Skip to content

The DNS implementation must protect the authenticity of communications sessions for zone transfers.

An XCCDF Rule

Description

DNS is a fundamental network service that is prone to various attacks, such as cache poisoning and man-in-the middle attacks. If communication sessions are not provided appropriate validity protections, such as the employment of DNSSEC, the authenticity of the data cannot be guaranteed.

ID
SV-205182r961110_rule
Version
SRG-APP-000219-DNS-000028
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the DNS server with transaction signing (TSIG) or SIG(0).