400 <DNSSEC_key_file>
If the server is in a classified network, this is Not Applicable.
Verify permissions assigned to the DNSSEC keys enforce read-only access to the key owner and deny access to group or system users:
With the assistance of the DNS Administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation:
# ls –al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key
If the key files are more permissive than 400, this is a finding.
V-207570
False
BIND-9X-001132
If the server is in a classified network, this is Not Applicable.
Verify permissions assigned to the DNSSEC keys enforce read-only access to the key owner and deny access to group or system users:
With the assistance of the DNS Administrator, determine the location of the DNSSEC keys used by the BIND 9.x implementation:
# ls –al <DNSSEC_Key_Location>
-r--------. 1 named named 76 May 10 20:35 DNSSEC-example.key
If the key files are more permissive than 400, this is a finding.
M
2926