SV-69205r1_rule
V-54959
SRG-APP-000516-DNS-000111
SRG-APP-000516-DNS-000111
CAT II
10
Apply permissions to the private key corresponding to the ZSK alone with read/modify permissions for the account under which the name server software is run.
Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, ensure the private key corresponding to the ZSK alone is protected with directory/file-level access control list-based or cryptography-based protections.
If the private key corresponding to the ZSK alone is not protected with directory/file-level access control list-based or cryptography-based protections, this is a finding.
V-54959
False
SRG-APP-000516-DNS-000111
Review the DNS name server and documentation to determine whether it accepts dynamic updates. If dynamic updates are accepted, ensure the private key corresponding to the ZSK alone is protected with directory/file-level access control list-based or cryptography-based protections.
If the private key corresponding to the ZSK alone is not protected with directory/file-level access control list-based or cryptography-based protections, this is a finding.
M
2355