Rule ID
SV-285308r1258974_rule
Version
V1R1
CCIs
A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.
Verify that HSM signing is configured: 1. Navigate to Data Management >> DNS tab. 2. Click "Grid DNS Properties" (Toolbar menu). 3. Toggle Advanced Mode (if not enabled). 4. Click the "DNSSEC" tab. 5. Confirm "Enable DNSSEC" and "Enable HSM Signing" checkboxes are selected. If "Enable HSM Signing" is not selected, this is a finding.
Configure HSM Group: 1. Navigate to Infoblox Grid >> HSM Group. 2. Click the drop-down next to "Add" and select "Thales Luna Group" or "Entrust nShield Group". 3. Input the configuration information for either group. 4. Click "Save & Close". Enable HSM Signing: 1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu). 2. Toggle Advanced Mode (if not selected). 3. Click the "DNSSEC" tab. 4. Confirm "Enable DNSSEC" and "Enable HSM Signing" checkboxes are selected. 5. Configure DNSSEC Parameters. Note that Entrust nShield HSMs do not support DSA. 6. Click "Save & Close". A Grid can be integrated with third-party, network-attached Hardware Security Modules (HSMs) for secure private key storage and generation, and zone-signing off-loading. Infoblox appliances support integration with either Thales Luna HSMs or Entrust nShield HSMs. When using a network-attached HSM, tight physical access control can be provided, allowing only selected security personnel to physically access the HSM that stores the DNSSEC keys. When this feature is enabled, the HSM performs DNSSEC zone signing, key generation, and key safe keeping. Refer to Infoblox Documentation for configuring a Thales Luna or Entrust nShield HSM Device. https://docs.infoblox.com/space/nios90/280664372/About+HSM+Signing