UBTU-16-030520 - For Ubuntu operating systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured - nameserver 1

Information

To provide availability for name resolution services, multiple redundant name servers are mandated. A failure in name resolution could lead to the failure of security functions requiring name resolution, which may include time synchronization, centralized authentication, and remote system logging.

Solution

Configure the Ubuntu operating system to use two or more name servers for Domain Name Server (DNS) resolution.

Edit the '/etc/resolv.conf' file to uncomment or add the two or more 'nameserver' option lines with the IP address of local authoritative name servers. If local host resolution is being performed, the '/etc/resolv.conf' file must be empty. An empty '/etc/resolv.conf' file can be created as follows:

# echo -n > /etc/resolv.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_16-04_LTS_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-215145r610931_rule, STIG-ID|UBTU-16-030520, STIG-Legacy|SV-90551, STIG-Legacy|V-75871, Vuln-ID|V-215145

Plugin: Unix

Control ID: 7ccd0c987756263382c9dfdfbaffda77d4024ec9b641b6e6ca14896f19ef1bf1