SV-69061r1_rule
V-54815
SRG-APP-000213-DNS-000024
SRG-APP-000213-DNS-000024
CAT II
10
Generate an RRSET for each zone hosted by the DNS server to include an RRSIG, DNSKEY and NSEC for each zone.
Review the zones hosted by the DNS server. Verify each of the zones have been digitally signed.
To determine if the zones have been digitally signed, verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).
If the DNS server's zones do not contain these additional RRs along with the regular RRs, this is a finding.
V-54815
False
SRG-APP-000213-DNS-000024
Review the zones hosted by the DNS server. Verify each of the zones have been digitally signed.
To determine if the zones have been digitally signed, verify the existence of an RRSET for each zone, which will include, at a minimum, an RRType RRSIG (Resource Record Signature) as well as an RRType DNSKEY and RRType NSEC (Next Secure).
If the DNS server's zones do not contain these additional RRs along with the regular RRs, this is a finding.
M
2355