SV-215605r561297_rule
V-215605
SRG-APP-000176-DNS-000018
WDNS-IA-000007
CAT II
10
Access Windows Explorer.
Navigate to the following location:
%ALLUSERSPROFILE%\Microsoft\Crypto
Right-click on each sub-folder, choose “Properties”, click on the “Security” tab, and click on the “Advanced” button.
Click on "Change" next to the listed Owner and change to be the account under which the DNS Server Service is running.
Access Services on the Windows DNS Server and locate the DNS Server Service.
Determine the account under which the DNS Server Service is running.
Access Windows Explorer.
Navigate to the following location:
%ALLUSERSPROFILE%\Microsoft\Crypto
Note: If the %ALLUSERSPROFILE%\Microsoft\Crypto folder doesn't exist, this is not applicable.
Right-click on each sub-folder, choose “Properties”, click on the “Security” tab, and click on the “Advanced” button.
Verify the Owner on the folder, sub-folders, and files are the account under which the DNS Server Service is running.
If any other user or group is listed as OWNER of the %ALLUSERSPROFILE%\Microsoft\Crypto folder, sub-folders, and files, this is a finding.
V-215605
False
WDNS-IA-000007
Access Services on the Windows DNS Server and locate the DNS Server Service.
Determine the account under which the DNS Server Service is running.
Access Windows Explorer.
Navigate to the following location:
%ALLUSERSPROFILE%\Microsoft\Crypto
Note: If the %ALLUSERSPROFILE%\Microsoft\Crypto folder doesn't exist, this is not applicable.
Right-click on each sub-folder, choose “Properties”, click on the “Security” tab, and click on the “Advanced” button.
Verify the Owner on the folder, sub-folders, and files are the account under which the DNS Server Service is running.
If any other user or group is listed as OWNER of the %ALLUSERSPROFILE%\Microsoft\Crypto folder, sub-folders, and files, this is a finding.
M
4016