12 - Restrict BIND Access with SELinux - named_write_master_zones

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Security Enhanced Linux (SELinux) project started by the NSA provides targeted mandatory access controls, which may be used to restrict BIND to minimal access. SELinux is included in the RedHat Enterprise and Fedora Core installation options. Make sure you have the latest versions of following RPM's, or install them if needed.

Rationale:

Latest version of RPM,s ensure bugs and securty vulnerability are patched enhancing the performance of the system.

Solution

Make sure you have the latest versions of following RPM's, or install them as needed.
- libselinux-devel
- libselinux
- selinux-policy-targeted
- selinux-policy-targeted-sources
- selinux-doc
- checkpolicy

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3)

Plugin: Unix

Control ID: ddb60f0265b7d11df377e5a7acacd9d625af3d2d222145ae89d48274bfbfbd6f