24 - Disable dnssec-accept-expired option

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Introduced in BIND 9.4, the dnssec-accept-expired option allows named to accept expired Signed RRSets (RRSIGs).

Rationale:

Accepting expired RRSIGs may increase the server's exposure to replay attacks.

Solution

If present, remove the dnssec-accept-expired option from named.conf.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 2480bb20c9106ecf88723a1f6d376ce8a545cfd91c10846e4279f06ac82b799f