SV-69133r1_rule
V-54887
SRG-APP-000427-DNS-000060
SRG-APP-000427-DNS-000060
CAT II
10
Configure the DNS server to only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected transactions.
If the DNS server is using SIG(0), review the DNS server implementation configuration to determine if the DNS server only allows the use of DoD PKI-established certificate authorities for verification of the establishment of protected transactions. If the DNS server allows the use of other certificate authorities, this is a finding.
V-54887
False
SRG-APP-000427-DNS-000060
If the DNS server is using SIG(0), review the DNS server implementation configuration to determine if the DNS server only allows the use of DoD PKI-established certificate authorities for verification of the establishment of protected transactions. If the DNS server allows the use of other certificate authorities, this is a finding.
M
2355