STIGQter STIGQter: STIG Summary: Infoblox 7.x DNS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The Key Signing Key (KSK) rollover interval must be configured to no less than one year.

DISA Rule

SV-214170r612370_rule

Vulnerability Number

V-214170

Group Title

SRG-APP-000214-DNS-000079

Rule Version

IDNS-7X-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to Data Management >> DNS >> Grid DNS Properties.
Toggle Advanced Mode and select the "DNSSEC" tab.

Modify the “Key-Signing Key Rollover Interval” to a period of no less than one year.

When complete, click "Save & Close" to save the changes and exit the "Properties" screen.

Perform a service restart if necessary.

Follow manual key rollover procedures and ensure changes are published to all applicable systems, including parent DNS systems.

Check Contents

Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.

Navigate to Data Management >> DNS >> Grid DNS properties.

Toggle "Advanced Mode" and click on the "DNSSEC" tab.

Validate the “Key-Signing Key Rollover Interval” is configured to a value of no less than one year.

If the “Key-Signing Key Rollover Interval” is configured to more than one year, this is a finding.

Vulnerability Number

V-214170

Documentable

False

Rule Version

IDNS-7X-000230

Severity Override Guidance

Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.

Navigate to Data Management >> DNS >> Grid DNS properties.

Toggle "Advanced Mode" and click on the "DNSSEC" tab.

Validate the “Key-Signing Key Rollover Interval” is configured to a value of no less than one year.

If the “Key-Signing Key Rollover Interval” is configured to more than one year, this is a finding.

Check Content Reference

M

Target Key

3995

Comments