SV-207597r612253_rule
V-207597
SRG-APP-000516-DNS-000102
BIND-9X-001620
CAT III
10
Edit the local root zone file.
Remove any reference to a domain that is outside of the name server’s primary domain.
Restart the BIND 9.x process.
If this is an authoritative name server, this is Not Applicable.
Identify the local root zone file in named.conf:
zone "." IN {
type hint;
file "<file_name>"
};
Examine the local root zone file.
If the local root zone file lists domains outside of the name server’s primary domain, this is a finding.
V-207597
False
BIND-9X-001620
If this is an authoritative name server, this is Not Applicable.
Identify the local root zone file in named.conf:
zone "." IN {
type hint;
file "<file_name>"
};
Examine the local root zone file.
If the local root zone file lists domains outside of the name server’s primary domain, this is a finding.
M
2926