SV-214202r612370_rule
V-214202
SRG-APP-000516-DNS-000078
IDNS-7X-000710
CAT II
10
Navigate to Data Management >> DNS >> Grid DNS Properties. Toggle “Advanced Mode” and select the "DNSSEC" tab.
Modify the “Zone-Signing Key Rollover Interval” to a period of less than two months.
When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
Perform a service restart if necessary.
Follow manual key rollover procedures and ensure changes are published to all applicable systems, including parent DNS systems.
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Review the Infoblox DNSSEC configuration and validate the ZSK rollover interval is configured for a range of no more than two months.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode and click on the "DNSSEC" tab.
Validate the “Zone-Signing Key Rollover Interval” is configured to a value of less than two months.
If the “Zone-Signing Key Rollover Interval” is configured to a value more than two months, this is a finding.
When complete, click "Cancel" to exit the "Properties" screen.
V-214202
False
IDNS-7X-000710
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Review the Infoblox DNSSEC configuration and validate the ZSK rollover interval is configured for a range of no more than two months.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode and click on the "DNSSEC" tab.
Validate the “Zone-Signing Key Rollover Interval” is configured to a value of less than two months.
If the “Zone-Signing Key Rollover Interval” is configured to a value more than two months, this is a finding.
When complete, click "Cancel" to exit the "Properties" screen.
M
3995