SV-214207r612370_rule
V-214207
SRG-APP-000516-DNS-000090
IDNS-7X-000780
CAT I
10
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode click on "DNSSEC" tab.
Follow manual key rollover procedures and update all non-compliant Key Signing Keys (KSK) and Zone Signing Keys (ZSK) to utilize FIPS-approved algorithms.
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Infoblox supports FIPS compliant DSA and RSA; SHA-1, SHA-256, and SHA-512 algorithms.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode click on "DNSSEC" tab.
Validate that all Key Signing Keys (KSK) and Zone Signing Keys (ZSK) utilize FIPS approved algorithms.
When complete, click "Cancel" to exit the "Properties" screen.
If FIPS approved algorithms are not used for the Key Signing Keys (KSK) and Zone Signing Keys (ZSK), this is a finding.
V-214207
False
IDNS-7X-000780
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable.
Infoblox supports FIPS compliant DSA and RSA; SHA-1, SHA-256, and SHA-512 algorithms.
Navigate to Data Management >> DNS >> Grid DNS properties.
Toggle Advanced Mode click on "DNSSEC" tab.
Validate that all Key Signing Keys (KSK) and Zone Signing Keys (ZSK) utilize FIPS approved algorithms.
When complete, click "Cancel" to exit the "Properties" screen.
If FIPS approved algorithms are not used for the Key Signing Keys (KSK) and Zone Signing Keys (ZSK), this is a finding.
M
3995