SV-214168r612370_rule
V-214168
SRG-APP-000213-DNS-000024
IDNS-7X-000210
CAT II
10
Navigate to Data Management >> DNS >> Zones tab.
Place a check mark in the box next to the desired external authoritative zone. Using the "DNSSEC" drop-down menu in the toolbar, select "Sign zones". Acknowledge the informational banner and the service restart banner if prompted.
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode click on "DNSSEC" tab, verify "Enable DNSSEC" is enabled.
Navigate to Data Management >> DNS >> Zones.
Verify that the "Signed" column is displayed.
Validate that all external authoritative zones are signed by displaying "Yes".
When complete, click "Cancel" to exit the "Properties" screen.
If DNSSEC is not enabled, and external authoritative zones are not signed, this is a finding.
V-214168
False
IDNS-7X-000210
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode click on "DNSSEC" tab, verify "Enable DNSSEC" is enabled.
Navigate to Data Management >> DNS >> Zones.
Verify that the "Signed" column is displayed.
Validate that all external authoritative zones are signed by displaying "Yes".
When complete, click "Cancel" to exit the "Properties" screen.
If DNSSEC is not enabled, and external authoritative zones are not signed, this is a finding.
M
3995