SV-69063r1_rule
V-54817
SRG-APP-000214-DNS-000025
SRG-APP-000214-DNS-000025
CAT II
10
Configure each child zone to upload its DS RRset to the parent zone.
Review the zones hosted by the DNS server. Every zone should have an RRSET which includes the RRTypes of RRSIG, DNSKEY and NSEC.
If a zone has a child, the RRSET should also include the RRType DS (Delegation Signer) RR, which contain the (hash) public key of child zones.
If the zones hosted by the DNS server do not have any child domains, this is not a finding.
If the zones hosted by the DNS server have child domains, and there is not an RRType DS RR in the zone's RRSET, this is a finding.
V-54817
False
SRG-APP-000214-DNS-000025
Review the zones hosted by the DNS server. Every zone should have an RRSET which includes the RRTypes of RRSIG, DNSKEY and NSEC.
If a zone has a child, the RRSET should also include the RRType DS (Delegation Signer) RR, which contain the (hash) public key of child zones.
If the zones hosted by the DNS server do not have any child domains, this is not a finding.
If the zones hosted by the DNS server have child domains, and there is not an RRType DS RR in the zone's RRSET, this is a finding.
M
2355