SV-207578r612253_rule
V-207578
SRG-APP-000214-DNS-000025
BIND-9X-001310
CAT II
10
Sign each child zone. During the zone signing process, ensure that a DS record is created and is stored on the Parent zone name server.
If the server is in a classified network, this is Not Applicable.
Verify that there is a DS record set for each child zone defined in "/etc/named.conf" file.
For each child zone listed in "/etc/named.conf" file, verify there is a corresponding "dsset-zone_name" file.
If any child zone does not have a corresponding DS record set, this is a finding.
V-207578
False
BIND-9X-001310
If the server is in a classified network, this is Not Applicable.
Verify that there is a DS record set for each child zone defined in "/etc/named.conf" file.
For each child zone listed in "/etc/named.conf" file, verify there is a corresponding "dsset-zone_name" file.
If any child zone does not have a corresponding DS record set, this is a finding.
M
2926