SV-233910r621666_rule
V-233910
SRG-APP-000214-DNS-000079
IDNS-8X-700005
CAT II
10
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on "DNSSEC" tab, and edit the "Signature Validity" setting to a period between two days and one week.
3. When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
4. Any zones that used an incorrect value should perform a ZSK rollover to update the inception and expiration dates with the new value.
5. Navigate to Data Management >> DNS and select the "Zones" tab.
6. Using the zone selection check boxes and the DNSSEC drop-down menu, select "Rollover Zone-Signing Key".
7. When prompted, select "Roll Over".
8. Perform a service restart if necessary.
Note: For Infoblox DNS systems on a classified network, this requirement is Not Applicable.
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on "DNSSEC" tab, and review the "Signature Validity" setting.
3. Validate that the Signature Validity is configured for a range of no less than two days and no more than one week.
4. When complete, click "Cancel" to exit the "Properties" screen.
If the Signature Validity period is less than two days or greater than one week, this is a finding.
V-233910
False
IDNS-8X-700005
Note: For Infoblox DNS systems on a classified network, this requirement is Not Applicable.
1. Navigate to Data Management >> DNS >> Grid DNS properties.
2. Toggle Advanced Mode, click on "DNSSEC" tab, and review the "Signature Validity" setting.
3. Validate that the Signature Validity is configured for a range of no less than two days and no more than one week.
4. When complete, click "Cancel" to exit the "Properties" screen.
If the Signature Validity period is less than two days or greater than one week, this is a finding.
M
5251