SV-207593r612253_rule
V-207593
SRG-APP-000516-DNS-000084
BIND-9X-001610
CAT II
10
Resign each zone that is missing NSEC records.
Restart the BIND 9.x process.
If the server is in a classified network, this is Not Applicable. If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.
With the assistance of the DNS Administrator, identify each internal DNS zone listed in the "named.conf" file.
For each internal zone identified, inspect the signed zone file for the NSEC resource records:
86400 NSEC example.com. A RRSIG NSEC
If the zone file does not contain an NSEC record for the zone, this is a finding.
V-207593
False
BIND-9X-001610
If the server is in a classified network, this is Not Applicable. If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.
With the assistance of the DNS Administrator, identify each internal DNS zone listed in the "named.conf" file.
For each internal zone identified, inspect the signed zone file for the NSEC resource records:
86400 NSEC example.com. A RRSIG NSEC
If the zone file does not contain an NSEC record for the zone, this is a finding.
M
2926