SV-207576r612253_rule
V-207576
SRG-APP-000176-DNS-000096
BIND-9X-001150
CAT I
10
Remove all private KSKs from the name server and ensure that they are stored offline in a secure location.
If the server is in a classified network, this is Not Applicable.
Ensure that there are no private KSKs stored on the name sever.
With the assistance of the DNS Administrator, obtain a list of all DNSSEC private keys that are stored on the name server.
Inspect the signed zone files(s) and look for the KSK key id:
DNSKEY 257 3 8 ( <hash_algorithm) ; KSK ; alg = ECDSAP256SHA256; key id = 52807
Verify that none of the identified private keys, are KSKs.
An example private KSK would look like the following:
Kexample.com.+008+52807.private
If there are private KSKs stored on the name server, this is a finding.
V-207576
False
BIND-9X-001150
If the server is in a classified network, this is Not Applicable.
Ensure that there are no private KSKs stored on the name sever.
With the assistance of the DNS Administrator, obtain a list of all DNSSEC private keys that are stored on the name server.
Inspect the signed zone files(s) and look for the KSK key id:
DNSKEY 257 3 8 ( <hash_algorithm) ; KSK ; alg = ECDSAP256SHA256; key id = 52807
Verify that none of the identified private keys, are KSKs.
An example private KSK would look like the following:
Kexample.com.+008+52807.private
If there are private KSKs stored on the name server, this is a finding.
M
2926