Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-34097 | SRG-NET-000146-DNS-000087 | SV-44550r1_rule | Medium |
Description |
---|
Replay attacks, if successfully used against a DNS account could result in unfettered access to the DNS settings and data records. A successful replay attack against a privileged DNS account could result in a complete compromise of the DNS infrastructure. |
STIG | Date |
---|---|
Domain Name System (DNS) Security Requirements Guide | 2012-10-24 |
Check Text ( C-42056r1_chk ) |
---|
Review the DNS system account management configuration and settings to determine whether organization defined replay-resistant authentication mechanisms for network access to privileged accounts exist. If these mechanisms do not exist, this is a finding. |
Fix Text (F-38007r1_fix) |
---|
Configure the DNS system to utilize organization defined replay-resistant authentication mechanisms for network access to privileged accounts. The account management functions will be performed by the name server application if the capability exists. If the capability does not exist the underlying platform's account management system may be used. |