SV-69163r1_rule
V-54917
SRG-APP-000516-DNS-000077
SRG-APP-000516-DNS-000077
CAT II
10
Include instructions in the DNS operational procedures to change the salt value every time RRs signed by NSEC3 have been re-signed.
Check the DNS configuration files and operational documentation. If the zone's RRs have been signed with NSEC3, the operational procedures should stipulate to change the salt value every time the zone is completely re-signed.
If the operational procedures do not specify to change the salt value for RRs signed with NSEC3 every time the zone is completely re-signed, this is a finding.
V-54917
False
SRG-APP-000516-DNS-000077
Check the DNS configuration files and operational documentation. If the zone's RRs have been signed with NSEC3, the operational procedures should stipulate to change the salt value every time the zone is completely re-signed.
If the operational procedures do not specify to change the salt value for RRs signed with NSEC3 every time the zone is completely re-signed, this is a finding.
M
2355