SV-233861r621666_rule
V-233861
SRG-APP-000516-DNS-000078
IDNS-8X-400003
CAT II
10
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on the "DNSSEC" tab, and edit the "Signature Validity" setting to a period between two days and one week.
3. When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
4. Any zones that used an incorrect value should perform a ZSK rollover to update the inception and expiration dates with the new value.
5. Navigate to Data Management >> DNS and select the "Zones" tab.
6. Using the zone selection check boxes and the DNSSEC drop-down menu, select "Rollover Zone-Signing Key".
7. When prompted, select "Roll Over".
8. Perform a service restart if necessary.
Note: For Infoblox DNS systems on a classified network, this requirement is Not Applicable.
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on the "DNSSEC" tab, and review the "Signature Validity" setting.
3. Validate that the Signature Validity is configured for a range of no less than two days and no more than one week.
4. When complete, click "Cancel" to exit the "Properties" screen.
If the "Signature Validity" period is less than two days or greater than one week, this is a finding.
V-233861
False
IDNS-8X-400003
Note: For Infoblox DNS systems on a classified network, this requirement is Not Applicable.
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on the "DNSSEC" tab, and review the "Signature Validity" setting.
3. Validate that the Signature Validity is configured for a range of no less than two days and no more than one week.
4. When complete, click "Cancel" to exit the "Properties" screen.
If the "Signature Validity" period is less than two days or greater than one week, this is a finding.
M
5251