SV-69165r1_rule
V-54919
SRG-APP-000516-DNS-000078
SRG-APP-000516-DNS-000078
CAT II
10
Configure RRSIGs covering each zone's DNSKEY RRSet to be greater than two days and less than one week.
Review the DNS configuration files. Ensure the validity period for RRSIGs has been explicitly configured and is configured for a range of no less than two days and no more than one week.
If the validity period for the RRSIGs covering a zone's DNSKEY RRSet is less than two days or greater than one week, this is a finding.
V-54919
False
SRG-APP-000516-DNS-000078
Review the DNS configuration files. Ensure the validity period for RRSIGs has been explicitly configured and is configured for a range of no less than two days and no more than one week.
If the validity period for the RRSIGs covering a zone's DNSKEY RRSet is less than two days or greater than one week, this is a finding.
M
2355