UCF STIG Viewer Logo

The DNS implementation must use organization defined replay-resistant authentication mechanisms for network access to non-privileged accounts.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34098 SRG-NET-000147-DNS-000088 SV-44551r1_rule Medium
Description
Replay attacks, if successfully used against a DNS account could result in unfettered access to the DNS settings and data records. A successful replay attack against a privileged DNS account could result in a complete compromise of the DNS infrastructure.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-42057r1_chk )
Review the DNS account management configuration and settings to determine whether organization defined replay-resistant authentication mechanisms for network access to non-privileged accounts exist. If these mechanisms do not exist, this is a finding.

The account management functions will be performed by the name server application if the capability exists. If the capability does not exist the underlying platform's account management system may be used.
Fix Text (F-38008r1_fix)
Configure the DNS implementation to utilize organization defined replay-resistant authentication mechanisms for network access to non-privileged accounts.