Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-34195 | SRG-NET-000230-DNS-000136 | SV-44670r1_rule | Medium |
Description |
---|
DNS is a fundamental network service which is prone to various attacks. If the authenticity of the originator of a dynamic update cannot be guaranteed through the use of TSIG , the DNS server is more susceptible to attacks such as cache poisoning and man-in-the middle attacks. |
STIG | Date |
---|---|
Domain Name System (DNS) Security Requirements Guide | 2012-10-24 |
Check Text ( C-42175r1_chk ) |
---|
Review the DNS server configuration to determine if communication sessions for dynamic updates are provided integrity protections through the use of TSIG. If communications sessions do not employ authenticity protections, this is a finding. |
Fix Text (F-38124r1_fix) |
---|
Configure the DNS server to employ mechanisms to protect the authenticity of communications sessions for dynamic updates. |