SV-69055r1_rule
V-54809
SRG-APP-000176-DNS-000094
SRG-APP-000176-DNS-000094
CAT II
10
Store the private keys of the ZSK and KSK off-line in an encrypted file system.
Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, verify only the private keys corresponding to the ZSK (Zone Signing Key) are located on the server.
If the private keys to the KSK are located on the name server that accepts dynamic updates, this is a finding.
V-54809
False
SRG-APP-000176-DNS-000094
Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, verify only the private keys corresponding to the ZSK (Zone Signing Key) are located on the server.
If the private keys to the KSK are located on the name server that accepts dynamic updates, this is a finding.
M
2355