From Infoblox 7.x DNS Security Technical Implementation Guide
Part of SRG-APP-000215-DNS-000026
Associated with: CCI-001663
If name server replies are invalid or cannot be validated, many networking functions and communication would be adversely affected. With DNS, the presence of Delegation Signer (DS) records associated with child zones informs clients of the security status of child zones. These records are crucial to the DNSSEC chain of trust model. Each parent domain's DS record is used to verify the DNSKEY record in its subdomain, from the top of the DNS hierarchy down.
Note: For Infoblox DNS systems on a Classified network, this requirement is Not Applicable. Authoritative Check: Navigate to Data Management >> DNS >> Zones. Ensure external authoritative zones are DNSSEC signed. Recursive Check: Navigate to Data Management >> DNS >> Zones. Note: DNSSEC validation is only applicable on a grid member where recursion is active. Edit "Grid DNS Properties", toggle Advanced Mode, and select the DNSSEC tab. Validate that both "Enable DNSSEC" and "Enable DNSSEC Validation" are enabled. When complete, click "Cancel" to exit the "Properties" screen. If DNSSEC is not utilized for authoritative DNS and recursive clients this is a finding. Note: To add "Signed" column, select an existing column, select the down arrow, select "Columns", select "Edit Columns", select the check box for "Visible" and select "Apply".
Authoritative Fix: Navigate to Data Management >> DNS >> Zones. Select the appropriate zone using the check box, then use the "DNSSEC" drop-down menu and select "Sign Zones". Follow prompt to acknowledge zone signing. Recursive Fix: Navigate to Data Management >> DNS >> Zones. Edit "Grid DNS Properties", toggle Advanced Mode, and select the "DNSSEC" tab. Enable both "Enable DNSSEC" and "Enable DNSSEC Validation" options. When complete, click "Save & Close" to save the changes and exit the "Properties" screen. Perform a service restart if necessary.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer