NIST Checklist Logo
NIST Security Configuration Checklists Repository
BETA
Browse Repository by
   Product Category
   Vendor
   Submitting
Organization

Our Sponsor
white space white space

Domain Name System Security Technical Implementation Guide

Name

Domain Name System Security Technical Implementation Guide, v3 Release 1

Version

v3 Release 1

Status

Final

Creation Date

Not available.

Revision Date

2006-08-31

Product Category

Domain Name System

Vendor

Internet System Consortium, Inc.
Microsoft Corporation
Cisco Systems

Product

Bind 9.2.1
Bind 9.2.1 for Microsoft Windows NT, 2000, 2003
Windows 2000 DNS
CSS DNS

Product Version

Bind 9.2.1
Bind 9.2.1 for Microsoft Windows NT, 2000, 2003
Windows 2000 DNS
CSS DNS

Product Role

Domain Name Server

Checklist Summary

This DNS Security Technical Implementation Guide (STIG) is designed to assist administrators with the configuration of DNS server software (BIND, Windows 2000 DNS, and CSS DNS) and related portions of the underlying operating system. This STIG also provides guidance for standard operating procedures related to configuration management, business continuity, and other topics, such as a DNS overview and general security requirements for DNS architectures.

This document details DOD DNS security practices and procedures applicable to all DOD Top Level Domain (TLD) and below name servers. The policy portions of this STIG are relevant to all name servers connected to either the DOD Non-Classified Internet Protocol Router Network (NIPRNet) or Secret Internet Protocol Router Network (SIPRNet).

This includes the following entities, which are hereinafter referred to as sites or facilities:

- Defense Enterprise Computing Centers (DECCs)

- Defense Enterprise Computing Center-Detachments (DECC-Ds)

- Regional Network Operations and Security Centers (RNOSCs)

- DOD Components

- Systems Support Offices (SSOs)

- Combatant Commanders

- Other DISA customers

This document supports the following implementations of DNS:

- BIND 9.2.1

- BIND 9.2.1 for Microsoft Windows NT, Windows 2000, and Windows 2003

- Windows 2000 DNS

- CSS DNS

The field use of Berkeley Internet Name Domain (BIND) releases are 8.2.7 and above, 8.3.4 and above, and 9.2.1 and above are acceptable, but the document does not detail the syntax of BIND 8 configuration statements. In most cases, BIND 8 and BIND 9 statements are identical. When they are not, organizations deploying BIND 8 must make the appropriate changes to the BIND 9 syntax in this document to achieve the desired effect.

This document supersedes previous DNS guidance found in the Network and UNIX STIGs. It also has implications for organizations within the scope of the Enclave, IP WAN, and Web Server STIGs.

Known Issues

This STIG does not address the DNS configuration of DNS clients (i.e., workstations, servers, and network devices that query name servers). Each of these clients runs DNS resolver software. Any requirements concerning those resolvers would be addressed in the STIG corresponding to the underlying technology (e.g., Desktop, Network, etc.)

Target Audience

Developped for the DOD.
The requirements set forth in this document are designed to assist Information Assurance Officers (IAOs) and DNS administrators. This document assumes that the reader has experience installing and administering DNS servers.

Target Operational Environment

Enterprise and Specialized Security-Limited Functionality.

Checklist Installation Tools

Not available.

Rollback Capability

Not available.

Testing Information

Not available.

NIAP/CMVP Status

Not available.

Regulatory Compliance

DOD Directive 8500.

Comments, Warnings, Disclaimer, Miscellaneous

Refer to Known Issues.

Disclaimer

Not available.

Product Support

It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.

Submitting Organization/Authors

Defense Information Systems Agency

Point of Contact

Not available.

Sponsor

Not available.

Licensing

Not available.

Checklist Homepage

http://iase.disa.mil/stigs/stig/index.html

Download Package

http://iase.disa.mil/stigs/stig/
DNS_STIG_V3R1%20final.pdf

Integrity

SHA1 Digest (DNS_STIG_V3R1%20final.pdf) =
42200a0b0367680d9daf1187d2e72759465d77d3

SHA256 Digest (DNS_STIG_V3R1%20final.pdf) =
59fd90ab739978b81f546bb511f5cf5da30e3c10d93c
2469c75426107e4bac72

Change History

v2 Release 1: 2004-03-19
v2 Release 2: 2005-03-11

v3 Release 1: 2006-08-31

Dependency/Requirement

Domain Name System (DNS) Checklist, v2r1.3

References

Not available.

NIST Identifier

1063




NIST and the checklist submitter do not guarantee or warrant the checklist's accuracy or completeness. NIST is not responsible for loss, damage, or problems that may be caused by using the checklist.

Last updated: November 15, 2006
Page created: October 28, 2004

Disclaimer Notice & Privacy Statement / Security Notice
Send comments or suggestions to checklists@nist.gov
NIST is an Agency of the U.S. Commerce Department's Technology Administration